Privacy Policy
How we collect, use, and protect your personal information.
Effective Date: February 6, 2026 · Last reviewed: February 14, 2026
Table of Contents
- Who We Are
- Information We Collect
- How We Use Your Information
- Legal Basis for Processing (GDPR)
- Data Sharing & Third-Party Services
- Cookies & Tracking Technologies
- Children's Privacy (COPPA Compliance)
- Health Information & HIPAA Disclaimer
- Data Retention
- Data Security
- Automated Access & Anti-Scraping
- Your Rights
- California Privacy Rights (CCPA/CPRA)
- European Privacy Rights (GDPR)
- Do Not Track Signals
- International Data Transfers
- Changes to This Policy
- Contact Us
1. Who We Are
MyopiaProgression.com ("we," "us," or "our") is an educational health information website dedicated to providing evidence-based resources about myopia (nearsightedness) progression and myopia control for parents, eye care providers, educators, and researchers.
Data Controller:
MyopiaProgression.com
P.O. Box 1587
Hope Mills, NC 28348
United States
Privacy Contact: [email protected]
2. Information We Collect
A. Information You Provide Directly
We collect information that you voluntarily provide when using our services:
- Account registration: Name and email address when you create an account through our authentication provider
- Email subscriptions: Name and email address when you subscribe to newsletters or download resources
- Risk Assessment Tool: Your child's age, vision history, lifestyle factors, family history of myopia, and optionally your child's name and your email address. This information is used to generate a personalized risk report.
- Appointment requests: Parent/guardian name, email, phone number, child's name and age, preferred appointment details, and any message you include
- Provider directory listings: Practice name, credentials, contact information, address, specialties, insurance accepted, and professional biography
- Research submissions: Academic credentials, institutional affiliation, ORCID ID, and uploaded research documents
- Advertiser inquiries: Company name, contact information, advertising goals, and budget range
- Community participation: Poll responses and feedback
B. Information Collected Automatically
When you visit our website, we automatically collect certain information:
- Device and browser information: Browser type and version, operating system, screen resolution
- Usage data: Pages visited, time spent on pages, click patterns, and navigation paths
- Network information: IP address and approximate geographic location (city/region level)
- Referral data: The website or search engine that directed you to our site
C. Information We Do NOT Collect
- We do not collect Social Security numbers, government-issued ID numbers, or financial account numbers
- We do not collect biometric data
- We do not collect precise geolocation data (GPS coordinates) from your device
- We do not collect protected health information (PHI) as defined by HIPAA (see Section 8)
- We do not knowingly collect any personal information from children under 13 years of age without verifiable parental consent
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To provide our educational tools, risk assessments, provider directory, and resource library
- Communication: To send newsletters, appointment confirmations, and respond to your inquiries (only with your consent for marketing communications)
- Provider matching: To connect parents with appropriate myopia control specialists based on location and treatment preferences
- Payment processing: To process provider subscription payments and advertiser billing through our payment processor
- Website improvement: To analyze usage patterns, fix technical issues, and improve our content and user experience
- Security: To detect and prevent fraud, abuse, and unauthorized access
- Legal compliance: To comply with applicable laws, regulations, and legal processes
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:
- Consent: When you opt in to receive marketing emails, submit a risk assessment, or accept analytics cookies
- Contract performance: When processing is necessary to provide services you have requested (e.g., provider subscriptions, appointment requests)
- Legitimate interests: For website security, fraud prevention, and improving our services, where these interests are not overridden by your rights
- Legal obligation: When we are required to process data to comply with applicable law
5. Data Sharing & Third-Party Services
We do not sell, rent, or trade your personal information to third parties. We share data only with the following categories of service providers who assist us in operating our website:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Plausible Analytics | Privacy-focused website analytics | Anonymized page views, referral sources (no personal identifiers, no cookies) |
| Microsoft Clarity | Session replay and heatmap analysis | Anonymized interaction data, click patterns (with your cookie consent) |
| Stripe | Payment processing | Name, email, payment card details (processed directly by Stripe; we never see or store full card numbers) |
| Resend | Transactional and marketing emails | Name and email address |
| Cloudflare | CDN, DDoS protection, DNS | IP address, request metadata (processed at the network level) |
| Cloud Storage (S3-compatible) | File storage | Uploaded files (research PDFs, provider avatars) |
Each service provider is contractually obligated to use your data only for the purposes described above and to maintain appropriate security measures. We do not permit these providers to use your data for their own marketing purposes.
