Ebomi Privacy Policy
Last updated 18 August 2026
Ebomi is an academic research project that emails you when company insiders buy or sell shares. To do that we need your email address, and the list of companies you asked to watch. That is very nearly everything we hold about you.
We do not sell your data. We do not store a password, because Ebomi has no passwords. You can stop the emails or close your account at any time, and closing means we stop writing to you permanently.
The rest of this page is the detail, including the parts that are less flattering.
1. Who we are
Ebomi is run by Dr Attila Balogh personally, a finance academic, as an open research tool. It is built on the insider-trading dataset published in Scientific Data (doi:10.1038/s41597-023-02147-6). There is no company behind it. It operates from Australia, and Australian law governs this policy.
Contact for anything on this page, including a request to see the data we hold about you or to have it deleted: balogh@unimelb.edu.au.
2. What we collect about you
Because you signed up
| What | Why |
|---|---|
| Your email address | It is your account, the address we send your sign-in link to, and the address we send alerts to. Nothing works without it. |
| When your account was created, and when you last signed in | The first is automatic. The second exists for two reasons we should be open about: it lets us count how many people actually use Ebomi, a figure cited in a research grant application, and it tells us whether a sign-in was your first. |
| Which companies you watch | The whole product. This is a list of company tickers you chose. |
| Which alerts we have sent you | So we never send you the same filing twice, and so we can answer you if you ask what we sent. |
| Your plan | Which tier you are on and, if you ever paid, an identifier pointing at Stripe's record. |
We do not collect your name, your postal address, your phone number, your date of birth, or your age. There are no fields for them.
We do not store a password. Ebomi signs you in with a link emailed to you. There is a leftover database column from an older design that holds the literal word "magic" for every account, and no code reads it. We are naming it here rather than letting it look like a hidden credential store.
Because of how the internet works
| What | How long we keep it |
|---|---|
| Your IP address, recorded when you request a sign-in link or apply for the academic tier | 24 hours, then deleted automatically. It is kept to stop the sign-up form being abused to send mail to strangers, which happened to us in August 2026. |
| A one-way digest of your sign-in link, never the link itself | Until it is used or expires. |
If you ask us to stop emailing you
We keep your address on a suppression list, permanently and deliberately. This is the one place where keeping data is the privacy-protecting choice: we cannot promise never to write to you again if we have forgotten who you are. That list is keyed on the address itself, so it also works for people who never had an account.
If you apply for the academic tier
We record the institutional address you claim, the institution, and the decision. The claimed address is replaced by just its domain once verified.
Note that this is the one form on Ebomi where you can type somebody else's address, because verification works by us emailing that address. If you have received a verification email from us that you did not ask for, someone entered your address into that form, and you can tell us at the contact address above.
3. What we do not do
- We do not sell your data, and we do not share it for advertising.
- We do not profile you beyond the list of companies you chose to watch.
- We do not read your email, and we cannot: we send, we do not receive.
4. Research use of usage data
Ebomi is run by an academic, and how people use it is itself of research interest. We may use data about how Ebomi is used in academic research and in published work. We are telling you before we do it rather than afterwards, because consent given after the fact is not consent.
What that would mean in practice:
- Aggregate and de-identified. Counts, patterns and trends, not individuals. Nothing we publish would name you or make you identifiable.
- Never your email address, and never a list tying a named person to the companies they watch.
- Subject to university ethics approval. Research involving data about people goes to a human research ethics committee before it happens, and that is a stricter test than this policy alone.
If you would rather your usage were excluded from research entirely, write to the address above and we will exclude it. You do not have to give a reason and it will not affect your account.
