How NeuroRest handles your personal information and EEG data.
Last updated: 2 May 2026Effective date: 2 May 2026Version: 1.0
NeuroRest ("NeuroRest", "we", "us", "our") operates the NeuroRest mobile application (the "App") and any related websites, hardware companion accessories, and services (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and the choices you have regarding that information.
We pay particular attention to the electroencephalographic (EEG) data generated when you use a compatible EEG accessory with the App, because this kind of data is sensitive and is treated as a special category of personal data under several privacy laws.
By installing or using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1.Who is the data controller?
The data controller responsible for your personal data is:
NeuroRest
Email: ntu.neurorest@gmail.com
Postal address: No. 1, Sec. 4, Roosevelt Rd., Da'an Dist., Taipei City 106216, Taiwan (R.O.C.)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland and we are required to designate a representative or Data Protection Officer (DPO), the contact details will be added to this Policy.
2.Information we collect
2.1 Information you provide
Account information (only if you choose to create an account): display name, email address, password hash, and optional profile preferences such as preferred language or sleep goal.
Hardware pairing information: the model and firmware version of any EEG accessory you pair with the App.
User-generated content: notes, ratings, or feedback you submit through the App.
Scope — this section applies only when an EEG accessory becomes available in a future release: the current version of NeuroRest in the App Store does not support an EEG accessory and does not collect any EEG / brainwave data. The text below describes how Neural Data would be handled when an EEG accessory is introduced; we will update this Policy and notify users at that time.
When you connect a compatible EEG accessory and start a session, the App will receive a continuous stream of brainwave readings, typically expressed as voltage measurements per channel and derived band-power values (delta, theta, alpha, beta). The App will also compute derived metrics — for example, an estimate of your transition between light sleep and deep sleep — and adjust the binaural-beat audio in response.
By default, Neural Data is processed locally on your device and is not transmitted to our servers. If you opt in to cloud features (such as long-term sleep history or AI-personalized programs), Neural Data may be transmitted to and processed by our cloud infrastructure or by the third-party service providers listed in Section 6.
We do not use Neural Data to attempt to infer medical diagnoses, mental-health conditions, identity, or thoughts.
2.3 Audio and microphone data
The App can play audio. The App does not record from the microphone unless you explicitly enable an optional feature (for example, ambient-noise calibration). If enabled, the audio sample is processed in memory and is not stored or transmitted.
2.4 Device, technical, and usage information
We collect technical information that is generated automatically:
Device model, operating-system version, language, time zone, and screen size.
App version, crash reports, and diagnostic logs.
A randomly generated installation identifier (we do not use the iOS Identifier for Advertisers / IDFA).
Aggregate, non-identifying usage events such as "session started" or "session completed".
2.5 Information from connected services
If you connect optional integrations such as Apple Health, we read or write only the specific data categories you grant permission for (for example, sleep analysis). We do not read other Health data.
2.6 Information we do not collect
We do not collect financial-account numbers, government-issued ID numbers, precise location, contact lists, photos, or files outside the App's own storage. We do not use facial-recognition data.
3.How we use the information
We use the information described above for the following purposes:
Provide and operate the Service, including delivering personalized binaural-beat audio that responds to your Neural Data.
Pair and communicate with EEG accessories over Bluetooth.
Improve and develop new features, including training and refining our AI models on aggregated and de-identified data.
Diagnose technical problems and prevent abuse, including monitoring crashes and detecting fraud.
Communicate with you about the Service (transactional emails, security notices, and — only if you opt in — product news).
Comply with legal obligations and respond to lawful requests.
We do not use your data for advertising, profiling for marketing, or sale to third parties.
4.Legal bases for processing (EEA, UK, Switzerland)
If you are in the EEA, UK, or Switzerland, we process your personal data on the following legal bases:
Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) — for processing Neural Data, which is treated as health-related personal data, and for any optional cloud features. You may withdraw consent at any time through the App's Settings.
Performance of a contract (Art. 6(1)(b)) — to deliver the Service you requested when you installed the App.
Legitimate interests (Art. 6(1)(f)) — to keep the Service secure and to improve it, balanced against your rights and freedoms.
