00

Ebomi Privacy Policy

Last updated 18 August 2026

The short version

Ebomi is an academic research project that emails you when company insiders buy or sell shares. To do that we need your email address, and the list of companies you asked to watch. That is very nearly everything we hold about you.

We do not sell your data. We do not store a password, because Ebomi has no passwords. You can stop the emails or close your account at any time, and closing means we stop writing to you permanently.

The rest of this page is the detail, including the parts that are less flattering.

1. Who we are

Ebomi is run by Dr Attila Balogh personally, a finance academic, as an open research tool. It is built on the insider-trading dataset published in Scientific Data (doi:10.1038/s41597-023-02147-6). There is no company behind it. It operates from Australia, and Australian law governs this policy.

Contact for anything on this page, including a request to see the data we hold about you or to have it deleted: balogh@unimelb.edu.au.

2. What we collect about you

Because you signed up

WhatWhy
Your email addressIt is your account, the address we send your sign-in link to, and the address we send alerts to. Nothing works without it.
When your account was created, and when you last signed inThe first is automatic. The second exists for two reasons we should be open about: it lets us count how many people actually use Ebomi, a figure cited in a research grant application, and it tells us whether a sign-in was your first.
Which companies you watchThe whole product. This is a list of company tickers you chose.
Which alerts we have sent youSo we never send you the same filing twice, and so we can answer you if you ask what we sent.
Your planWhich tier you are on and, if you ever paid, an identifier pointing at Stripe's record.

We do not collect your name, your postal address, your phone number, your date of birth, or your age. There are no fields for them.

We do not store a password. Ebomi signs you in with a link emailed to you. There is a leftover database column from an older design that holds the literal word "magic" for every account, and no code reads it. We are naming it here rather than letting it look like a hidden credential store.

Because of how the internet works

WhatHow long we keep it
Your IP address, recorded when you request a sign-in link or apply for the academic tier24 hours, then deleted automatically. It is kept to stop the sign-up form being abused to send mail to strangers, which happened to us in August 2026.
A one-way digest of your sign-in link, never the link itselfUntil it is used or expires.

If you ask us to stop emailing you

We keep your address on a suppression list, permanently and deliberately. This is the one place where keeping data is the privacy-protecting choice: we cannot promise never to write to you again if we have forgotten who you are. That list is keyed on the address itself, so it also works for people who never had an account.

If you apply for the academic tier

We record the institutional address you claim, the institution, and the decision. The claimed address is replaced by just its domain once verified.

Note that this is the one form on Ebomi where you can type somebody else's address, because verification works by us emailing that address. If you have received a verification email from us that you did not ask for, someone entered your address into that form, and you can tell us at the contact address above.

3. What we do not do

4. Research use of usage data

Ebomi is run by an academic, and how people use it is itself of research interest. We may use data about how Ebomi is used in academic research and in published work. We are telling you before we do it rather than afterwards, because consent given after the fact is not consent.

What that would mean in practice:

If you would rather your usage were excluded from research entirely, write to the address above and we will exclude it. You do not have to give a reason and it will not affect your account.

5. Who else sees your data

We use a small number of outside services. Each one is here because the product cannot work without it, and each is listed with what it actually receives.

ServiceWhat it receivesWhat for
RenderEverything, as our hosting provider and the operator of our database.Running the site.
CloudflareEvery request you make to ebomi.com, including your IP address, the page you asked for, your browser's User-Agent and your cookies. Cloudflare terminates the encryption, so it can see this in the clear.It is our DNS and our front door, and it filters attacks.
Cloudflare TurnstileYour IP address and browser details, when the sign-up form checks that you are not a robot. Your browser loads a script from Cloudflare on the home page, and our server sends your IP address to Cloudflare when it checks the result.Stopping automated abuse of the sign-up form. Cloudflare's handling of this is described in their Turnstile Privacy Addendum.
MailgunThe email address we are writing to, and the contents of the message.Actually delivering the email.
StripeYour email address, and only if you start a paid checkout.Taking payment. Stripe holds card details on their side. We never see or store a card number.
GoogleSee the section below, which is the part of this page we would least like to write.

We also fetch filings from the SEC's EDGAR system. That traffic goes out from our servers and carries nothing about you.

6. Analytics, stated plainly

Every page on Ebomi loads Google Analytics, and it does so before you have agreed to anything. That discloses your IP address and your browser's identifying string to Google, and it sets analytics cookies in your browser so Google can tell a repeat visit from a new one. This is how we count how many people use Ebomi, which is the main thing an open research tool has to be able to report.

Separately, when you sign in or add a company to your watchlist, our server can send an event to Google Analytics. Those events carry your numeric account id and, for watchlist changes, the ticker symbol you added or removed. They never carry your email address.

Google receives those events and retains them, for the period given in How long we keep things below. That is so whether or not anyone is reading the result.

Advertising: Ebomi runs no advertising and sets no advertising identifier. A Google Ads remarketing pixel was configured historically; it was removed on 18 August 2026 and never ran a campaign.

7. Insiders named on this site

Ebomi publishes SEC Form 4 filings, which name the company insiders who traded, their job titles and their transactions. That information is about those individuals, not about you, it comes from public filings that US law requires to be disclosed, and it is visible on Ebomi without signing in.

If you are named in a filing and want to talk to us about it, use the contact address above. We cannot alter the public record, which is the SEC's, but we will listen.

8. How long we keep things

DataKept
Your account and watchlistUntil you close your account
Record of alerts sent to youKept, so we do not repeat ourselves
Your IP address24 hours
Analytics data in Google Analytics14 months, the longest Google offers. Summary totals are kept beyond that
Sign-in link digestsUntil used or expired
Opt-out recordPermanently, on purpose, so the opt-out cannot be lost

9. Your choices

Stop the alerts, keep the account. Every alert has an unsubscribe link, and there is a control on your dashboard. Your account and watchlist stay.

Close your account. This stops everything, permanently. We keep a marker that the account existed and your address on the suppression list, for the reason given above: we cannot honor "never write to me again" if we delete the only record of who asked. Your watchlist is removed and you cannot sign in again.

Ask us what we hold, or ask us to delete it. Write to the contact address.

10. Cookies

Ebomi sets a cookie to keep you signed in, and Google Analytics sets its own cookies to count visitors. Neither is used for advertising and neither is shared. We do not use Google Tag Manager: the analytics tag is loaded directly by the page.

11. Changes

If this policy changes materially we will say so on the site rather than quietly editing this page.

Analytics is now switched on, and sections 6 and 10 had described the analytics cookie as something that would happen “if Google Tag Manager is ever configured”. Google Tag Manager is not configured and never was. The analytics tag is now loaded directly by the page instead, so the cookie is being set while the condition this page named remains false. A reader who checked that condition would have concluded nothing was set, and would have been wrong. Both sections now state what happens rather than naming a setting, which is the same correction this page had to make on the day it was published.

Published, and corrected the same day. Section 6 said our analytics account was set to a placeholder and that Google discarded the sign-in and watchlist events it received. That was true when this page was written and stopped being true hours later, when our analytics was pointed at a real property. Those events are received and kept. The wording now says so, and no longer describes a setting this page cannot see.

The same section also said our tag container was not configured, so nothing was collected and no analytics cookie was set. That was accurate, and it described a setting rather than a practice, so it would have quietly stopped being accurate the moment the container was switched on. It now says plainly that if the container is switched on it sets analytics cookies in your browser, which is true either way.