Privacy Policy

Effective Date: May 1, 2026

Even Health LLC, and any affiliated companies, doing business as Cabana ("Cabana," "we," "us," or "our"), values your privacy. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you visit our websites, create an account, purchase or manage a Cabana subscription, use Cabana Live or related wellness features, participate in live groups, contact support, or otherwise interact with our services.

This Privacy Policy applies to Cabana-operated digital properties that link to it, including our websites, mobile applications, web applications, hosted payment and account-management pages, and customer-support channels. Certain services, promotions, or trials may be governed by additional terms or notices that supplement this Privacy Policy.

Cabana currently offers services both:
• directly to individuals who purchase or activate a subscription for themselves; and
• through employers, health plans, benefit sponsors, providers, or other organizations that make Cabana available to members.

If your access to Cabana is provided by a sponsoring organization, we may process certain information needed to verify eligibility, administer the benefit, provide the service, maintain security, and generate reports that do not identify your live-group participation, reflections, or wellness activity to your employer for advertising purposes. If you purchase a subscription yourself, your account is treated as a direct-to-consumer account.

Information We Collect
‍
We collect information you provide directly to us, information collected automatically when you use our services, and information we receive from sponsors, payment providers, or other third parties you direct us to interact with.

The categories of personal information we may collect include:
• Identifiers and contact information, such as your name, email address, login credentials, account alias or display name, mailing address, phone number, and customer-support identifiers.
• Account and subscription information, such as your account status, subscription plan, enrollment channel, eligibility details, renewal dates, receipts, billing status, promotion or referral codes, cancellation history, refund history, and communications about your subscription.
• Payment and transaction information, such as billing contact details, payment method type, payment token or last four digits, payment processor identifiers, invoices, receipts, chargeback information, tax-related records, and fraud-prevention signals. Unless we clearly tell you otherwise, payment-card entry and processing are handled by a third-party payment processor, and we do not store your full payment-card number or card security code in our own systems.
• Wellness and support information, such as live-group registrations and attendance, journals, mood check-ins, survey and quiz responses, goals, reflections, content preferences, support requests, and any information you choose to share during your use of the service.
• Sensitive and consumer health data, which may include information linked or reasonably linkable to you that relates to your mental-health status, emotional well-being, stress, coping patterns, interventions, symptoms, assessments, or similar wellness-related insights.
• Audio/visual and participation metadata, such as whether you joined a live session, whether you joined by chat only, your participation settings, timestamps, and technical details needed to deliver a live session. We do not record live support groups unless we tell you in advance and obtain any consent required by law.
• Device, network, and usage information, such as IP address, browser type, app version, device identifiers, operating system, crash logs, pages or screens viewed, referring URLs, session activity, timestamps, and similar diagnostics and security logs.
• Marketing and preference information, such as newsletter sign-up status, communication preferences, consent records, campaign interactions, and suppression or opt-out records.
• Information from sponsors or providers, such as eligibility data, access codes, or limited administrative information necessary to activate or administer a sponsored benefit.
• Information from third parties you choose to interact with, such as app-store operators, referral features, or customer-support providers.

How We Use Information
‍
We use personal information for the following purposes:
• to create, authenticate, secure, and administer your account;
• to activate, bill, renew, suspend, cancel, refund, and otherwise manage subscriptions, trials, promotions, and payments;
• to provide Cabana Live, wellness features, content, live groups, scheduling, support communities, and customer service;
• to personalize your experience, including by recommending content, groups, or features based on your interactions and preferences;
• to communicate with you about your account, product updates, receipts, billing events, renewal notices, support requests, security alerts, or policy changes
• to send marketing messages to you where permitted by law and consistent with your preferences;
• to maintain safety, detect and prevent fraud, enforce our terms, protect users, and respond to legal process;
• to analyze service performance, troubleshoot issues, improve accessibility and functionality, and better understand how our services are used;
• to create aggregated or deidentified insights for service improvement, research, reporting, and product development, where permitted by law; and
• to comply with legal, accounting, tax, regulatory, and recordkeeping obligations.

