NeuroMetrics ("the app", "we", "us", "our") is operated by Declan Curran of New South Wales, Australia. This policy explains how we handle your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because NeuroMetrics handles health information, we are bound by the Privacy Act and the APPs regardless of our size or turnover.
Contact / Privacy Officer: declan.curran@outlook.com
NeuroMetrics is a wellness and self-insight tool. It estimates focus, a "Flow Score", and a mood reading from a consumer EEG headband (Muse). These are personalised wellness estimates, not medical or diagnostic measures. NeuroMetrics is not a medical device and does not diagnose, treat, cure, or prevent any condition.
You can use the core app fully on-device without an account. Cloud features (sync, history, comparison to your average) are optional and only begin when you choose to sign in.
a) Account information (only if you create an account): email and password, handled by our authentication provider (Supabase Auth); passwords are stored only as a one-way hash. If you choose "Continue with Google", Google authenticates you and shares your Google account email address with us; we receive no other Google data. Choosing "Continue as guest" creates no account and sends nothing to the cloud — all data stays on your device.
b) Health and wellness information (sensitive information): when you record while signed in, we store a downsampled summary (about one point every 5 seconds) of EEG-derived brain-state metrics (focus, calm, engagement, fatigue, Flow Score), mood estimates (valence, arousal, 0–100 score), heart rate and HRV, experimental fNIRS oxygenation, session metadata (duration, headband model, optional "intention" label), and any optional mood check-ins.
c) Raw EEG recordings (opt-in only): if — and only if — you switch on Settings → "Back up raw EEG recordings", the full 256 Hz EEG waveform recorded during your sessions is compressed and uploaded to private cloud file storage under your account, together with any mood self-ratings (1–9 valence / arousal / dominance scores and optional note) you attached to those recordings. This switch is off by default; while it is off, your raw EEG waveform is never uploaded. You can turn it off at any time, and deleting your account permanently deletes the uploaded files.
d) Stored only on your device (not uploaded): calibration baseline, settings, and the full local copy of recorded sessions.
e) Technical information: standard network information needed to communicate securely with our backend, handled transiently by our host. No advertising identifiers; the app contains no ads and no third-party analytics or tracking SDKs.
Bluetooth & location: Bluetooth is used solely to connect to your headband. On Android 12+ scanning uses the "neverForLocation" flag; we do not collect or use your location. Older Android versions require a location permission to permit any Bluetooth scan, but we still do not access your location.
Brain, heart, and mood data are "health information", a type of sensitive information. We collect it only with your consent: recording is started by you; cloud storage of your metrics requires the express consent checkbox you tick when creating an account; and raw-EEG backup requires the separate opt-in switch in Settings. You can withdraw consent at any time by using guest mode, turning the backup switch off, signing out, or deleting your account and data.
We do not sell your personal information and do not use it for advertising.
We do not disclose your personal information except to: our infrastructure providers, Supabase (database and authentication) and Cloudflare (private file storage for opt-in raw-EEG backups), each as a processor under contract; Google (only if you choose Google sign-in, solely to authenticate you); FormSubmit, a form-delivery service that relays data-deletion requests submitted through our website to us by email; or where required or authorised by law. We use no third-party advertising, analytics, or tracking services.
Our backend database stores your data in Australia (AWS ap-southeast-2). Opt-in raw-EEG backups are stored with Cloudflare R2 with an Asia-Pacific/Oceania location preference; Cloudflare may route or process operational metadata through other regions. Some operational metadata — such as authentication and system logs handled by our providers — may be processed overseas. If you submit a data-deletion request through our website form, the details you enter are transmitted via our form-delivery provider (FormSubmit) and processed outside Australia, solely to deliver your request to us by email. By using cloud features, or submitting the website deletion form, you consent to storage and processing in these locations. Where data is held outside Australia, we take reasonable steps to ensure APP-consistent handling.
Data is encrypted in transit (HTTPS/TLS) and at rest by our host, and is restricted per-user by database row-level security. Your cloud metrics are stored pseudonymously — keyed to your account identifier and held separately from any identifying account details. Our infrastructure provider (Supabase) maintains recognised security controls, including SOC 2 compliance. We keep your data until you delete it or your account; deletion is permanent.
View your history in-app and export any session as CSV or JSON. Contact us to correct information we hold. To delete everything, open Account → "Delete account & all data" in the app, which permanently removes your account and all cloud and on-device data — or email us to request deletion, which we action within 30 days. See our account & data deletion page for details.
You may use the app without identifying yourself: choose "Continue as guest" and no account is created and no data leaves your device.
NeuroMetrics is intended for adults (18+) and is not directed to children.
If a breach likely to cause serious harm occurs, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme.
Contact us first. If unsatisfied, you may complain to the OAIC at www.oaic.gov.au or 1300 363 992.
If you live in the United States, our Consumer Health Data Privacy Policy additionally applies (including for the purposes of the Washington My Health My Data Act, Nevada SB 370, and Connecticut's consumer health data provisions). It describes the consumer health data we collect, our consent practices, and your rights to access, withdraw consent, delete, and appeal. We do not sell consumer health data or use it for advertising. In the event of a breach of identifiable health data we comply with the FTC Health Breach Notification Rule.
Do Not Track / Global Privacy Control: the app and this website use no advertising, analytics, or tracking cookies at all, so there is no tracking to opt out of; browser "Do Not Track" or Global Privacy Control signals change nothing because we never sell, share, or use your data for targeted advertising in the first place.
We may update this policy; material changes are reflected by the "Last updated" date above.