Privacy policy
Effective September 25, 2026. Last updated October 10, 2026.
This policy explains what personal information EBO2.com collects through ebo2.com and app.ebo2.com, why we collect it, who handles it for us, how long we keep it, and what you can do about it. It is long because it covers two sites and the laws of several places. Most readers give us very little: reading the sites needs no account, and an ordinary visit sends us only the technical information that every website receives.
1. Who we are
EBO2.com ("we," "us," or "our") runs two websites: ebo2.com, a free, independent information site and clinic directory about EBO2 (also called EBOO), an ozone blood therapy; and app.ebo2.com, its companion site for accounts. In this policy, "the sites" means both. This policy explains what personal information we collect on the sites, how we use and share it, how long we keep it, and the rights and choices you have.
EBO2.com decides how and why this information is used, which makes us its "controller" under European and UK data protection law. You can reach us through the contact form or by mail at EBO2.com, 1968 S. Coast Hwy, #1921, Laguna Beach, CA 92651, United States.
Who this policy covers
It covers everyone whose personal information reaches us through the sites: people who read ebo2.com, people who create an account on app.ebo2.com, people who write to us through the contact form or by mail, people who contact us on behalf of a clinic, people who use our tools or download our data, clinicians whose names appear in our listings, people named in the public records that our guides, reports, and data files cite, and the authors of the studies in our library. It covers the sites themselves, our contact inbox, and the service providers that work for us, which section 11 lists.
What it does not cover
This policy does not cover other websites that we link to, such as clinic websites and journal publishers. They have their own privacy policies. If you contact or visit a clinic after finding it in our directory, the clinic handles your information under its own policies, and we do not receive what you tell it.
How it fits with our other policies
Our cookie policy describes each cookie and how the cookie banner works. Our consumer health data privacy policy adds to this policy for health information covered by Washington, Nevada, and Connecticut law, and it controls where the two differ on consumer health data. Our terms of use set the rules for using the sites; on how we handle personal information, this policy controls.
2. Information we collect
We collect information you give us, information your browser sends when you use the sites, and, only if you allow it, information from analytics cookies. Section 4 sums it up in a table, and section 5 explains where each kind of information comes from.
On ebo2.com
- Contact form. When you send us a message, we receive your name, your email address, the topic you choose, your message, and, if your message is about a clinic listing, the clinic's name. The form sends your message through Resend, our email delivery service, to our inbox, which Google hosts as part of Google Workspace. We do not store it in a database, and our code passes it on without keeping a copy along the way.
- Requests from clinics. The form on our For clinics page is the same contact form. Besides your name, email address, and message, it asks for the clinic's name, or a link to the listing you want to claim. To check that a claim sent through the form comes from the clinic, we may look at whether the email address you wrote from is on the clinic's own website domain, or ask for a reply from an address on that domain. Clinics can also claim a listing themselves at app.ebo2.com, described below.
- Request logs. Vercel, which hosts ebo2.com, records basic information about each request your browser makes: your IP address, your browser's user agent (a short description of the browser and device), the address of the page, and the time. Vercel keeps these logs briefly, under its retention settings, and we use them for security and reliability.
- Cookie-free analytics. Vercel Web Analytics counts visits so we can see which pages people read. It sets no cookies. For each page view it records the page address, the address of the page that sent you there, an approximate location worked out from your connection, down to the city, your browser and operating system and their versions, and your device type. It tells visitors apart with a hash created from the incoming request instead of a cookie, and Vercel discards each visitor's session after 24 hours.
- Google Tag Manager and Google Analytics. Neither is connected to ebo2.com today. If we connect them: in the European Economic Area, the United Kingdom, Switzerland, Jersey, Guernsey, the Isle of Man, Gibraltar, Svalbard and Jan Mayen, California, Washington, Nevada, and Connecticut, and wherever we cannot tell where you are, Google's tags will load only after you accept analytics or marketing cookies in our cookie banner, and Google Analytics will set its cookies only if you accept analytics. Elsewhere, no banner appears and they will load unless you turn analytics and marketing off with "Cookie settings" at the bottom of any page; marketing stays off if your browser sends a Global Privacy Control signal. Google Analytics uses cookies to measure how visitors use a site, such as which pages they view.
- Tools, reports, and downloads. The tools work in your browser and send us nothing you enter. The only request a tool sends because of what you enter is the clinic finder's download of a ZIP code table, whose address shows the first digit of the ZIP code you searched, and it reaches our request logs like any other request. Reading a report or downloading a data file is an ordinary request too. Section 3 explains each case, including "Use my location."
- Maps. A clinic page shows a map made of OpenStreetMap's map tiles, which your browser loads from OpenStreetMap when you open the page. OpenStreetMap receives your IP address, the map area around the clinic, and our site's address, but not the page you were on.
- Your cookie choices and location. When you choose in the cookie banner, your browser stores
your choice and the time you made it in a cookie named
ebo2_consent. So that we know whether to show the banner, our host, Vercel, works out your country and state or region from your IP address and stores it in a cookie namedebo2_geo(for example "US-CA") for one day. We use it for nothing else and do not store it on our servers.
On app.ebo2.com
- Your account. To create an account, you give us your email address and a password, and you will be able to add a display name once profile editing is available. We store your email address, a hash of your password (a one-way scrambled version, not the password itself), your display name if you add one, your account's role, such as reader or clinic owner, and the dates the account was created and last changed. We also keep a record that you confirmed you are 18 or older and accepted our terms: the version you accepted and when. This account data is kept in Supabase, which provides the database and sign-in service for app.ebo2.com. You need an email address and a password to create an account; without them, we cannot open one.
- Sign-in cookies. When you sign in, Supabase's sign-in service sets cookies on app.ebo2.com that keep you signed in. Our cookie policy lists them.
- Bot protection. When you sign up, Vercel BotID has your browser answer an invisible challenge, which Vercel checks to tell people apart from automated bots. If the check flags an attempt as automated, the sign-up is blocked. If you think that happened to you by mistake, contact us.
- Account emails. We send account emails, such as sign-up confirmations and password resets, through Resend. They come from noreply@ebo2.com.
- Clinic claims and listing edits. The listing you claim, linked to your account, and how you showed that you represent the clinic: your account's confirmed email address and the clinic website domain it matched. The details you set for the listing (phone number, public email address, booking link, opening hours, services, and description), when you set them, and the status of each. Phone number, public email address, booking link, and opening hours appear on the public listing right away; services and descriptions appear after a person on our team approves them. We record each claim, change, and decision, who made it, and when.
- Request logs. Vercel also hosts app.ebo2.com and keeps the same kind of request logs for it.