We may use automated tools, including search, recommendation, or reflective-assistance tools, to support certain product features. Unless we specifically disclose otherwise, we do not use identifiable member content to train third-party general-purpose AI models.

Sensitive Data and Consumer Health Data
‍
Because Cabana offers mental-wellness and support features, some personal information we process may be considered sensitive personal information under state law and/or consumer health data under certain state laws.

Where required by law, we will obtain your consent before:
• collecting consumer health data for a purpose that is not necessary to provide the product or service you requested;
• sharing consumer health data where separate consent is required; or
• using sensitive information in ways that go beyond the purposes reasonably expected to provide and secure the service.

We do not sell consumer health data.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising unless we clearly disclose that practice and provide any required opt-out rights.

How We Disclose Information
‍
We may disclose personal information to the following categories of recipients:
• Service providers and processors that help us host the service, process payments, provide cloud infrastructure, authenticate users, detect fraud, support customer service, deliver communications, maintain security, analyze service performance, or perform similar functions on our behalf;
• Moderators, coaches, clinicians, or similar personnel involved in delivering a live group, support interaction, or related service;
• Sponsors, employers, health plans, and organizational customers when necessary to verify eligibility, administer a sponsored program, or provide aggregated/deidentified reporting or limited administrative data consistent with our contractual obligations and applicable law;
• Professional advisers such as auditors, lawyers, accountants, and insurers;
• Law enforcement, regulators, courts, or other parties when we reasonably believe disclosure is required by law, legal process, or to protect the rights, safety, and security of Cabana, our users, or others;
• Successors or counterparties in connection with a merger, acquisition, financing, reorganization, asset sale, or similar transaction; and
• Other parties at your direction or with your consent.

We contractually require service providers/processors that handle personal information on our behalf to protect it and to use it only for authorized purposes.

Cookies and Similar Technologies
‍
We and our service providers may use cookies, SDKs, pixels, local storage, and similar technologies to:
• keep you signed in;
• remember settings and preferences;
• maintain security and detect abuse;
• understand service performance and usage patterns; and
• measure the effectiveness of communications and service improvements.

You can control cookies through your browser or device settings. Some features may not function properly if you disable certain technologies. If Cabana engages in targeted advertising or other activity that triggers opt-out rights under applicable law, we will provide the required opt-out methods.

Payment, Renewals, and Subscription Management
‍
If you purchase a subscription, we use payment and billing information to:
• complete your purchase;
• process recurring charges you authorize;
• send receipts and billing notices;
• apply credits, promotions, or refunds;
• administer cancellations, pauses, or reactivations where offered;
• detect fraud, payment abuse, and chargebacks; and
• comply with accounting, tax, and audit requirements.

Our Privacy Policy explains how we handle subscription-related data. The commercial terms of your subscription, including pricing, renewal timing, cancellation rules, refund eligibility, and any trial or promotional terms, are described in the checkout flow and any applicable Subscription Terms or Terms of Service.

Communications and Your Choices
‍
We send transactional or service messages when necessary to operate your account or deliver the service, such as receipts, renewal notices, security alerts, support responses, policy updates, appointment or schedule reminders, and other operational communications.

We may also send marketing communications about upcoming Cabana live groups offerings and product updates available to you where permitted by law. You can opt out of marketing emails at any time using the unsubscribe link in the message. If you consent to receive promotional texts or calls, you can opt out by following the instructions provided in the message or by contacting us. Opting out of marketing will not stop transactional or service communications.

Data Retention
‍
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the service, administer subscriptions, maintain security, resolve disputes, enforce our agreements, and comply with legal obligations.

Our retention approach is based on the category of information and the reason we collected it. For example:
• Account information is retained while your account is active and for a reasonable period afterward to support reactivation, account administration, fraud prevention, and legal obligations.
• Subscription and transaction records are retained as needed for billing, accounting, tax, chargeback, audit, and legal compliance purposes.
• Support, wellness, and participation records are retained as needed to provide the service, improve the experience, handle support issues, maintain safety, and honor deletion requests, subject to backup, security, and legal-retention constraints.
• Security, device, and diagnostic logs are retained for the period reasonably necessary for security, fraud prevention, investigations, and service reliability.
• Marketing suppression records may be retained so that we can honor opt-out requests.
• Aggregated or deidentified data may be retained for longer periods where permitted by law.

