Skip to content
everlon

Legal

Privacy Policy

How we collect, use, and protect your personal information.

Effective date: September 19, 2026

Company: Everlon Health LLC ("Everlon," "we," "us," "our")

IMPORTANT — this is not the document that governs your medical information. The Notice of Privacy Practices is a separate document that governs how protected health information ("PHI") about you may be used and disclosed in connection with your health care, under the Health Insurance Portability and Accountability Act ("HIPAA"). This Privacy Policy covers the other information we collect through our website and communications.

1. Scope; relationship to HIPAA

This Policy covers information collected through everlonhealth.com and our Services. Protected Health Information ("PHI") handled in connection with your care is also governed by the applicable HIPAA Notice of Privacy Practices and federal/state health-privacy law; where they conflict as to PHI, the HIPAA Notice and applicable law control.

2. Information we collect

  • You provide: name, contact details, date of birth, health/intake information, payment information, communications.
  • Identity verification: before you receive any health care service, we are required to verify your identity, and where identity cannot be verified, we do not provide health care services. During intake we collect the number and issuing state (or, for a passport, the issuing country) of a government-issued ID — driver's license, state ID, or passport — you provide, which are transmitted to the telehealth platform vendor that maintains your patient record on our behalf, under a Business Associate Agreement. We do not request Social Security numbers. Identity-document data is kept only as long as needed to verify you and to satisfy recordkeeping obligations. Everlon does not store your ID number.
  • Photos you upload: photos of current medications or prescriptions you choose to share with your provider during intake.
  • Automatically: device and usage data, IP address, and information from cookies and similar technologies — including, if you arrive through a marketing link, the campaign and referral tags described in Section 5.
  • From providers and partner pharmacies: treatment, prescription, and fulfillment information needed to provide the Services.

3. How we use information

To operate and improve the Services, connect you with providers and pharmacies, process payments and shipping, communicate with you, provide support, comply with law, and prevent fraud and misuse.

4. How we share information

  • Independent licensed providers and licensed partner pharmacies to deliver care and fulfill prescriptions.
  • Licensed laboratories, where your provider orders lab work — they receive the information needed to perform the testing and report results to your provider.
  • E-prescribing networks used to route prescriptions from your provider to the pharmacy.
  • Service providers (hosting, payment processing, communications, technology platform) under contracts — and, where PHI is involved, Business Associate Agreements.
  • Legal/safety disclosures required or permitted by law.
  • Business transfers (merger, acquisition).
  • We do not sell your personal information or PHI, and we do not share PHI or identifiable health information with advertising platforms.
  • Our platform vendor is contractually barred from marketing to you. Under our agreement, the telehealth platform that maintains your patient record on our behalf may not contact, market to, or solicit you for any purpose outside providing the Services, and may not de-identify, aggregate, sell, license, or transfer any data derived from you without our separate prior written consent. It retains no right to use or transfer that data if our agreement ends.

5. Health data & advertising

We do not disclose your health information to any third-party advertising or analytics platform. That includes your intake responses, health conditions, prescriptions, lab results, and the fact that you use or have inquired about Everlon — and it applies to any purpose, ours or theirs. Hashed or pseudonymized identifiers are still personal information under this promise.

Non-health information. We use first-party website analytics and marketing attribution that we operate ourselves. No third-party advertising or analytics network receives it. If you arrive through a link that carries campaign or referral tags, we may store those tags — campaign source, medium, name, term, and content, and a partner referral code — together with the page you landed on, the time of your first visit, and a coarse device type (phone, tablet, or computer), in a first-party cookie on your device and, if you later create an account or start a health review, in our own records. This information never includes your health information, is never combined with your health information for advertising, and is never sent to an advertising platform. You can opt out at any time using the "Privacy choices" link in the site footer, and we honor the Global Privacy Control signal. We do not use third-party advertising pixels or tags; if we ever introduce one, it will load only with your prior consent, and never on pages that handle health information.

6. Cookies and tracking

We use cookies in three ways:

  • Essential cookies — signing you in, keeping your session secure, and remembering your privacy choices. These are required for the site to work and cannot be switched off.
  • First-party analytics and attribution cookies — the campaign and referral cookie described in Section 5 (kept for up to 90 days), set only on marketing pages and only when your privacy choices allow it.
  • Third-party advertising cookieswe do not use any. If we ever introduce one, it will be loaded only with your prior consent.

You can manage cookies through your browser and through the "Privacy choices" link in the site footer, which reopens our consent tool at any time. We honor recognized opt-out preference signals, including Global Privacy Control: when your browser sends one, non-essential data use is off unless you expressly allow it.

7. Your privacy rights

Depending on your state, you may have rights to access, correct, delete, or obtain a copy of your personal information, to opt out of sale/sharing/targeted advertising, and to limit use of sensitive information. Health information may carry additional protections.

California residents (CCPA/CPRA)

Important scope limit. Your rights under the CCPA do not apply to all information we collect. The CCPA does not apply to protected health information governed by HIPAA, to "medical information" governed by the California Confidentiality of Medical Information Act ("CMIA"), or to other patient information we maintain in the same manner as PHI or medical information. Your intake responses, health history, treatment information, prescriptions, and lab results are governed by HIPAA, CMIA, and the Notice of Privacy Practices — not by the CCPA rights described here.