Legal obligation (Art. 6(1)(c)) — when required by applicable law.
5.How long we keep information
Data category
Retention period
Account information
While your account is active, plus 90 days after deletion request
Neural Data processed locally
Stored on device until you delete it through the App
Neural Data uploaded to cloud (opt-in)
Up to 12 months unless you choose a longer history setting
De-identified, aggregated research data
Indefinitely (cannot be linked back to you)
Crash logs and diagnostic data
90 days
Support correspondence
24 months
After the retention period, we delete or de-identify the data using industry-standard methods.
6.With whom we share information
We share personal data only as described below.
Service providers acting on our behalf, under written agreements that limit them to processing data for our purposes only. Categories include cloud hosting, crash reporting, and customer-support tools.
Apple, when you download the App, make in-app purchases, or submit reviews. Apple's privacy practices apply: see apple.com/legal/privacy.
Authorities and other parties when legally required, such as in response to a valid subpoena, court order, or to protect the rights, property, or safety of any person.
Successor entities in the context of a merger, acquisition, or asset sale — in which case we will give you notice and an option to delete your data before any transfer.
We do not sell or rent your personal data, and we do not share Neural Data with advertisers or data brokers.
If we transfer personal data outside the EEA, UK, Switzerland, or your country of residence, we use safeguards required by applicable law, such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.
8.Security
We use a combination of technical and organizational safeguards designed to protect your data, including:
TLS 1.2+ encryption for data in transit;
AES-256 encryption for Neural Data at rest in our cloud (where applicable);
Access controls limiting employee access to personal data on a need-to-know basis;
Regular vulnerability scans and security reviews of the App and infrastructure.
No method of electronic storage is fully secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities to the extent required by law.
9.Your rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
Access a copy of the data we hold about you.
Rectify inaccurate data.
Erase your data ("right to be forgotten").
Restrict or object to certain processing.
Receive your data in a portable, machine-readable format.
Withdraw consent at any time, without affecting the lawfulness of processing already carried out.
Lodge a complaint with a supervisory authority (EEA: your local Data Protection Authority; UK: the Information Commissioner's Office).
You can exercise most of these rights directly through the App's Settings → Privacy Controls, or by emailing ntu.neurorest@gmail.com. We will respond within the time required by applicable law (generally 30 days).
California residents (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to opt out of "sale" or "sharing" of personal information (we do not sell or share for cross-context behavioral advertising), and to limit use of sensitive personal information. To exercise these rights, email ntu.neurorest@gmail.com with the subject line "California Privacy Request".
We do not discriminate against users who exercise their privacy rights.
Other jurisdictions
Residents of other regions, including Brazil (LGPD), Canada (PIPEDA), Australia, Japan, South Korea, and Taiwan (個人資料保護法), may have similar rights and may contact us at the same address.
10.Children
The Service is not intended for, and we do not knowingly collect personal data from, anyone under 16 years old. If you believe a child has provided us with personal data, please contact ntu.neurorest@gmail.com and we will delete it.
11.Health and medical disclaimer
NeuroRest is a wellness product designed to support relaxation and the user's listening experience. It is not a medical device, is not intended to diagnose, treat, cure, or prevent any disease, sleep disorder, or other medical condition, and is not a substitute for professional medical advice, diagnosis, or treatment.
The Neural Data the App processes is used only to personalize the audio experience in real time. Always seek the advice of a qualified health-care provider for any questions regarding a medical or psychological condition.
12.Cookies and similar technologies
The App itself does not use cookies. Our marketing website may use a small number of essential and analytics cookies; please consult the cookie banner on the website for choices.
13.Changes to this Policy
We may update this Policy to reflect changes to our practices or for legal reasons. The "Last updated" date at the top of this Policy will reflect the latest revision. If the changes are material, we will provide additional notice — for example, an in-app notification — before they take effect.
Postal address: No. 1, Sec. 4, Roosevelt Rd., Da'an Dist., Taipei City 106216, Taiwan (R.O.C.)
If you contact us about a privacy request, please describe the request clearly and confirm the email address associated with your account so we can verify your identity.