Summary
NeuroAmaze is a mental wellness app. We collect only the information needed to deliver your personalised experience. Health data is encrypted and stored on your device by default. We do not sell your personal information — ever.
1. Who We Are
NeuroAmaze, Inc. ("NeuroAmaze," "we," "us," or "our") operates the NeuroAmaze mobile application and related services (collectively, the "Service"). We are committed to protecting your privacy, especially the sensitive mental health information you entrust to us.
This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service. It applies to all users of the NeuroAmaze iOS and Android apps and website.
Not a Medical Provider
NeuroAmaze is a wellness tool, not a healthcare provider. This Privacy Policy is separate from HIPAA's Notice of Privacy Practices, which applies only to covered entities and their business associates under HIPAA. For our HIPAA-aligned practices, see our Consumer Health Data Notice.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: email address, display name, and password when you create an account.
- Health and wellness data: mood entries, symptom logs, sleep records, journal entries (text and voice transcripts), thought records, mental health test results, and medication information you choose to enter.
- Communications: messages you send to our support team.
2.2 Information Collected Automatically
- Usage data: which features you use, session duration, and feature interactions — collected in anonymised, aggregated form only.
- Device information: device type, operating system version, app version, and crash reports (via Firebase Crashlytics).
- Push notification tokens: to deliver medication reminders and check-in prompts you request.
2.3 Information We Do NOT Collect
- We do not collect precise GPS location.
- We do not collect contacts, photos, or camera data (unless you attach a photo to a journal entry — that photo is stored locally on your device).
- Voice recordings are processed by Apple's on-device Speech Recognition framework by default. Raw audio is never transmitted to our servers unless you have explicitly enabled cloud voice processing in Privacy Settings.
| Data Category | Stored Where | Encrypted |
| Health & mood data | Device + Firebase (if synced) | AES-256 at rest, TLS 1.3 in transit |
| Journal entries | Device only by default | iOS Data Protection (AES-256) |
| Voice transcripts | Device only by default | iOS Data Protection |
| Medication info | Device + Firebase (if synced) | AES-256 at rest |
| Account email | Firebase Auth | TLS 1.3 in transit |
| Crash reports | Firebase Crashlytics | No PHI included |
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: deliver personalised CBT programmes, mood tracking, sleep coaching, AI insights, and medication reminders.
- Generate AI insights: our local rules engine analyses your data on-device to generate wellness suggestions. Cloud AI analysis (via third-party API) is only performed if you have explicitly opted in under Privacy Settings.
- Send reminders: deliver medication and check-in notifications at times you have configured.
- Improve the Service: use aggregated, anonymised analytics to understand feature usage and improve the app. Your individual health data is never used for this purpose.
- Provide support: respond to your support requests.
- Comply with law: meet legal obligations and enforce our Terms of Service.
Legal basis (GDPR)
We process health data on the basis of your explicit consent (Art. 9(2)(a) GDPR). You may withdraw consent at any time in Settings → Privacy. Withdrawing consent does not affect the lawfulness of processing prior to withdrawal.
4. How We Share Your Information
We do not sell your personal information. We do not share your health data for advertising or marketing purposes.
We may share information with:
- Service providers: Firebase (Google) for authentication, database, crash reporting, and push notifications — governed by a signed Business Associate Agreement (BAA) and Google's Data Processing Terms.
- AI providers (opt-in only): if you enable cloud AI, anonymised, non-identifying contextual data (aggregated mood trends, not verbatim journal text) may be shared with our AI provider. You can disable this at any time.
- Caregivers (opt-in only): if you invite a caregiver, they can see only your medication adherence percentages and mood trend summaries — not your journal entries, test results, or thought records — unless you explicitly grant expanded access.
- Legal authorities: if required by law, court order, or to protect the safety of users or the public. We will notify you unless legally prohibited from doing so.
- Business transfers: in the event of a merger or acquisition, your data will be subject to the same privacy protections and you will be notified before any transfer occurs.