Features coming to app.ebo2.com
We are building two more features for app.ebo2.com. When each one launches, it will collect the following:
- Comments. The text of your comment, the page it is on, the time you posted it, and its moderation status, linked to your account. To help prevent abuse, we also keep the IP address you posted from, but only as a keyed hash: a one-way code made with a secret key, so the address itself is not stored. Comments are held for approval, and approved comments are public. When a moderator decides on a comment, we record the decision, who on our team made it, when, and any note they wrote.
- Newsletter. Your email address and your subscription status, with the dates you subscribed, confirmed your address, and unsubscribed.
Until a feature launches, it collects nothing. If a feature, once built, needs information that this policy does not describe, we will update this policy before it starts collecting it.
What we do not collect
We never receive your precise location. The clinic finder can use your location inside your browser if you allow it, but the position is not sent to us or to anyone else (section 3). We do not use the pages you read to draw conclusions about your health, and what you check in the questions for your doctor stays in your browser. To read the sites, use the tools, write to us, or open an account, you never need to give us your date of birth, home address, phone number, payment details, or any government identification number, and we do not ask for them. We have no paid features, so we hold no payment information.
3. The tools, the reports, and the downloads
Our tools are the price check, the session cost planner, the clinic finder, and the questions for your doctor. They are free, they need no account, and they are built to work in your browser, so that what you enter does not have to reach us. This section says exactly what does and does not leave your browser when you use them, read our reports, or download our data.
What the tools do with what you enter
Each tool page carries the data it needs, such as the prices clinics publish or the list of situations and questions, and the page's own script does the work in the open browser tab. The price check, the session cost planner, and the questions for your doctor send nothing you enter to us or to anyone else: no amount, no number of sessions, no distance, and no box you check. The tools set no cookies and save nothing you enter in your browser's storage. They also leave the page address unchanged, so what you enter does not appear in your browser history, in a link you share, in our request logs, or in our visit counts. Loading a tool page is an ordinary visit: our host logs the request, and our cookie-free analytics counts the page, as for any page of ebo2.com.
In the questions for your doctor, you can check situations that concern your health, such as taking a blood thinner, pregnancy, or a heart condition. Those checks stay in your browser, and we never receive them, so we hold no health information from the tool. Your browser may keep what you entered in a tool for a while, for example to show it again if you go back to the page, as browsers do on any site; that copy stays on your device.
The clinic finder's ZIP code search
To turn a ZIP code into a point on the map, the clinic finder downloads one of ten public tables of ZIP code centers from ebo2.com, the one for ZIP codes that begin with the same digit as yours, and looks your ZIP code up inside your browser. The ZIP code itself, and its other four digits, never leave your browser. The request for the table reaches our host like any request: its logs record your IP address, your browser's user agent, the address of the table, which ends in that first digit (for example /data/zip/6.json), and the time. We use those logs only for security and reliability, and our host keeps them briefly. A first digit covers several states; 6, for example, covers Illinois, Kansas, Missouri, and Nebraska. Your browser may keep the downloaded table in its ordinary cache, as it does for any file, and your browser's own autofill may offer a ZIP code you saved; both stay on your device.
"Use my location"
The clinic finder also offers a "Use my location" button. Every other page of ebo2.com tells your browser that it may not ask for your location. The clinic finder's page lets only the page itself ask, not frames from other sites embedded in it, and a test checks these rules each time the site's code changes. When you press the button, your browser asks your permission first. If you allow it, your browser gives the page your coordinates, and the page uses them to measure distances in the tab and sends them nowhere: not to us, and not to any other service. The finder asks for an ordinary position, not a high-accuracy one, and accepts a position your browser found in the previous five minutes.
To work out where you are, your browser or device may use its own location service, which the company that makes it runs under its own privacy policy; we receive nothing from that service. Your browser may remember your answer for ebo2.com, and you can change it in your browser's settings for the site. If you say no, nothing is shared, and you can search by ZIP code instead.
Copying and printing
The session cost planner and the questions for your doctor can copy your plan or list as text, or print it. Copying puts the text on your device's clipboard only when you press the button, and printing opens your browser's print window; the site does not read your clipboard. A copied or printed list from the questions tool includes the situations you checked, so what happens to it next is up to you.
Reports and data downloads
Reading a report and downloading clinics.csv, clinics.json, studies.csv, or regulatory.json need no account, no email address, and no form. A download is an ordinary request that reaches our host's request logs. Our visit counts come from a script on our pages, so a file you download is not counted as a page visit, and opening a file sets no cookie. We do not ask who you are, and we do not track what anyone does with the files. The files contain personal information only where a name appears in what we record, such as a clinic named after a person, the authors of a paper, or a person that a public document names, as section 6 explains.
4. Categories of personal information
This table sums up each kind of personal information we handle: where it comes from, why we use it, the legal basis we rely on where European or UK data protection law applies (section 8 explains these), who receives it, and how long we keep it. "When available" marks a feature that has not launched yet. The sections after the table give the detail.
