Privacy Policy

Last updated: July 25, 2026
\n
Plain-English summary: We collect what you give us (name, email, quiz answers, messages, provider-listing info), plus basic analytics about how the site is used. We don't sell your data, we don't run advertising trackers, and we don't want your medical records — please don't send them. You can ask for a copy of your data, a correction, or deletion at any time: [email protected].

Who we are

TMJDirectory ("we," "us") is an independent, U.S.-operated directory of TMJ/TMD-focused providers, owned and operated by Stanley Wellness LLC. This one policy covers everything on tmjdirectory.com: the provider directory and all of our educational content — articles, guides, facts pages, the glossary, quizzes, and self-assessments. One site, one operator, one policy. Contact: [email protected] or the contact form.

Reading our content collects nothing about you beyond the aggregate analytics described below — no account, sign-up, or personal information is required to use any educational page on this site.

What we collect

If you're a visitor

If you're a provider

What we deliberately do NOT collect

TMJDirectory is a directory, not a medical records system. We do not ask for and do not want: diagnoses, treatment history, imaging (MRI/X-ray), intake forms, insurance ID numbers, or Social Security numbers. Please do not include medical details in contact-form messages beyond what's needed to route your question. Clinical information belongs with the provider you choose, under their own privacy practices. Our quiz collects only symptom checkboxes for educational routing — not a medical questionnaire tied to care.

Why we collect it (and our legal bases)

AI usage

We use AI tools to help build the site — drafting and editing educational content (always subject to human review), generating site artwork and icons, and writing software. AI is not used to make individualized decisions about you: it does not diagnose, does not match visitors to providers, and does not decide search rankings. Listing order follows disclosed, deterministic rules (claimed and Premium listings appear above unclaimed ones). AI does not replace professional judgment — nothing AI-assisted on this site is medical advice.

Where data lives and how it's protected

Data is stored with Supabase (Postgres, U.S. region), encrypted in transit (TLS) and at rest. Row-level security limits what each role can read: anonymous visitors see only public display fields; providers can read and edit only their own records; submissions like contact messages are readable only by operations. Sign-in uses one-time magic links — no stored passwords. The site is served through Cloudflare, which provides TLS and bot protection. Administrative access is limited to the operator.

Third-party services

Each processes data only as needed to provide its service to us. We do not sell personal information to anyone, and we do not share it for cross-context behavioral advertising.

Cookies, Do Not Track & Global Privacy Control

Covered in full in the Cookie Policy: Google Analytics cookies, functional localStorage (session ID, favorites, sign-in), and Cloudflare security cookies. No advertising pixels. We honor Global Privacy Control (GPC) signals as an opt-out of data sale/sharing where state law requires — and because we don't sell or share data for advertising in the first place, both GPC and Do Not Track users get the same minimal-tracking experience as everyone else.

How long we keep things (retention)

Your rights & how to exercise them

Regardless of what state or country you live in, we honor the same core set of rights for everyone:

Submitting a request

Email [email protected] (suggested subject: "Access Data Request", "Delete Data Request", or "Correct Data Request") with enough information for us to (1) verify you are the person the data belongs to — usually by confirming control of the email address you used on the site — and (2) understand what you're asking for. An authorized agent may submit a request on your behalf with proof of your written permission. We use the information in a request only to verify and fulfill it.

We respond within 30 days for most requests and within any shorter period a specific state law requires (up to 45 days with notice of extension where the law allows). We don't charge for requests unless they are excessive or repetitive, and we will never discriminate against you for exercising your rights — no denied service, different prices, or reduced quality.

Appeals

If we decline a request, we'll explain why. You may appeal by replying with "Consumer Appeal" in the subject line; a second review will be completed within 45 days. If your appeal is denied, you may contact the attorney general or data-protection regulator in your state or country.

California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you specific rights, all of which are covered by the process above: the right to know (the categories of personal information we collect, the sources, our purposes, and the third parties we disclose it to — all described in this policy), the right to access specific pieces of your information, the rights to correct and delete, the right to opt out of sale or sharing, the right to limit use of sensitive personal information, and the right to non-discrimination.

In CCPA terms, the categories we collect are: identifiers (name, email, phone, ZIP); professional information (for providers: credentials, license details on request); internet activity (pages visited, card interactions); coarse geolocation (from IP or the ZIP you search); and — only if you choose to submit the symptom quiz — information that may be considered sensitive personal information. We collect them from you, from your device, and (for unclaimed provider listings) from public sources; we disclose them only to the service providers listed above for the business purposes described.

