neuroglympse

Legal

What we collect, how we use it, and what we never send

Covers both the diagnostic platform and the monitoring app, including the biometric data the app reads from your phone and the data it deliberately leaves there.

Collection

What data we collect

Health and identifying data

  • Name, email address, age, gender
  • Login credentials
  • Biometric signals — heart rate, HRV, oxygen saturation
  • Stress and sleep measures derived from those signals
  • Assessment results and clinical communications
  • Device and browser IP address, account activity
  • Geolocation — only with your permission
  • Google profile, if you register via Google

Technical data

  • Device metadata (OS, app version)
  • Interaction metadata (taps, swipes)
  • Crash reports and performance data

This is a statement about the monitoring app, not about clinical testing. Ocular motor assessment is performed by video-oculography — a recording device tracks your eye movement, and the recording and the values derived from it become part of your medical record. That data is retained as a clinical record and handled under the terms below. How the record is held.

Use

How we use your data

De-identified and aggregate data

  • Product research and development
  • Application performance improvement
  • Clinical trial research support, under separate authorization
  • Aggregate statistics

Health and identifying data

  • Operating and personalising your experience
  • Communicating important information
  • Complying with healthcare regulations
  • Facilitating clinical programs, with your consent

Protection

Security and data protection

Encryption

All data is encrypted in transit and at rest.

Compliance

We operate as a HIPAA-covered entity and apply the Security Rule’s administrative, physical and technical safeguards. Our security programme is modelled on ISO 27001 controls; we do not hold an ISO 27001 certification and do not claim one.

Infrastructure

Servers are hosted on Amazon Web Services using secure cloud infrastructure with multiple layers of protection.

Retention

Clinical records are kept for at least six years, or longer where state medical-record law requires it. App telemetry and marketing contact details can be deleted on request; the medical record cannot.

Your rights

You own your data

You can obtain a copy of your record, request a correction to it, request an accounting of disclosures, withdraw consent for anything consent-based, and opt out of marketing. You can have app telemetry and marketing contact details deleted.

Two limits, stated plainly. Your medical record cannot be deleted on request — retention is required by law, and a record that could be deleted on demand would be worth nothing to anyone who later needs to rely on it. And where litigation or an audit is reasonably anticipated, a hold suspends routine deletion within its scope. See Records & custody.

To exercise any of these rights, email support@neuroglympse.com or use the in-app contact form.

Transfers & incidents

Breach and transfer policies

Where your data is processed

NeuroGlympse provides care in the United States and processes data there, under HIPAA and applicable state law. We do not offer services in the EU or UK and do not represent ourselves as GDPR-compliant.

Breach notification

Following a breach of unsecured protected health information we notify affected individuals without unreasonable delay and no later than 60 days from discovery, and notify HHS as the Breach Notification Rule requires. We aim to reach affected people well inside that limit.

Business transfers

If NeuroGlympse undergoes a corporate transaction such as a merger, acquisition or bankruptcy, your data may transfer as part of our business assets, subject to this policy.

Special considerations

Additional terms

Children’s privacy

NeuroGlympse does not knowingly collect data from children under 13 without verified parental or legal guardian consent. If you believe we have inadvertently collected information from a child under 13, contact us immediately.

Cookies and website analytics

This marketing site runs no analytics or advertising trackers and sets no cookies of its own. Three things reach third parties: the enrollment forms are hosted by Typeform, so what you type into a form goes to Typeform; our web fonts are served by Google Fonts; and our story video is hosted on YouTube, embedded through youtube-nocookie.com so that YouTube sets no tracking cookies unless you press play. The Care Portal and the monitoring app are separate systems with their own notices. If you have a question about tracking, email support@neuroglympse.com.

Clinical program participation

If you enroll in a clinical program you must authorize data sharing with that program’s governing entity under a separate consent agreement, which sets out how your data will be used for research.

Policy updates

We may periodically update this policy. Material updates require review and re-acceptance before continued use.

HIPAA

Your rights under HIPAA, and how to enforce them

Our full Notice of Privacy Practices governs protected health information. The essentials belong here as well as in a PDF.

Reach our Privacy Officer

Email support@neuroglympse.com marked for the Privacy Officer, or call (504) 370-3910. We will provide a mailing address for written requests on request.

Request an accounting of disclosures

You are entitled to a list of the disclosures we have made of your protected health information, who received it, when and why. Ask and we will produce it.

Complain, without retaliation

You may complain to us, and you may file a complaint directly with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/hipaa. We will not retaliate against you for doing either.

Version history

What changed, and when

Privacy policy version history
EffectiveChange
26 August 2026Added the YouTube story-video embed to the list of third parties this site reaches. Scoped the imaging statement to the monitoring app, corrected the breach-notification timeline to the HIPAA rule, removed an ISO 27001 claim we do not hold as a certification, reclassified account-linked biometric data as personal rather than anonymous, and separated clinical-record retention from app telemetry.

Contact

Questions about your data

Our support team can help with any question or concern about your data. Email support@neuroglympse.com, or call (504) 370-3910.

Call usEnroll a patient