5. Health Information
NeuroAmaze handles mental health information with heightened care. Health data you enter — including mood, symptoms, sleep, journal entries, test results, and medications — constitutes sensitive personal data under GDPR and Consumer Health Data under Washington State's My Health MY Data Act and similar state laws.
We apply the following additional protections to health data:
- Health data is never included in any advertising profile or shared with advertising networks.
- Health data is excluded from our anonymised analytics pipeline.
- Mental health test results (PHQ-9, GAD-7, etc.) are stored encrypted on your device only and are not synced to our cloud servers unless you enable iCloud backup.
- If you enable iCloud backup, data is end-to-end encrypted before transmission — NeuroAmaze servers cannot read your backed-up data.
For detailed information about how we handle consumer health data under applicable state laws, please see our Consumer Health Data Privacy Notice.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
| Data Type | Retention Period | Notes |
| Account data | Until account deletion | Deleted within 30 days of request |
| Health and wellness data | Until account deletion or manual deletion | You can delete individual entries at any time |
| Anonymised analytics | Up to 24 months | Cannot be linked back to you |
| Crash reports | 90 days | No personal health data included |
| Support correspondence | 2 years after resolution | Used for quality and safety purposes |
When you delete your account, we will delete or anonymise all your personal data within 30 days, except where we are required to retain it for legal obligations (e.g., financial transaction records).
7. Your Rights
Depending on where you live, you may have the following rights. You can exercise most of these directly in the app under Settings → Privacy → Your Data Rights.
| Right | Description | How to Exercise |
| Access | Request a copy of your personal data | Settings → Export My Data |
| Correction | Correct inaccurate data | Edit entries directly in the app |
| Deletion | Delete your account and all data | Settings → Delete Account |
| Portability | Export data in JSON format | Settings → Export My Data |
| Restrict processing | Opt out of specific processing | Settings → Privacy toggles |
| Withdraw consent | Revoke consent for health data processing | Settings → Privacy → Consent |
| Opt out of sale/sharing | We do not sell data — this right is satisfied by default | N/A |
| Non-discrimination | Exercising your rights will not affect your service | Guaranteed |
To exercise rights not available in-app, or if you have concerns, contact us at privacy@neuroamaze.com. We will respond within 45 days (extendable by 45 days with notice).
EU/UK residents: You have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your country's data protection authority in the EU).
8. Children's Privacy (COPPA)
NeuroAmaze is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Service without a parent or guardian's involvement.
If a parent or guardian becomes aware that their child under 13 has provided personal information without consent, they should contact us at privacy@neuroamaze.com. We will delete such information within 30 days.
For users aged 13–17, we recommend parental involvement. Our onboarding includes age verification, and users under 16 in certain EU states require verifiable parental consent before we process their health data.
9. International Data Transfers
NeuroAmaze uses Firebase (Google Cloud) infrastructure. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred to and processed in the United States.
We ensure such transfers comply with applicable law through:
- Standard Contractual Clauses (SCCs): incorporated into our agreements with Google/Firebase.
- EU-US Data Privacy Framework: Google's participation where applicable.
- Data residency: where possible, we configure Firestore to store EU users' data in the
europe-west1 (Belgium) region.
10. Security
We implement industry-standard security measures including:
- AES-256 encryption for all data at rest on our servers
- TLS 1.3 for all data in transit
- iOS Data Protection (AES-256) for locally stored data
- Face ID / Touch ID app-level locking
- Automatic session lock after 5 minutes of inactivity
- Screenshot prevention in iOS app switcher
- Firebase App Check to prevent API abuse
- Regular security reviews and penetration testing
No method of transmission over the internet or electronic storage is 100% secure. If you become aware of any security issue, please contact security@neuroamaze.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the new policy with an updated "Last updated" date
- Sending a push notification or in-app message for significant changes
- Emailing you at the address associated with your account for changes that materially affect your rights
Continued use of the Service after the effective date of the updated policy constitutes acceptance of the changes.