When retention is no longer necessary, we will delete, deidentify, or anonymize information, unless we are legally required or permitted to keep it.

Your Privacy Rights
‍
Depending on where you live and subject to applicable law, you may have the right to:
• confirm whether we process your personal information;
• access or receive a copy of your personal information;
• correct inaccurate personal information;
• delete personal information;
• obtain a portable copy of certain information;
• withdraw consent where processing is based on consent;
• opt out of certain marketing communications;
• opt out of sales, sharing, or targeted advertising if those practices occur;
• appeal a denial of certain privacy-rights requests; and
• not be unlawfully discriminated against for exercising your rights.

If you are a Washington or Nevada consumer and applicable law gives you rights concerning consumer health data, you may also have the right to confirm whether we collect, share, or sell such data, obtain access to it, obtain deletion, withdraw consent where applicable, and receive information about certain third parties with whom the data has been shared where required by law.

To exercise privacy rights, contact us at privacy@even.health. We may need to verify your identity before acting on your request. You may also designate an authorized agent where permitted by law.

California Disclosures
‍
For the preceding 12 months, the categories of personal information we have collected may include identifiers, customer records, commercial information, internet/network activity, geolocation-derived device information, audio/visual participation metadata, professional or employment-related information where relevant to sponsored access, inferences, and sensitive personal information such as account credentials and wellness-related information.

We collect that information from you, from your use of the service, from your devices, from payment and service providers, and from sponsors or referral sources where applicable. We use it for the business and commercial purposes described in this Privacy Policy.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising unless we clearly disclose that practice and provide any required rights.

Consumer Health Data Disclosures
‍
For consumers protected by consumer-health-data laws, the categories of consumer health data we may collect include information about your mental or emotional well-being, stress, coping patterns, surveys, assessments, mood check-ins, journals, wellness preferences, live-group participation, and inferences drawn from your interactions with the service.

We collect this information from you, from your use of Cabana features, from your devices and session activity, from sponsors or providers where relevant to eligibility or administration, and from service providers acting on our behalf.

We may share consumer health data only:
• with processors/service providers acting on our behalf;
• with personnel necessary to provide the service you requested;
• with sponsors only to the limited extent necessary to administer a sponsored service and subject to contractual and legal restrictions;
• in connection with legal obligations or safety needs; or
• otherwise with your consent or as otherwise permitted by law.

How you can exercise rights concerning consumer health data is described in the "Your Privacy Rights" section above.

Children
‍
Cabana's direct-to-consumer services are intended for adults age 18 and older. We do not knowingly allow children to purchase direct subscriptions or create D2C accounts. We do not knowingly collect personal information online from children under 13 in connection with the D2C service. If you believe a child has provided personal information to Cabana in violation of this policy, contact us and we will take appropriate steps to review and address the issue.

Security
‍
We use administrative, technical, and physical safeguards designed to protect personal information appropriate to the nature of the information and the risks involved. No security measure is perfect, and we cannot guarantee absolute security. If we determine that notification is required by law following a security incident, we will provide notice in accordance with applicable law.

Third-Party Services and Links
‍
Cabana may link to third-party websites, applications, or services that we do not control. Their privacy practices are governed by their own notices and policies, and we encourage you to review them.

U.S.-Only Service
‍
Cabana's direct-to-consumer services are currently intended for persons located in the United States. If we later offer services in other jurisdictions, we may provide a supplemental regional privacy notice that applies to those users.

Changes to This Privacy Policy
‍
We may update this Privacy Policy from time to time. When we do, we will update the effective date above and provide additional notice where required by law.

Contact Us
‍
If you have questions about this Privacy Policy or would like to exercise your privacy rights, contact:

Privacy Office
Even Health LLC d/b/a Cabana
privacy@even.health
1910 Towne Center Blvd, Suite 250, Annapolis, MD 21403

‍