| Information | Where it comes from | Why we use it | Legal basis (EEA and UK) | Who receives it | How long we keep it |
|---|---|---|---|---|---|
| Contact-form messages: your name, email address, topic, message, and, for clinic topics, the clinic's name | You | To read and answer your message, and to act on corrections, listing requests, and privacy requests | Legitimate interests; legal obligation for privacy requests; your explicit consent for any health details you include | Vercel, Resend, and Google (our inbox) | Up to 24 months |
| Account data: email address, password hash, display name, role, dates, and your terms-acceptance record | You; the acceptance time comes from our database | To open and run your account, sign you in, send account emails, and show which terms you accepted | Contract | Supabase; Resend for account emails | While your account is open |
| Sign-in cookies | Supabase's sign-in service, in your browser | To keep you signed in | Contract | Supabase | Until you sign out, or up to 400 days |
| Your browser's answer to the bot check at sign-up | Your browser | To block automated sign-ups | Legitimate interests | Vercel (BotID) | We do not keep it |
| Request logs: IP address, user agent, page address, and time | Your browser | To keep the sites secure and working | Legitimate interests | Vercel | Briefly, under Vercel's retention settings |
| The first digit of a ZIP code you search in the clinic finder, in the address of the table your browser downloads, with the request-log details above | Your browser, when you search by ZIP code | To send the table your browser asked for, and to keep the sites secure and working | Legitimate interests | Vercel | As request logs: briefly, under Vercel's retention settings |
| What you enter in the tools, including the boxes you check and a location you share with the clinic finder | You, in your browser | To work out the result you asked for, in your browser | Not applicable: it does not reach us | No one: it stays in your browser | We keep none of it |
| Visit counts: for each page view, the page address, the referring page, an approximate location down to the city, and your browser, operating system, and device type | Your browser, through Vercel Web Analytics | To see which pages readers use | Legitimate interests | Vercel | Vercel discards each visitor's session after 24 hours and keeps the visit records under its retention settings |
Your cookie choices (ebo2_consent) and approximate location (ebo2_geo) | You, and Vercel from your IP address | To remember your choice and decide whether to show the cookie banner | Legal obligation, for your choice; legitimate interests, for your location | Kept in your browser, not on our servers | 12 months for your choice; 1 day for your location |
| Map tiles on clinic pages | Your browser, directly, when you open a clinic page | To show where a clinic is | Legitimate interests | OpenStreetMap, as an independent service | Under OpenStreetMap's own policy |
| Google Analytics cookies (not connected today) | Your browser, through Google's tags | To measure how visitors use ebo2.com | Consent | Up to 2 years | |
| Comments (when available) | You | To publish approved comments and to moderate them | Contract; legitimate interests for moderation and abuse prevention; your explicit consent for any health details | Supabase; the public, once a comment is approved | Until the comment is deleted or your account is closed |
| Clinic claims and listing edits | You | To confirm that you represent a clinic and to keep its listing accurate | Contract; legitimate interests | Supabase; the listing details you set appear on the public listing | While your account is open |
| Newsletter subscription (when available) | You | To send you the newsletter | Consent | Supabase, and Resend, which will send it | While you are subscribed |
| Clinicians' names and credentials, and what public records say about them | Clinics' own websites, and public records such as regulators' notices and court decisions | To show who provides EBO2 at a listed clinic and to report what regulators and courts have said | Legitimate interests | The public; the web-reading, cloud browser, and AI research services that read those pages for us | While the listing or page that shows it is published |
| Names of people in our data files: parties that public documents name, in regulatory.json, and the authors of papers, in studies.csv | Public records, such as warning letters, licensing board orders, court decisions, and indictments, and the published papers themselves | To publish an open, sourced record of what regulators and courts have said, and of the studies in our library, that anyone can check and reuse | Legitimate interests | The public, including anyone who downloads the files under CC BY 4.0; the web-reading, cloud browser, and AI research services that help us read the sources | While the record is published; copies others have downloaded are outside our control |
Section 13 gives the full retention schedule, including what stays after an account is closed, and section 22 sorts the same information into the categories that California law uses.
5. Where information comes from
From you
Most personal information we hold reaches us because you sent it: a message through the contact form, a letter by mail, the details you enter to create an account, and, when those features launch, the comments, clinic claims, listing edits, and newsletter sign-ups you submit. You decide what goes into a message or a comment, so please leave out anything you do not want us to have, especially details about your health.
From your browser and device
Every time your browser asks for a page, it sends our host, Vercel, your IP address, its user agent, and the address it wants, which become the request logs described in section 2. Vercel Web Analytics counts the visit without a cookie. When you sign up on app.ebo2.com, Vercel BotID has your browser answer an invisible challenge to check that a person is signing up. Your browser also sends back the cookies the sites have set, such as your cookie choices. If you search the clinic finder by ZIP code, the address of the table your browser downloads shows the first digit of that ZIP code; nothing else you enter in a tool reaches us (section 3).
From the services that run the sites
Some information is created by the services we use rather than typed by you. Vercel works out your country and state or region from your IP address so that the site knows whether to show the cookie banner. Supabase's sign-in service creates the codes in the cookies that keep you signed in, and our database adds the time to the record of the terms you accepted.
From public sources, about clinics and clinicians
Our directory describes clinics from what each clinic publishes on its own website. Some of that is about people: the names and credentials of the practitioners a clinic lists, and the business phone number and email address it publishes. Our guides and reports also cite public records, such as regulators' warning letters, licensing decisions, and court rulings, which can name the clinicians involved, and the studies in our library name their authors. We publish this information so that readers can see who provides the procedure and what regulators have said. We read these pages and documents with the help of a web-reading service, a cloud browser service, and AI research tools, which section 11 lists among our processors. If you are a clinician named on the sites and something about you is wrong or out of date, tell us through the contact form: we check it against the source, correct mistakes, and remove a name from a listing when the clinic's own website no longer shows it. Some of these names also appear in the data files we publish for download; section 6 explains what we publish, where, and how to ask for a correction, an update, or removal.
What we do not do
We do not buy personal information, and we do not receive it from data brokers, advertisers, social networks, or clinics' patient records. We do not combine what we know about you with information from other companies to learn more about you. If someone else tells us about you, for example a reader who reports an error in a listing that names you, we use what they sent only to handle their message, under this policy.
6. People named in our listings, records, and data files
Some of what we publish names people who never contacted us. This section says who they are, where their names appear, why we publish them, and how a person we name can ask us to correct, update, or remove what we say.
Who we name, and where
- Clinicians in listings. A clinic page shows the names and credentials of the practitioners a clinic lists on its own website. The clinic data files we publish for download leave these names out.
- People in public records. Our regulatory tracker records what regulators, courts, and legislatures have said about ozone therapy and EBO2. Each record shows the party the document names, when it names one, with the document's date, the body that issued it, its status as of the date we checked, our neutral summary, a key quote, and a link to the document itself. Some parties are people: for example, physicians named in licensing board orders, a practitioner named in a regulator's prohibition order abroad, a person named in an indictment, and people named in a court order or a court decision. The same records, names included, are in regulatory.json.
- Authors of studies. Our research library and studies.csv name each paper's authors, as the paper itself does.
Why we publish names, and on what basis
Readers deciding about a health procedure should be able to see who provides it and what regulators and courts have said, and to check it against the primary source. We name a person only when the clinic's own website or the public document itself does, and we copy the name as the source gives it. Where European or UK law applies, we rely on legitimate interests for this, and you can object as section 18 explains. A record reflects the document on its date: a warning letter states an agency's position, and an indictment states a charge, which is an allegation and not a finding of guilt. Where the document or the issuing body says so, our summary says so too.
What the open license means for these names
The data files are published under the CC BY 4.0 license, so anyone may download, copy, and reuse them, names included. That license does not cover privacy or publicity rights, and our terms of use remind people who reuse the files that the laws on privacy and defamation still apply to them. Once a file has been downloaded, we cannot recall the copy or control what someone else does with it.
Asking for a correction, an update, or removal
- Write to us through the contact form, choosing "Privacy or data request," or by mail to the address in section 31.
- Tell us which page or record you mean, for example the record's title and date in the regulatory tracker, or its id in regulatory.json, and what you want changed: an error to correct, a later development to record, such as charges dismissed, an order lifted, or a later decision, or a name to remove.
- Send a link to any public document that shows the correction or the later development. We may ask for enough information to show that the record is about you, or that you act for the person it names.
We check what you send against the source. We correct errors in our summary or in how we recorded a name, and we update a record's status, or add the later public document, when the sources show that the situation has changed. We consider every request to remove a name, weighing your reasons against the public's interest in an accurate record of what regulators and courts have said, and we reply in writing with what we decided and why, within the times in section 19. A change appears on our pages, and in the data files, at the next update of the site. We cannot change the original public document, or copies of our files that others have already downloaded. For a clinician named in a listing, we also remove the name when the clinic's own website no longer shows it.