Other U.S. state privacy rights

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you have substantially the same rights — confirmation of processing, access, correction, deletion, portability, opt-out of targeted advertising and sale, opt-out of profiling with significant effects (we don't do such profiling), and the right to appeal a denial. All of these are honored through the request process above, for every visitor, whether or not your state's law technically applies to a business of our size.

Consumer health data (Washington My Health My Data and similar laws)

Some states — including Washington and Nevada — regulate "consumer health data" collected by websites even outside HIPAA. The only thing we collect that could qualify is the symptom quiz: checkboxes you voluntarily select to receive an educational result pointing you toward provider types. We use quiz responses only for that purpose and to respond if you asked us to; we do not sell consumer health data, do not share it with advertisers, and do not use it for any form of profiling. You may access or delete your quiz responses through the request process above. Searching the directory itself (location, specialty) is not tied to your identity.

International visitors (GDPR and other laws)

TMJDirectory is operated from the United States and aimed at U.S. audiences, but if you visit from the EU, UK, or EEA, the GDPR (or UK GDPR) applies to your personal data, and you have the rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, objection, data portability, and withdrawal of consent — all honored through the request process above. Our legal bases are described in "Why we collect it" (consent for marketing; performance of the service; legitimate interests, minimized, for security and analytics). Your data is processed and stored in the United States; where GDPR requires safeguards for that transfer, we rely on our processors' Standard Contractual Clauses and equivalent mechanisms. You also have the right to lodge a complaint with your local supervisory authority. Visitors from other jurisdictions (for example, Australia's Privacy Act) may exercise the same rights through the same process, including complaint escalation to your local regulator (for Australian residents, the Office of the Australian Information Commissioner).

HIPAA and health information

TMJDirectory is a directory and publisher, not a healthcare provider, and we are not a "covered entity" under HIPAA. We do not provide, bill for, or facilitate medical care; we display provider information and let you make contact directly. We do not operate a care message center, store intake forms, or handle medical records — and we ask you not to send us any (see "What we deliberately do NOT collect" above). When you contact a provider using details on a listing, whatever you share goes directly to that provider under their privacy practices — ask them for their Notice of Privacy Practices. Health-adjacent data we do hold (quiz symptom selections) is handled under the consumer-health-data section above and applicable state laws, not HIPAA.

For providers (professional members)

If you claim or create a listing, we additionally collect and hold: your professional information (credentials, specialty, practice details, and — on request for verification — license number, issuing state, expiration, and NPI); your account email and sign-in timestamps; and aggregate analytics about your own listing. Sources are you, state licensing authorities and the NPI Registry (verification lookups), and public records (pre-claim listing data). We use this to operate your listing, verify credentials, and show you your own analytics — never for advertising. If and when paid subscriptions begin, payment details go directly to Stripe; we never see or store card numbers.

Remember that your listing and full profile are public by design — everything you choose to publish there (bio, photos, contact details) is visible to anyone, and public pages may be copied or cached by search engines and other services we don’t control. Publish only what you want public.

You can review and update your information any time from your provider dashboard. Deleting your personal data generally means removing your listing and account — email us and we'll complete it, except where a legal obligation requires limited retention. Note that pages removed from the site may persist temporarily in search-engine caches we don't control.

Providers: take-down requests

If your listing was compiled from public information and you want it removed rather than claimed, email us or use the contact form ("Dispute or correction"). We remove verified requests within 7 business days.

If something goes wrong (security incidents)

We maintain a written internal incident-response plan. If a breach affects your personal data, we will investigate, contain it, and notify affected people and authorities as required by applicable state breach-notification laws — promptly and plainly, telling you what happened, what data was involved, and what we're doing about it.

Children's privacy

TMJDirectory is not intended for or directed to children under 13, and we do not knowingly collect personal data from them. If we learn we have inadvertently received such information, we will delete it promptly — if you believe a child under 13 has provided us data, email [email protected]. Users between 13 and the age of majority in their state should use the site only with a parent or guardian's consent; a parent using the site on behalf of a minor (for example, seeking pediatric TMJ care) is treated as the user, and their information is handled under this policy.

Changes

Material changes get a new "Last updated" date at the top of this page, and where reasonable we'll notify newsletter subscribers and signed-in providers.

Contact

[email protected] · contact form · See all policies at /legal.

\n