7. Children's Privacy (COPPA Compliance)
MyopiaProgression.com takes children's privacy seriously. Our website is designed for use by parents, guardians, and eye care professionals — not by children directly.
Our Practices Regarding Children's Data
- This website is not directed at children. Our services are intended for parents, guardians, eye care providers, educators, and researchers. Children under 13 should not use this website without direct parental supervision, and children under 13 should never submit personal information through this website.
- We do not knowingly collect personal information directly from children under 13. Our Risk Assessment Tool and appointment request forms are designed to be completed by a parent or guardian on behalf of their child. If we learn that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will delete that information promptly.
- Child-related data is provided by parents. When a parent or guardian uses our Risk Assessment Tool, they may voluntarily provide their child's age, vision history, and lifestyle information. This data is associated with the parent's email address, not a child's account.
- We do not require children's personal information. The child's name field in our forms is optional and is provided solely for the parent's convenience in generating personalized reports.
- No behavioral advertising targeting children. We do not use any data related to children for advertising, profiling, or behavioral targeting purposes.
- No sale of children's data. We never sell, rent, or trade any information related to children, regardless of age, to any third party for any purpose.
- Minimal data collection principle. We collect only the minimum amount of child-related information necessary to provide the requested service (e.g., age range for risk assessment), and we do not condition a child's participation in any activity on the disclosure of more personal information than is reasonably necessary.
Parental Rights Under COPPA
If you are a parent or guardian and believe that your child has provided personal information to us without your consent, you have the right to:
- Request to review any personal information we have collected about your child
- Request that we delete any personal information about your child
- Refuse to permit further collection of your child's information
To exercise these rights, contact us at [email protected]. We will respond to verified requests within 30 days.
FTC Enforcement
We are committed to full compliance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, and the FTC's COPPA Rule, 16 C.F.R. Part 312. Violations of COPPA can result in civil penalties of up to $50,120 per violation as enforced by the Federal Trade Commission. We take these obligations seriously and have implemented technical and organizational measures to ensure compliance.
8. Health Information & HIPAA Disclaimer
Important: MyopiaProgression.com is NOT a healthcare provider, health plan, or healthcare clearinghouse. We are NOT a "covered entity" or "business associate" as defined under the Health Insurance Portability and Accountability Act (HIPAA).
- The information provided on this website is for educational and informational purposes only and is not a substitute for professional medical advice, diagnosis, or treatment.
- Our Risk Assessment Tool provides general educational guidance based on known risk factors. It does not constitute a medical diagnosis or clinical recommendation.
- We do not access, store, or process protected health information (PHI) from healthcare providers' electronic health record (EHR) systems.
- Information you voluntarily provide (such as your child's age or vision history) is treated as general personal information under applicable privacy laws, not as PHI under HIPAA.
- When you use our appointment request feature, your information is shared with the selected eye care provider. Once that provider receives your information, their own HIPAA obligations apply to how they handle it.
- Always consult a qualified eye care professional for medical advice regarding your child's vision.
9. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| User accounts | Until you request deletion or 3 years of inactivity |
| Email subscriptions | Until you unsubscribe |
| Risk assessment data | 2 years, then anonymized for aggregate statistical purposes |
| Appointment requests | 1 year after completion or cancellation |
| Provider directory listings | Until the provider requests removal or subscription ends |
| Payment records | As required by tax and accounting regulations (typically 7 years) |
| Analytics data | Aggregated and anonymized; no individual-level retention |
You may request early deletion of your data at any time by contacting us at [email protected].
10. Data Security
We implement industry-standard technical and organizational security measures to protect your personal information:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS enforced site-wide with HSTS preloading)
- Encryption at rest: Database storage is encrypted at the infrastructure level
- Access controls: Administrative access is restricted and requires authentication
- Security headers: Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, and Permissions-Policy headers are enforced
- Rate limiting: API endpoints are protected against brute-force and abuse attacks
- Spam prevention: Forms include honeypot fields and validation to prevent automated abuse
- DDoS protection: Cloudflare provides network-level protection against distributed denial-of-service attacks
- Payment security: All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. We never see, store, or process full credit card numbers.
While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.
Automated Access & Anti-Scraping Policy
Unauthorized automated access to this website, including but not limited to scraping, crawling, data mining, or bulk downloading, is strictly prohibited and constitutes a violation of our Terms of Use and applicable law.