7. How we use information
We use personal information to:
- answer your messages and requests, including privacy requests;
- create and run your account, sign you in, and send account emails, such as sign-up confirmations, password resets, and notices about changes to our terms or this policy;
- keep a record of the version of our terms you accepted and when;
- provide the features you choose to use, such as publishing approved comments, reviewing clinic claims and listing edits, and sending the newsletter to subscribers;
- moderate content under our terms of use;
- keep the directory accurate, including by checking listing details and clinicians' names against each clinic's own website;
- publish our directory, regulatory tracker, and data files, including the names that clinics' websites, public records, and published papers give (section 6);
- keep the sites secure and working, including by detecting and preventing fraud, spam, abuse, and automated sign-ups, and by finding and fixing problems;
- understand which pages readers use, through cookie-free Vercel Web Analytics and, only if you consent, Google Analytics; and
- comply with the law and respond to lawful requests.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it for targeted advertising. If we want to use personal information for a new purpose that is not compatible with the purposes above, we will tell you first and ask for your consent where the law requires it.
We do not build a profile of you from the pages you read, and we do not send marketing email. Today the only email we send is account email and our replies to your messages. When the newsletter launches, it will go only to people who sign up for it.
8. Legal bases (EEA and UK)
If you are in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) and the UK GDPR require a legal basis for each use of your personal information. We rely on these:
- Contract. To create and run your account, to provide the account features you use, and to keep the record of the terms you accepted.
- Legitimate interests. To keep the sites secure; to prevent fraud, abuse, and automated sign-ups, including through request logs, bot detection, and keyed hashes of commenters' IP addresses; to answer messages you send us; to count visits with cookie-free analytics; to send the clinic finder the ZIP code table it asks for; and to publish accurate information about clinics, the clinicians who work there, and the people that public records name, drawn from clinics' own websites and from public records, including in the data files we publish under an open license. We rely on these interests only where your rights and interests do not outweigh them, and you can object to this use, as described in section 18.
- Consent. For analytics cookies, for marketing cookies if we ever use them, and for the newsletter once we offer it. You can withdraw consent at any time: for cookies, in the cookie banner; for the newsletter, by unsubscribing. Withdrawing does not affect our use of your information before you withdrew.
- Legal obligation. When the law requires us to keep or disclose information, to answer privacy requests, and to remember your cookie choice so that we respect it.
Health information. Where you choose to tell us about your health in a message, a comment, or a clinic claim, we process that information on the basis of your explicit consent (GDPR Article 9(2)(a)), which you give by sending it, and, for comments you publish, because you have made it public (Article 9(2)(e)). You can withdraw consent by asking us to delete it.
How we weigh legitimate interests
Before relying on legitimate interests, we consider what you would reasonably expect and keep the use narrow. For example, request logs are kept only briefly and used only for security and reliability; the analytics we use sets no cookie, records your location only down to the city, and discards each visitor's session after 24 hours; and a listing shows only the practitioners a clinic names on its own website. You can ask us for more detail about how we weighed any of these.
What you have to give us
You never have to give us personal information to read the sites. To use the contact form, you need to give a name, an email address, and a message, because we need them to reply. To open an account, you need an email address and a password. If you would rather not give them, we cannot answer you or open the account, but everything else on the sites works the same.
9. Sensitive information
Some laws give extra protection to certain kinds of personal information. On our sites, two kinds can arise:
- Account sign-in details. Your email address together with your password. We never see or store the password itself, only a hash of it.
- Health information you choose to share. A condition, symptom, treatment, medication, or experience that you mention in a message, a comment, or a clinic claim. European and UK law treat this as special category data, California law treats it as sensitive personal information, and Washington, Nevada, and Connecticut law treat it as consumer health data.
We never ask you to send us health information, and no form that sends anything to us has a field for it. In the questions for your doctor, you can check health situations, but what you check stays in your browser and never reaches us (section 3). We do not infer anything about your health from the pages you read or the questions you ask. We use sensitive information only to provide the services you request, including moderation and security, and never to advertise to you or to build a profile of you. Approved comments are public, so please do not put health details in a comment unless you are comfortable with anyone reading them. Clinics should never send us information about their patients.
We do not ask you to send us other sensitive information, such as your precise location (the clinic finder uses a location you share only inside your browser), government identification numbers, financial account details, biometric data, or information about your race, religion, or sexual orientation. If you include something like that in a message, we use it only to answer you. Our consumer health data privacy policy explains how we handle health information in more detail.
10. Cookies and similar technologies
ebo2.com sets two necessary cookies, ebo2_consent to remember your cookie choices and
ebo2_geo to know whether to show the cookie banner, and app.ebo2.com uses necessary sign-in
cookies. In the European Economic Area, the United Kingdom, Switzerland, Jersey, Guernsey, the Isle of Man,
Gibraltar, Svalbard and Jan Mayen, California, Washington, Nevada, and Connecticut, and wherever we cannot tell
where you are, including a visit from the United States whose state we cannot tell, optional cookies such as
analytics cookies stay off until you opt in through our cookie banner. Elsewhere there is no banner, and optional
cookies are on unless you turn them off. If your browser sends a Global Privacy Control signal, marketing cookies stay off wherever you are. Our
cookie policy lists the cookies we use and explains how to change your choices.
Two other technologies work without cookies. Vercel Web Analytics counts visits on ebo2.com and sets no cookie, so it runs whether or not you accept optional cookies. Vercel BotID has your browser answer an invisible challenge when you sign up on app.ebo2.com; we treat it as necessary because it protects sign-up from abuse. ebo2.com does not use other browser storage, such as local storage, to keep information about you. The tools set no cookies of their own and save nothing you enter in your browser's storage, and opening or downloading a data file sets no cookie (section 3). Today nothing optional is set on either site, because Google's tags are not connected, and we set no advertising cookies.