Categories of personal information covered by the CCPA. In the preceding twelve months we have collected the following CCPA-covered categories:

  • Identifiers — name, postal address, email address, telephone number, account identifiers, IP address, and cookie identifiers
  • Characteristics of protected classifications — such as age and gender
  • Commercial information — products or services purchased or considered
  • Internet or other electronic network activity — browsing and interaction with our site
  • Geolocation data — approximate location derived from IP address
  • Audio or electronic information — if you contact customer support
  • Inferences drawn from the above

Your CCPA rights. California residents have the right to know and access the personal information we collect, use, and disclose about them in the preceding twelve months; to request deletion; to request correction; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights.

Sensitive personal information. Of the categories above, the CCPA treats the following as sensitive: government identifiers such as the number of a government-issued ID — driver's license, state ID, or passport; account log-in or financial-account credentials; precise geolocation; racial or ethnic origin, religious or philosophical beliefs, and union membership; the contents of mail, email, and text messages where we are not the intended recipient; genetic data; biometric information processed to identify you; and information concerning health or sex life. We use sensitive personal information only to provide the Services you requested, to verify your identity, and to keep the Services secure — not to infer characteristics about you and not for advertising.

We do not sell or share personal information as those terms are defined by the CCPA. If that ever changes — including through the use of advertising or analytics technologies — we will update this Policy and provide the required opt-out mechanisms before doing so.

Limits on deletion. We will delete personal information on request, except where we must keep it to: complete a transaction or provide a service you requested; detect security incidents or protect against fraudulent or illegal activity; debug and repair errors; comply with a legal obligation — including medical-record retention requirements, which generally require us to keep treatment records for years after your last visit; or make other internal, lawful uses compatible with the context in which you provided it. Where we cannot delete, we will tell you why.

Request limits, timing, and format. You may make an access or portability request twice in any 12-month period. We respond within 45 days, and where more time is needed we will tell you in writing and may take up to 90 days total. Disclosures cover the 12 months preceding your request. Portability responses are provided in a readily usable format. We do not charge for responding unless a request is excessive, repetitive, or manifestly unfounded — in which case we will give you a cost estimate and our reasoning before proceeding, and may decline.

Non-discrimination, specifically. We will not deny you goods or services, charge you a different price or rate (including through discounts or penalties), provide you a different level or quality of service, or suggest that you will receive any of those, because you exercised a privacy right.

How to exercise your rights. Contact care@everlon.health. We will verify your identity before responding, and we respond within the time required by your state's law (generally within 45 days, with a permitted extension where the law allows). To verify you, we may use the name, email address, and phone number associated with your request, may contact you to confirm, and in some cases may ask you to declare under penalty of perjury that you are the person whose information is the subject of the request.

Authorized agents. You may designate an authorized agent to make a request on your behalf. To do so, you or your agent must provide one of the following: (a) proof that the agent is registered with the California Secretary of State together with your written authorization; (b) evidence of a power of attorney granted under the California Probate Code; or (c) your written, signed permission for the agent to act on your behalf — in which case we may also verify your identity directly with you and ask you to confirm that you authorized the request. We may deny a request from an agent who does not provide sufficient proof of authority.

Appeals. If we decline all or part of a rights request, you may appeal by replying to our decision or emailing care@everlon.health with "Privacy Appeal" in the subject line. We will respond to appeals within the period your state's law requires, and, where applicable, we will tell you how to contact your state Attorney General if you disagree with the appeal outcome.

Consumer health data (Washington and Nevada residents)

Washington's My Health My Data Act and Nevada's consumer-health-data law give residents of those states additional rights over "consumer health data." We do not sell consumer health data, and we do not share it for advertising (see Section 5). Where those laws apply to you, you may ask what consumer health data we have collected, ask us to delete it, and withdraw any consent you previously gave, by emailing care@everlon.health with "Consumer Health Data Request" in the subject line. We will verify your request and respond within the time your state's law requires, and you may appeal our decision as described above. Health information handled as part of your medical care remains governed by HIPAA and the Notice of Privacy Practices.

8. Data security

We use administrative, technical, and physical safeguards to protect information. No method of transmission or storage is 100% secure.

On your own device. When you use the Services on a phone or computer, information — including health information — may be stored on that device, in some cases unencrypted. We use safeguards designed to limit this, but we cannot guarantee them. Keep your device locked, keep your account password confidential, and sign out on shared devices.

9. Data retention

We retain the information we hold for as long as necessary to provide the Services and to meet legal, tax, and regulatory obligations, and then delete or de-identify it. Records of your medical care are created and maintained in the secure health-record system of the telehealth platform and your care team. Medical records are retained according to the schedules state law sets for the clinicians and entities that create them (commonly seven to ten years). You may request copies of your records at any time, as described in the Notice of Privacy Practices.

10. Children

The Services are for adults 18+. We do not knowingly collect information from minors.

11. Changes; contact

We may update this Policy; material changes will be posted with a new effective date. Everlon Health LLC · 2108 N St, Ste N, Sacramento, CA 95816 · care@everlon.health


Questions? Contact us at care@everlon.health.