5. Who else sees your data
We use a small number of outside services. Each one is here because the product cannot work without it, and each is listed with what it actually receives.
| Service | What it receives | What for |
|---|---|---|
| Render | Everything, as our hosting provider and the operator of our database. | Running the site. |
| Cloudflare | Every request you make to ebomi.com, including your IP address, the page you asked for, your browser's User-Agent and your cookies. Cloudflare terminates the encryption, so it can see this in the clear. | It is our DNS and our front door, and it filters attacks. |
| Cloudflare Turnstile | Your IP address and browser details, when the sign-up form checks that you are not a robot. Your browser loads a script from Cloudflare on the home page, and our server sends your IP address to Cloudflare when it checks the result. | Stopping automated abuse of the sign-up form. Cloudflare's handling of this is described in their Turnstile Privacy Addendum. |
| Mailgun | The email address we are writing to, and the contents of the message. | Actually delivering the email. |
| Stripe | Your email address, and only if you start a paid checkout. | Taking payment. Stripe holds card details on their side. We never see or store a card number. |
| See the section below, which is the part of this page we would least like to write. | ||
We also fetch filings from the SEC's EDGAR system. That traffic goes out from our servers and carries nothing about you.
6. Analytics, stated plainly
Every page on Ebomi loads Google Analytics, and it does so before you have agreed to anything. That discloses your IP address and your browser's identifying string to Google, and it sets analytics cookies in your browser so Google can tell a repeat visit from a new one. This is how we count how many people use Ebomi, which is the main thing an open research tool has to be able to report.
Separately, when you sign in or add a company to your watchlist, our server can send an event to Google Analytics. Those events carry your numeric account id and, for watchlist changes, the ticker symbol you added or removed. They never carry your email address.
Google receives those events and retains them, for the period given in How long we keep things below. That is so whether or not anyone is reading the result.
Advertising: Ebomi runs no advertising and sets no advertising identifier. A Google Ads remarketing pixel was configured historically; it was removed on 18 August 2026 and never ran a campaign.
7. Insiders named on this site
Ebomi publishes SEC Form 4 filings, which name the company insiders who traded, their job titles and their transactions. That information is about those individuals, not about you, it comes from public filings that US law requires to be disclosed, and it is visible on Ebomi without signing in.
If you are named in a filing and want to talk to us about it, use the contact address above. We cannot alter the public record, which is the SEC's, but we will listen.
8. How long we keep things
| Data | Kept |
|---|---|
| Your account and watchlist | Until you close your account |
| Record of alerts sent to you | Kept, so we do not repeat ourselves |
| Your IP address | 24 hours |
| Analytics data in Google Analytics | 14 months, the longest Google offers. Summary totals are kept beyond that |
| Sign-in link digests | Until used or expired |
| Opt-out record | Permanently, on purpose, so the opt-out cannot be lost |
9. Your choices
Stop the alerts, keep the account. Every alert has an unsubscribe link, and there is a control on your dashboard. Your account and watchlist stay.
Close your account. This stops everything, permanently. We keep a marker that the account existed and your address on the suppression list, for the reason given above: we cannot honor "never write to me again" if we delete the only record of who asked. Your watchlist is removed and you cannot sign in again.
Ask us what we hold, or ask us to delete it. Write to the contact address.
10. Cookies
Ebomi sets a cookie to keep you signed in, and Google Analytics sets its own cookies to count visitors. Neither is used for advertising and neither is shared. We do not use Google Tag Manager: the analytics tag is loaded directly by the page.
11. Changes
If this policy changes materially we will say so on the site rather than quietly editing this page.
Analytics is now switched on, and sections 6 and 10 had described the analytics cookie as something that would happen “if Google Tag Manager is ever configured”. Google Tag Manager is not configured and never was. The analytics tag is now loaded directly by the page instead, so the cookie is being set while the condition this page named remains false. A reader who checked that condition would have concluded nothing was set, and would have been wrong. Both sections now state what happens rather than naming a setting, which is the same correction this page had to make on the day it was published.
Published, and corrected the same day. Section 6 said our analytics account was set to a placeholder and that Google discarded the sign-in and watchlist events it received. That was true when this page was written and stopped being true hours later, when our analytics was pointed at a real property. Those events are received and kept. The wording now says so, and no longer describes a setting this page cannot see.
The same section also said our tag container was not configured, so nothing was collected and no analytics cookie was set. That was accurate, and it described a setting rather than a practice, so it would have quietly stopped being accurate the moment the container was switched on. It now says plainly that if the container is switched on it sets analytics cookies in your browser, which is true either way.