11. Who we share it with
We do not sell personal information. We share it with the service providers ("processors") below, which handle it on our behalf. Each processor receives only what it needs to provide its service to us. We have no affiliates that receive personal information.
| Processor | What it does for us | What personal information it handles | Where it processes data |
|---|---|---|---|
| Vercel | Hosts both sites, serves the data files and the clinic finder's ZIP code tables, runs the contact form, keeps request logs, and provides Web Analytics, BotID bot detection, and the location lookup for the cookie banner | IP addresses, user agents, the pages and files requested, including the first digit of a ZIP code in the address of a ZIP code table, and times; for Web Analytics, each page view's address, referring page, approximate location down to the city, and browser, operating system, and device type; contact-form messages on their way to Resend; your browser's answer to the bot check at sign-up | United States |
| Supabase | Database and sign-in service for app.ebo2.com | Account data and sign-in sessions, clinic claims, and listing edits; when available, comments and newsletter subscriptions | United States (Amazon Web Services, us-east-2, Ohio) |
| Resend | Delivers contact-form messages to our inbox and sends account emails | Contact-form messages, and your email address for account emails; when the newsletter launches, subscribers' email addresses | United States |
| Google (Google Workspace) | Hosts our email inbox, which stores contact-form messages for up to 24 months | Contact-form messages and our replies | United States and other countries where Google operates |
| Google (Tag Manager and Analytics) | Measures how visitors use ebo2.com, only as you allow: where the cookie banner appears, after you accept; elsewhere, unless you turn it off. Not connected today. | If connected: the pages you view and a cookie identifier | United States and other countries where Google operates |
| Web-reading, cloud browser, and AI research services | A web-reading service, a cloud browser service, and the providers of the AI models our research tools use, read clinics' public websites, published papers, and other public documents for our directory and our research, and copy out the facts and exact words we record | Only what those public pages and documents show, such as the names and credentials of the clinicians a clinic names, a clinic's business phone number and email address, and the people a public document names. Nothing about you as a reader or account holder. | United States and other countries where they operate |
Personal information also reaches others in these cases:
- The public. When comments launch, approved comments will be shown publicly on the sites. Changes to a clinic's listing that we approve are published as part of that listing. Our directory, regulatory tracker, and data files are public, and the data files are published under CC BY 4.0, so anyone may copy and reuse the names they contain (section 6).
- Services your browser connects to. When you open a clinic page, your browser loads the map's tiles from OpenStreetMap, which receives your IP address directly from your browser. OpenStreetMap is an independent service, not our processor, and its own privacy policy applies. The same is true of any other website that you visit by following a link from the sites.
- Legal requirements. We may disclose information when the law requires it, such as in response to a valid court order.
- Business transfers. If the sites or their operator are sold or merged, personal information may transfer to the successor, and it will remain protected by this policy. We will post a notice on the sites if that happens.
12. No sale or sharing of personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as California law defines those terms. We do not sell it or process it for targeted advertising as other states' privacy laws define those terms, and we do not sell consumer health data. In the 12 months before the date at the top of this policy, and at any time since the sites launched in September 2026, we have not sold or shared any category of personal information, including the personal information of people under 16.
We run no ads and let no advertising network collect information on the sites. We offer no financial incentive, discount, or reward in exchange for personal information. Because we do not sell or share, there is nothing you need to opt out of. If your browser sends a Global Privacy Control signal, we treat it as an opt-out request anyway (section 27), and you can also send us an opt-out request through the contact form. If we ever wanted to start selling or sharing personal information, we would first change this policy under section 30 and give you a way to opt out before the change applied to you.
13. How long we keep it
We keep personal information only as long as we need it for the purposes described above. Each period below reflects how long the information stays useful for its purpose, how long a question about it could reasonably come back, such as a correction request about a listing, and what the law requires.
| Information | How long we keep it |
|---|---|
| Contact-form messages, including privacy requests | Up to 24 months in our inbox, or less if you ask us to delete them sooner |
| Request logs | Briefly, under Vercel's retention settings |
| Requests for a clinic finder ZIP code table, which show the first digit of a ZIP code | As request logs: briefly, under Vercel's retention settings |
| What you enter in the tools, including a location you share with the clinic finder | We keep none of it: it stays in your browser and never reaches us |
| Web Analytics | No cookie is set. Vercel discards each visitor's session after 24 hours and keeps the visit records under its retention settings |
| Your browser's answer to the bot check at sign-up | We do not keep it; Vercel uses it for the check |
Your cookie choices (ebo2_consent) | 12 months, after which the banner asks again where it applies |
Your location for the cookie banner (ebo2_geo) | 1 day in your browser, renewed on each page you open; not stored on our servers |
| Google Analytics cookies (when connected) | Up to 2 years, unless you withdraw consent or delete them sooner |
| Account data, including your terms-acceptance record | While your account is open. When you ask us to close your account, we delete it. |
| Sign-in cookies | Until you sign out or they expire, at most 400 days |
| Comments (when available) | Until you or we delete the comment, or your account is closed. The keyed IP hash is kept with the comment. |
| Clinic claims and listing edits | While your account is open. Details published on a listing stay part of it until the clinic or we change them. |
| Records of moderation decisions (when available) | Kept as our record of each decision, including after the comment or account is deleted. They show what was decided, when, by whom on our team, and any note, but not the text of your comment or your email address. |
| Newsletter (when available) | While you are subscribed. After you unsubscribe, we keep your email address and unsubscribed status only so that we do not email you again. |
| Clinicians' names and credentials in listings | While the clinic's own website shows them, as of our last check. A listing can be published only if it was checked against the clinic's website within the previous 180 days. |
| Names in regulatory records and in the data files | While the record is published. When we correct or remove one, the change reaches the files at the next update of the site; copies that others have already downloaded are outside our control. |
| Backups of the app database | Overwritten on a rolling schedule within 30 days |
Copies of deleted information may remain in backups for a limited time. Backups of the app database are overwritten on a rolling schedule within 30 days. We keep information longer when the law requires it, and we tell you if that affects a request you make.
14. How we protect it
We protect personal information with measures that include these:
- Encrypted connections. Both sites are served only over HTTPS. ebo2.com also tells browsers to use only encrypted connections for ebo2.com and its subdomains, including app.ebo2.com.
- Less data in the first place. Reading the sites needs no account, and contact-form messages travel by email rather than being stored in a database.
- Hashes instead of secrets. Passwords are stored only as hashes, and commenters' IP addresses will be stored only as keyed hashes, made with a secret key so that the address itself is never kept.
- Access rules in the database. In the app database, access rules limit each account to its own records, only staff accounts can see moderation queues and other people's submissions, and the public can read only approved comments, never the IP hash or moderators' notes. Account roles limit who can see and change data in app.ebo2.com, and moderation decisions are logged.
- Protection against abuse. Sign-up is protected by bot detection. The contact form limits the length of each field and removes characters that could be used to tamper with the email it sends.
- Safer pages. ebo2.com's pages cannot be shown inside another website's frame, and when you follow a link from ebo2.com to another site, your browser tells that site only that you came from ebo2.com, not which page you were reading. Every page of ebo2.com tells your browser that it may not use your camera or microphone, and every page except the clinic finder tells it that the page may not ask for your location.
- Work done in your browser. The tools compute their results in your browser, so what you enter in them, including a location you share, never reaches our servers and cannot be exposed there. The one exception is the first digit of a ZIP code, which the clinic finder's table request shows.
- Keys kept out of our code. The keys our services use to talk to each other are kept in our hosting provider's settings, not in the code of the sites.
