Your privacy is not negotiable
AXVO collects nothing it doesn't need. We have never sold data, we never will, and we've built the system to make that structurally impossible.
Last updated: April 2026 · Version 1.2
Full policy
This policy applies to axvohealth.org and all AXVO-branded services. Click any section to expand.
AXVO is built on a core principle: we collect the minimum possible data to give you the best results.
When you search for a clinic, we use your city, ZIP code, or coordinates to return nearby results. This location data is used only during your active session and is never stored on our servers.
When you use our eligibility screener, your answers (income range, household size, insurance status) are processed in your browser. We do not transmit or store your eligibility quiz responses.
If you submit a community story, we collect only the name and city you provide, plus the story text. This is reviewed before publishing and stored securely.
If you create an account (optional), we store your email address, display name, and any profile information you choose to add. Account data is stored in Supabase with row-level security — only you can access your own records.
We do not collect: Social Security numbers, health records, medical history, biometric data, or any information that identifies you as a patient.
Your data is used exclusively to deliver the service you asked for.
Location data is used to filter and sort nearby clinics. It is never stored, never sold, and never shared with third parties.
Aggregated, anonymized analytics (e.g., "500 people searched for mental health clinics in Phoenix this month") may be used to improve our clinic database coverage and inform our impact reporting. No individual can be identified from these aggregates.
If you submit a story, it may be published on the Stories page with only your first name and city, exactly as you entered them. You can request removal at any time by contacting us.
Account data (if you create one) is used to pre-fill forms, save searches, and personalize your experience. We do not use it for advertising, profiling, or sharing.
AXVO integrates with the following third-party services:
HRSA (Health Resources & Services Administration) — Federal API used to retrieve Federally Qualified Health Center (FQHC) data. No user data is sent to HRSA.
OpenStreetMap / Nominatim — Used for geocoding ZIP codes and city names into coordinates. Your location query may be sent to Nominatim's public API. See nominatim.org/privacy for their policy.
Supabase — Used for user account storage and authentication (if you create an account). Supabase is SOC 2 Type II certified. Data is stored in the US. See supabase.com/privacy for their policy.
Vercel — Used for hosting. Vercel may log request metadata (IP addresses, timestamps) per their standard infrastructure logging. See vercel.com/privacy.
We do not use: Google Analytics, Facebook Pixel, advertising trackers, behavioral profiling tools, or any third-party marketing technology.
AXVO uses minimal cookies and local storage.
If you are logged in, a session cookie is used to keep you authenticated. This is a functional cookie and cannot be disabled without logging out.
We use local storage to remember your language preference and any bookmarked clinics. This data never leaves your device.
We do not use third-party tracking cookies. We do not use cookies for advertising or cross-site tracking.
You can clear all AXVO local data by clearing your browser's storage for this domain. If you log out, your session cookie is deleted immediately.
You have the right to:
Access — Request a copy of any personal data we hold about you (account holders only, since anonymous users have no stored data).
Deletion — Delete your account and all associated data at any time from the Profile page, or by contacting us. Deletion is permanent and takes effect within 24 hours.
Correction — Update any incorrect information in your profile at any time.
Portability — Export your data in JSON format from the Profile page.
Opt-out of Story Publishing — Request removal of any published story at any time.
CCPA Rights (California) — California residents may request disclosure of personal information collected, sold, or disclosed. AXVO does not sell personal data.
GDPR Rights (EU residents) — You have rights under GDPR including access, rectification, erasure, restriction, and data portability. Contact us to exercise these rights.
To exercise any right: email privacy@axvohealth.org with "Privacy Request" in the subject line.
We take reasonable and industry-standard measures to protect your data.
All data in transit is encrypted via TLS 1.3. Account data at rest is encrypted using AES-256. Supabase row-level security ensures users can only access their own records. We conduct periodic security reviews.
We do not guarantee absolute security — no system does. If you discover a security vulnerability, please disclose it responsibly to security@axvohealth.org. We will respond within 72 hours.
In the event of a data breach affecting personal information, we will notify affected users within 72 hours as required by law.
Questions about this policy?
If you have questions, concerns, or want to exercise any of your privacy rights, contact us at privacy@axvohealth.org. We respond to all privacy requests within 5 business days.