Consumer Health Data Privacy Policy — United States
Effective date: 13 August 2026 ·
Supplements the NeuroMetrics Privacy Policy
This policy is provided for United States residents, including under the
Washington My Health My Data Act, Nevada SB 370, and Connecticut's
consumer health data provisions. It explains how NeuroMetrics (operated by
Declan Curran, New South Wales, Australia — "we", "us")
collects, uses, and protects consumer health data, and the
rights you have over it.
1. Consumer health data we collect
- Brain-activity (EEG) metrics: downsampled brain-state
estimates (focus, calm, engagement, fatigue, Flow Score) and relative
brainwave band powers, recorded during sessions you choose to start.
- Estimated mood data: valence, arousal, dominance, and an
overall mood estimate derived from EEG.
- Self-reported mood data: optional 1–9 valence / arousal /
dominance ratings and notes you enter.
- Heart and oxygenation data: heart rate, heart-rate
variability, and experimental fNIRS oxygenation values, when available
from your headband.
- Raw EEG recordings (opt-in only): the full 256 Hz EEG
waveform, uploaded only if you enable
Settings → "Back up raw EEG recordings".
- Session metadata: session times, duration, headband
model, optional intention label and lifestyle tags.
Sources: all health data comes from your EEG headband via
the app, or from what you type into the app. We collect nothing from data
brokers or other companies.
2. Why we collect it (purposes)
- To provide the app's features: live metrics, session history, trends, and
comparing your scores to your own past averages.
- To securely store your data so you can access it across devices.
- With your separate opt-in only ("Help improve the models"), to improve our
wellness models using de-identified data.
We do not use consumer health data for advertising, and we do not
sell or share it. No data is used for
targeted advertising.
3. Consent
We collect consumer health data only with your affirmative consent:
recording is started by you; cloud storage requires the express consent
checkbox at account creation; raw-EEG backup requires a separate opt-in switch;
model-improvement use requires a further separate opt-in. Each consent can be
withdrawn at any time in the app (guest mode, the backup switch, the research
toggle, or signing out).
4. Who can access it
- You. Your data is keyed to your private account and
protected by per-user row-level security.
- Our processors, acting on our instructions under
contract: Supabase (database and authentication, hosted
in Australia, AWS ap-southeast-2) and Cloudflare
(private file storage for opt-in raw-EEG backups, Asia-Pacific/Oceania
location preference). If you use Google sign-in, Google
authenticates you; Google does not receive your health data from us.
- No one else, except where required by law. We do not
sell consumer health data, do not share it for advertising, and have no
affiliates with access to it.
5. Your rights
Wherever you live in the US, we honour the following on request (and, for
Washington, Nevada, and Connecticut residents, as a matter of statutory
right):
- Access: confirm whether we hold your health data and
receive a copy (in-app history and CSV/JSON export, or by request).
- Withdraw consent: at any time, in the app.
- Delete: Account → "Delete account & all
data" permanently deletes your account, all cloud records, and
uploaded raw-EEG files, or email us and we will action deletion within 30
days, including instructing our processors to delete.
To exercise any right, use the in-app controls or email
declan.curran@outlook.com. We
will respond within 45 days. We do not discriminate against you for exercising
your rights.
Appeals: if we refuse a request, you may appeal by replying
to our decision with "Appeal" in the subject line; we will respond within 45
days with reasons. Washington residents may also contact the Washington
Attorney General at www.atg.wa.gov;
Connecticut residents the Connecticut Attorney General; Nevada residents the
Nevada Attorney General.
6. Security and breach notification
Health data is encrypted in transit and at rest and access-controlled per
user. In the event of a breach of unsecured, identifiable health data, we will
notify affected users and the U.S. Federal Trade Commission as required by the
FTC Health Breach Notification Rule (16 CFR Part 318), and applicable state
authorities.
7. Children
NeuroMetrics is for adults 18+ and is not directed to children. We do not
knowingly collect data from anyone under 18 (and never from children under 13
per COPPA); any such data will be deleted.
8. Changes and contact
Material changes to this policy are posted here with a new effective date.
Questions:
declan.curran@outlook.com.