No website is completely secure, so we cannot guarantee the security of your information. If a security breach affects your personal information, we will notify you and the authorities as the law requires; section 28 explains what we would do. You can help by using a strong password that you do not use anywhere else, and by telling us promptly if you think someone has used your account.
15. Automated decisions
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects, and we do not use personal information for profiling. People on our team read every message we receive, and when comments launch, a person will review each one before it is published. A claim of a clinic listing is approved automatically when the account's confirmed email address is on the clinic's own website domain; a person on our team can withdraw any claim, and anyone without such an address can ask us to check another way. Services and descriptions a clinic proposes are approved by a person before they appear.
A few simple automatic checks keep the sites working. None of them judges you as a person:
- The bot check at sign-up. Vercel BotID decides whether a sign-up looks automated. If it does, the sign-up is blocked with a message asking you to try again from a regular web browser. If that happens to you, write to us through the contact form and a person will look into it.
- The contact form's spam trap. The form has a hidden field that people do not see. If it is filled in, which usually means a program sent the form, the message is discarded. The form also checks that the required fields are filled in and lists anything you need to fix.
- The cookie banner's location rule. Whether the banner asks you first depends only on the country and state or region your connection appears to come from, as section 10 describes.
The tools work out a result from what you enter, in your browser. They make no decision about you: the price check describes where a number falls, the planner adds up your numbers, the clinic finder sorts clinics by distance, and the questions for your doctor lists questions. None of their results reaches us or anyone else.
16. International transfers
We are based in the United States. The processors that handle information about you, Vercel, Supabase, Resend, and Google, process it in the United States, and Google may also process it in other countries where it operates; the web-reading, cloud browser, and AI research services in section 11 receive nothing about you. If you use the sites from the EEA or the UK, your personal information is transferred to the United States and, through Google, possibly to other countries. For those transfers, we rely on the EU-U.S. Data Privacy Framework and its UK extension where the recipient participates in them, or on standard contractual clauses. To ask about the safeguards for a particular transfer, contact us.
The Data Privacy Framework is a program in which US companies commit to protecting personal information that comes from Europe, and the European Commission and the UK government have recognized it as giving adequate protection. Standard contractual clauses are contract terms, approved by the European Commission and, for the UK, by UK authorities, in which the recipient promises to protect the information to European standards. Where we rely on them, you can ask us for a copy; we may remove commercial details that are not about your information.
Letters you send us are handled in the United States. When you open a clinic page, your browser loads its map from OpenStreetMap directly, so that transfer happens between you and OpenStreetMap, whose own policy explains where it processes data.
17. Your rights
Your rights depend on where you live. Some rights have exceptions, and we will tell you if one applies to your request. Depending on the law that applies to you, you can:
- find out whether we hold personal information about you, and get a copy of it;
- have inaccurate or incomplete information corrected;
- have your information deleted;
- receive the information you gave us in a format you can take elsewhere;
- opt out of the sale of personal information, its sharing for cross-context behavioral advertising, targeted advertising, and profiling, none of which we do;
- limit our use of sensitive information;
- object to or restrict some uses of your information, where European or UK law applies;
- withdraw any consent you gave; and
- appeal if we decline your request, and complain to a regulator.
Section 18 explains what each right gets you, section 19 explains how to use it, and sections 22 to 25 describe what the laws of California, Nevada, other US states, the EEA, and the UK add. Requests are free. We will not deny you service, charge you a different price, or give you a lower quality of service because you made a request.
18. How each right works
Access and the right to know
If you ask for access, we tell you whether we hold personal information about you and send you a copy in a form you can read, usually by email. That can include the messages you sent us, your account data and terms-acceptance record, your clinic claims and listing edits, and, once comments launch, your comments. Where a US state law gives you the right to know, we also tell you the categories of information we collected, where it came from, why we collected it, and the categories of recipients, as section 22 sets out. For consumer health data, we include the list of processors that received it and how to contact them.
Deletion
If you ask us to delete your information, we delete it from our inbox and our app database and ask our processors to delete any copy they hold for us. If you ask us to close your account, we delete its account data along with the comments, clinic claims, and listing edits linked to it. Copies in our database backups are overwritten within 30 days. Some things stay: changes we have already published to a clinic's listing, the records of moderation decisions described in section 13, copies that other people or services made of anything that was public, and information the law requires us to keep. We tell you when the deletion is done and what, if anything, we kept and why.
Correction
Tell us what is wrong and what it should say. Until you can edit your profile in the app yourself, we correct account details for you; before we change the email address on an account, we may ask you to confirm the new one. Information about a clinic is corrected when the clinic's own website shows the right information, as our terms of use explain.
Portability
For information you gave us, such as your account data and, once available, your comments, we can send you a copy in a structured, commonly used, machine-readable format. Where European or UK law gives you this right and it is technically feasible, we can send it to another organization you name.
Opting out of sale, sharing, targeted advertising, and profiling
We do none of these (section 12). You can still send an opt-out request, and we treat a Global Privacy Control signal from your browser as one (section 27). You do not need to prove who you are to opt out.
Limiting the use of sensitive information
We already use sensitive information only to provide the services you request, including moderation and security (section 9). You can still ask us to limit its use, and we will confirm in writing how we use it.
Objecting and restricting, in the EEA and the UK
Where we rely on legitimate interests, you can object, and we will stop unless we have compelling grounds that override your interests or need the information for legal claims. You can also ask us to restrict the use of your information while we check its accuracy or consider an objection, or when you need us to keep it but not use it.
Withdrawing consent
For cookies, change your choice in the cookie banner (section 26); for the newsletter, once it launches, unsubscribe; for health details you sent us, ask us to delete them. Withdrawing consent stops any further use based on it. It does not undo what happened before, such as a comment that others read while it was public.
19. How to make a request
- Send a request through the contact form, choosing "Privacy or data request," or write to us at EBO2.com, 1968 S. Coast Hwy, #1921, Laguna Beach, CA 92651, United States.
- Tell us which right you want to use, which site your request concerns, and the email address you used with us, so that we can find your information. If your request is about a comment or a listing, include a link to the page.
- We confirm your identity, as described below.
- We act on the request and reply in writing, usually by email, within the times below.
Confirming your identity
Before we act, we may need to confirm your identity, for example by checking that you control the email address involved. We use information you give us for that check only to verify your request. We ask for no more than we need: usually a reply from the email address we already have is enough. If we cannot confirm who you are, we tell you why and what would let us go ahead.
Authorized agents
You can have an authorized agent make a request for you. We may ask the agent for proof that you gave it permission, and we may ask you to confirm your identity with us directly.