Prohibited Activities
The following activities are expressly prohibited without prior written authorization from MyopiaProgression.com:
- Web scraping: Using automated tools, scripts, bots, or software to extract data from this website, including but not limited to provider directory listings, contact information, treatment data, and educational content
- Data mining: Systematically collecting, aggregating, or compiling information from this website for commercial or competitive purposes
- Bulk downloading: Downloading substantial portions of the website content through automated or manual means
- API abuse: Accessing our application programming interfaces (APIs) in a manner that exceeds reasonable use, circumvents rate limits, or is intended to extract data in bulk
- Database reconstruction: Attempting to reconstruct, replicate, or create a derivative database from our provider directory or any other structured data on this website
- Circumvention: Bypassing, disabling, or interfering with any technical protection measures, including rate limiting, CAPTCHAs, access controls, or copy protection mechanisms
Technical Enforcement
We employ technical measures to detect and prevent unauthorized automated access, including but not limited to: rate limiting on API endpoints, bot detection, IP blocking, user-agent filtering, and behavioral analysis. We reserve the right to block any IP address, user agent, or access pattern that we reasonably believe constitutes automated or abusive access.
Legal Remedies
Unauthorized automated access may violate the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, the Digital Millennium Copyright Act (DMCA), 17 U.S.C. § 1201, and applicable state computer crime statutes. We reserve the right to pursue all available legal remedies, including injunctive relief and monetary damages, against any person or entity that engages in prohibited automated access.
Permitted Automated Access
We permit access by major search engine crawlers (Googlebot, Bingbot, DuckDuckBot) for the purpose of indexing publicly available pages, subject to the directives in our robots.txt file. All other automated access requires explicit written permission. To request permission, contact [email protected].
11. Your Rights
Regardless of your location, you have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Opt-out: Unsubscribe from marketing communications at any time using the link in any email or by contacting us
- Data portability: Request your data in a commonly used, machine-readable format
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
To exercise any of these rights, email [email protected]. We will verify your identity and respond within 30 days (or 45 days for complex requests, with notice).
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions (such as completing a transaction or complying with legal obligations).
Right to Opt-Out of Sale or Sharing
We do NOT sell your personal information. We do NOT share your personal information for cross-context behavioral advertising. No opt-out is necessary because we do not engage in these practices.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different pricing, quality of service, or access based on exercising your privacy rights.
Authorized Agents
You may designate an authorized agent to submit requests on your behalf. We may require verification of both your identity and the agent's authority before processing such requests.
13. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, you have the following additional rights under the General Data Protection Regulation (GDPR):
- Right to restriction of processing: Request that we limit how we use your data in certain circumstances
- Right to object: Object to processing based on legitimate interests, including profiling
- Right to lodge a complaint: File a complaint with your local data protection authority (supervisory authority) if you believe your rights have been violated
- Right not to be subject to automated decision-making: We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you
To exercise these rights, contact us at [email protected]. We will respond within 30 days as required by GDPR.
14. Do Not Track Signals
Our website respects Do Not Track (DNT) browser signals. When we detect a DNT signal, we limit data collection to essential functionality only. Our primary analytics provider, Plausible Analytics, is privacy-focused by design and does not use cookies or track individual users regardless of DNT settings.
15. International Data Transfers
Our servers and database are located in the United States. If you access our website from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
By using our website, you consent to the transfer of your information to the United States. For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) or your explicit consent as the legal mechanism for international data transfers where required by GDPR.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Effective Date" and "Last reviewed" date at the top of this page
- Post a notice on our website for significant changes
- Send an email notification to registered users for material changes that affect how we handle their data
We encourage you to review this page periodically. Your continued use of our website after changes are posted constitutes your acceptance of the updated policy.
17. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: [email protected]
Mail: MyopiaProgression.com, P.O. Box 1587, Hope Mills, NC 28348, United States
We aim to respond to all privacy-related inquiries within 30 days. For urgent matters, please indicate "URGENT" in your email subject line.
Worried your child's myopia (nearsightedness) is getting worse?
Take the 2–3 minute risk assessment and get a clear next step.
Eye doctor?
Join our network where parents search for myopia specialists.
Pre-launch: secure your placement now.

5 Signs Your Child Needs Myopia Control
A quick-start guide for concerned parents. Learn when to take action.