Timing
For requests under US state privacy laws, and any other request that the GDPR and the UK GDPR do not cover, we respond within 45 days of receiving your request. If we need more time, we may extend that once, by up to 45 more days, and we will tell you before the first 45 days end. If the GDPR or the UK GDPR applies, we respond within one month. For complex or numerous requests we may extend that by up to two more months, and we will tell you within the first month.
What we send back
Our reply says what we did: for access and portability, it includes the copy of your information; for deletion, it confirms when the deletion was done and anything we kept and why; for correction, it says what we changed. If we decline any part of a request, the reply gives the reason and explains how to appeal.
20. Appeals and complaints
If we decline your request, in whole or in part, we will tell you why. You can appeal by replying to our decision. We answer appeals in writing within 45 days. If we deny your appeal, we will tell you how to submit a complaint to your state attorney general.
In your appeal, tell us which request it concerns and why you think our decision was wrong. We look at the whole request again, not only the point you raise, and our written answer says what we decided and why.
You can also complain to a regulator at any time, whether or not you have appealed:
- In the EEA: the data protection authority where you live or work, or where you think the problem happened. The European Data Protection Board lists them on its members page.
- In the UK: the Information Commissioner's Office, through its complaint page.
- In California: the California Privacy Protection Agency, through its complaint form, or the Attorney General, through its consumer complaint page.
- In Washington, Nevada, and Connecticut: the Attorney General, through the complaint pages listed in our consumer health data privacy policy.
- In any other US state: your state attorney general.
21. Children
The sites are not directed to children under 16, and we do not knowingly collect personal information from them. You must be 18 or older to create an account on app.ebo2.com, and the sign-up form asks you to confirm that you are. If you believe that a child under 16 has given us personal information, contact us and we will delete it.
If you are a parent or guardian and think your child has sent us a message, tell us through the contact form. We need only enough detail to find the message, not more information about the child. If we learn that an account belongs to someone under 18, we close it and delete its account data and everything linked to it. We do not sell or share anyone's personal information, including that of people under 16.
22. California residents
This section describes our practices in the terms that California's privacy law, the California Consumer Privacy Act as amended by the California Privacy Rights Act, uses. It adds to the rest of this policy.
In the categories of the California Consumer Privacy Act, we collect identifiers (such as your name, email address, and IP address); internet or other electronic network activity (such as the pages your browser requests, your browser type, and, only with your consent, analytics data); and sensitive personal information (your account login, meaning your email address and password, and any health information you choose to share). We collect this information from you and from your browser, for the purposes in section 7, and we disclose it for business purposes to the processors listed in section 11 that handle information about you, as the table below shows. We do not sell or share personal information, as the law defines those terms, and we have not done so since the sites launched in September 2026. We use consumer health data and account credentials, which are sensitive personal information, only to provide the services you request, including moderation and security, not to draw conclusions about you.
| Category | What it covers on our sites | Disclosed for a business purpose to | Sold or shared |
|---|---|---|---|
| Identifiers | Your name, email address, and IP address, and the random ID our database gives your account | Vercel, Supabase, Resend, and Google (our inbox) | No |
| Internet or other electronic network activity | The pages your browser requests and your browser type; Vercel Web Analytics' records of each page view, with the referring page, browser, operating system, and device type; Google Analytics data only if connected and allowed | Vercel; Google only if connected and allowed | No |
| Geolocation data | Approximate: the country and state or region worked out from your IP address for the cookie banner, the location down to the city that Vercel Web Analytics records with each page view, and the first digit of a ZIP code in the address of a clinic finder ZIP code table. A precise location you share with the clinic finder stays in your browser and never reaches us. | Vercel | No |
| Professional information | Your connection to a clinic, if you contact us for one or claim its listing | Vercel, Resend, Google (our inbox), and Supabase | No |
| Sensitive personal information | Your account login, and health information you choose to share | Vercel and Supabase; for health details in a message, also Resend and Google (our inbox) | No |
| Inferences | None: we draw no conclusions about you | Not applicable | No |
Section 13 says how long we keep each kind of information. You have the rights to know, access, delete, and correct your personal information, to opt out of its sale and sharing, to limit the use of sensitive personal information, and not to be discriminated against for using these rights; sections 18 and 19 explain how. An authorized agent can make a request for you with your signed permission, and we may ask you to confirm your identity with us directly, unless the agent holds a power of attorney under the California Probate Code.
California's "Shine the Light" law (Civil Code section 1798.83) lets California residents ask which personal information a business disclosed to third parties for their own direct marketing. We make no such disclosures. Section 27 explains how we respond to Do Not Track and Global Privacy Control signals.
23. Nevada residents
Nevada law lets consumers ask the operator of a website not to sell the covered information it collects about them, such as a name or an email address. We do not sell covered information, as Nevada law defines a sale. You can still send us a request through the contact form, choosing "Privacy or data request," and we will confirm it in writing within the times in section 19.
The covered information we collect is described in section 2, the processors we share it with are listed in section 11, you can review and ask us to correct it as section 18 explains, and section 30 explains how we tell you about changes to this policy. No third party collects covered information about your online activity over time and across websites through our sites today. Nevada's consumer health data law, Senate Bill 370, is covered by our consumer health data privacy policy.
24. Residents of other US states
Many states, including Colorado, Connecticut, Oregon, Texas, and Virginia, have comprehensive consumer privacy laws. Where one applies to you, it gives you the rights described in section 17: to confirm whether we process your personal data and to access it, to correct it, to delete it, to get a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. We do none of the things those opt-outs cover.
Several of these laws require consent before a business processes sensitive data, such as health information. Health information reaches us only when you choose to send it, and we use it only for the purpose you sent it for: to answer your message, review your comment, or handle your claim. Anything beyond that would need your separate consent first. If we decline your request, you can appeal as section 20 describes, and if we deny your appeal, you can contact your state attorney general. Washington, Nevada, and Connecticut also have consumer health data laws, which our consumer health data privacy policy covers.
25. If you are in the EEA or the UK
EBO2.com is the controller of your personal information, and you can reach us as section 1 explains. Section 8 sets out our legal bases, and section 16 our safeguards for transfers to the United States. If the GDPR or the UK GDPR applies to you, you have the right to:
- access the personal information we hold about you and get a copy of it;
- have inaccurate or incomplete information corrected;
- have your information deleted;
- restrict how we use it;
- receive the information you gave us in a structured, machine-readable format, and have it sent to another organization where that is technically feasible;
- object to our use of your information based on legitimate interests;
- withdraw your consent at any time, without affecting our use of your information before you withdrew it; and
- complain to a data protection authority, such as the one where you live or work. In the UK, that is the Information Commissioner's Office.
We answer within one month, as section 19 explains. We would welcome the chance to put things right first, so please tell us about a concern before you complain, but you do not have to.
26. Your choices
Cookies. Where our cookie banner appears, optional cookies stay off until you turn them on. Wherever you are, you can change your choice at any time. This button opens the cookie banner, as do the "Cookie settings" and "Your privacy choices" links at the bottom of every ebo2.com page:
If you turn analytics or marketing off after allowing it, we delete Google's cookies on ebo2.com and tell
Google's tags to stop using that kind of storage, and once both are off, Google's tags no longer load on the
pages you visit. The banner needs JavaScript. If JavaScript is off in your browser, the button above does
nothing, but the banner does not appear either, and no optional cookies are set and no tags load. You can also
delete or block cookies in your browser's settings. If you delete the ebo2_consent cookie, the
banner will ask you again where it applies.
Email. Account emails, such as sign-up confirmations and password resets, are part of running your account. When the newsletter launches, you will be able to unsubscribe at any time.
Your account. To close your account and have its data deleted, send a privacy request through the contact form.
What you share. You decide what goes into a message and, once comments launch, into a comment. You can read every page of ebo2.com without an account and without giving us your name or email address, and you can leave clinic maps unloaded.
Location. The clinic finder works without your location: search by ZIP code instead. If you have allowed it to use your location, you can withdraw that permission at any time in your browser's settings for ebo2.com, and your browser will apply the new setting the next time you press "Use my location."
27. Global Privacy Control and Do Not Track
Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of the sale of your personal information, its sharing for cross-context behavioral advertising, and targeted advertising, even though we do none of these. Our cookie banner also keeps marketing cookies off, and they cannot be turned on while your browser sends the signal. Where the banner appears, analytics cookies still need your opt-in; elsewhere, you can turn them off with the button in section 26. The banner reads the signal each time a page loads, and we do not store it.
Do Not Track. The sites do not respond to the older Do Not Track browser setting. They honor Global Privacy Control instead.
Tracking across websites. Today, no third party collects personal information about your activity over time and across different websites through our sites. If we connect Google's tags in the future, that could happen only as section 2 describes: where the banner appears, after you accept analytics or marketing cookies; elsewhere, unless you turn them off.
28. If there is a data breach
If we learn that personal information we hold has been accessed, disclosed, or lost without authorization, we will work to stop it, find out what happened and whose information was involved, and fix the cause. If the breach affects your personal information, we will notify you, and the authorities where the law requires, within the time the law sets.
Our notice will say what happened, what information was involved, what we have done about it, and what you can do to protect yourself, such as changing a password that you also use elsewhere. We will send it to the email address we have for you or, where the law allows, post a notice on the sites. If you think your account or your information has been misused, tell us through the contact form so that we can look into it.
29. Consumer health data
Some information you give us, such as a health condition or treatment that you mention in a comment, a message, or a clinic claim, may be consumer health data under Washington's My Health My Data Act, Nevada's Senate Bill 370, and Connecticut's data privacy law. Our consumer health data privacy policy explains what we collect, how we use and share it, and your rights.
In short: today, consumer health data reaches us only when you choose to send it; we use it only to provide what you asked for; we never sell it; and we do not use geofencing around places that provide health care. The situations you check in the questions for your doctor, and a location you share with the clinic finder to find clinics near you, stay in your browser and never reach us (section 3). That policy also links to the attorney general complaint pages for each of those states. Where it and this policy differ on consumer health data, that policy controls.
30. Changes to this policy
We may update this policy from time to time. When we do, we will post the new version on this page and change the date at the top, and the change history below lists each update. If a change is material, it takes effect no sooner than 30 days after we post it, and we will post a notice on the sites and email account holders before then. If a change requires your consent under the law, such as a new kind of optional cookie, we will ask for it before the change applies to you.
For this policy, a material change includes collecting a new kind of personal information, using it for a new purpose, or sharing it with a new kind of recipient. We will send you any earlier version of this policy on request.
31. Contact
For privacy questions or requests, use the contact form and choose "Privacy or data request," or write to EBO2.com, 1968 S. Coast Hwy, #1921, Laguna Beach, CA 92651, United States.
Change history
- October 10, 2026: clinics can now claim their listing at app.ebo2.com. Sections 2, 4, 11, 13, and 15 describe what a claim and a clinic's listing details record, which details appear on the listing at once and which a person approves first, and that a claim is approved automatically when the account's confirmed email address is on the clinic's website domain. This describes the feature at its launch; it does not change how we use information we already held.
- October 6, 2026: clinic pages now show their map without a "Show map" step: your browser loads the map's tiles from OpenStreetMap when you open a clinic page, so OpenStreetMap receives your IP address then. Sections 2, 4, 11, and 16 say so, and the legal basis for the map is now our legitimate interest in showing where a clinic is.
- October 4, 2026: section 11 now also lists a cloud browser service, which loads clinics' public websites so that we can check the facts we show are still on them. Like the web-reading service, it receives nothing about readers or account holders.
- October 3, 2026: section 11 now also lists the web-reading service and the AI model providers that read clinics' public websites, published papers, and other public documents for our directory and our research. They already did this work, and they receive nothing about readers or account holders. The policy now lists what Vercel Web Analytics records with each page view, as Vercel's documentation describes it, and says that Vercel discards each visitor's session after 24 hours, where it said before that a hash resets every day. It describes Vercel BotID's check as an invisible challenge your browser answers, and it no longer names a data center for Resend, which we have not confirmed. The cookie banner now also asks first in Jersey, Guernsey, the Isle of Man, Gibraltar, and Svalbard and Jan Mayen, and, as this policy already said, it asks first when we can tell that a visit comes from the United States but not from which state; until this update, such a visit got no banner.
- October 2, 2026 (second update that day): added section 3, on the tools, the reports, and the data downloads, which went live before this update, and section 6, on the people named in our listings, regulatory records, and data files, with a way to ask for a correction, an update, or removal. The policy now says exactly what leaves your browser when you use a tool: nothing you enter, except the first digit of a ZIP code in the address of the clinic finder's ZIP code table. It explains how "Use my location" works, and it states facts about location and health in place of broader statements that we do not collect them. The tables, processors, retention schedule, security measures, and the sections on sensitive information, cookies, and consumer health data now cover the tools and the downloads. Sections from 3 onward were renumbered.
- October 2, 2026: expanded every section with more detail; no change to how we handle your information. The policy now also describes information we already handled the same way but did not mention before: the clinicians' names and credentials that appear in listings and in the public records our guides and reports cite, and the records our moderators keep of their decisions. We also corrected two places that said Google's tags, if we connect them, would work only after you accept cookies: outside the places where our banner appears, they would load unless you turn them off, as the rest of this policy already said.
- September 26, 2026: the cookie banner now appears only in the European Economic Area, the United Kingdom, Switzerland, California, Washington, Nevada, and Connecticut, and wherever we cannot tell where you are; elsewhere, optional cookies are on until you turn them off.
- September 25, 2026: first published.