Privacy Policy

Peak Mind Coach — iOS and web · What we collect, how consent controls every use, and your rights

Version 3.0 — presented at account creation · Effective: July 6, 2026 · Prepared July 2026

This Policy is the companion to our Terms of Service (Version 3.0). The Terms govern the rules of using the Service; this Policy describes what data we collect, why, who can see it, and how to control it.

1. Scope and Roles

This Policy covers personal data processed through Peak Mind Coach for Performers, Leaders, Engineers, and enterprise organizations. For enterprise deployments, the organization may be an independent controller of some data; the enterprise agreement allocates those responsibilities. This Policy should be read with the Terms of Service and, where applicable, the Consumer Health Data Privacy Policy, your executed Biometric Releases, and the Genomic Data Consent. Because Peak Mind is not a HIPAA-covered entity, we treat ourselves as a vendor of personal health records under the FTC Health Breach Notification Rule: any unauthorized disclosure of your identifiable health information is a reportable breach, and our consent architecture exists to make such disclosures structurally impossible rather than merely prohibited.

2. Data We Collect

We classify everything we collect into the classes below. The class determines the consent required, how long we keep it, how it is de-identified, and who can access it. Together with the purposes in Section 4 and the retention periods in Section 9, this table is our notice at collection under state privacy law.

ClassExamplesSensitivity
Account & identityName, email, date of birth (for the 18+ age gate), role, org membership, device/install IDPersonal information
Assessment & psychometricMental-performance assessments, capacity checks, brain-game and RCI readsHealth-adjacent; consumer health data
Daily readiness & check-insReadiness scores, mood, stress, sleep-adjacent self-reportHealth-adjacent; consumer health data
Leader / deployment ratingsCoach observations and deployment ratings about a named PerformerPersonal; employment context
Narrative & identity workFree-text reflections, journaling, presenting complaintHealth-adjacent; may embed sensitive data
Goals & eventsGoals, event debriefs, performance narrativesPersonal
Biometric — cardiacWearable heart rate / HRV via HealthKit (optional)Sensitive / biometric identifier
Biometric — neuralEEG / neural-signal reads (optional sensor)Sensitive / neural data
Biometric — ocularEye-tracking data (optional sensor)Sensitive / biometric identifier
Biometric — voiceVoice features extracted on-device (optional)Sensitive / biometric identifier
GenomicImported genetic data, e.g., from 23andMe (optional)Sensitive / genetic; implicates relatives
Location & environmentCoarse venue/location and context (optional)Sensitive if precise; strong re-identification vector
Derived / AI outputsScores, insights, coaching outputs, labelsInherits the sensitivity of its sources

3. How Consent Controls Use

3.1 Per-record consent. Every record we capture is stamped, at the moment of capture, with the consent scopes then active on your account and the version of the consent text you agreed to. Consent changes create new entries in an append-only record; nothing is overwritten. This means we can prove — for any individual record — exactly what you permitted when it was collected, and we can produce that receipt to you, to a regulator, or to an auditor.

3.2 Prospective only. Turning a scope on applies from that moment forward; it never retroactively authorizes use of data captured before you enabled it. Turning a scope off stops the associated collection and excludes your data from all future uses of that scope, as described in Section 5.5.

3.3 Versioned consent text. We retain the exact wording of every consent version you agreed to, and the record of your acceptance of these documents at account creation. Material changes to any purpose require your renewed consent — we do not silently expand what a scope means.

4. How We Use Data (By Purpose)

  • Operate the Service (always on): deliver assessments, insights, coaching, and the role-based views you have permitted; secure the Service; comply with law. Legal basis: contract necessity and legitimate interests; explicit consent where required for sensitive classes.
  • Product improvement & analytics (opt-in): measure quality and evaluate features using the minimum data necessary. No third-party advertising or analytics SDK ever receives health-adjacent, biometric, neural, or genomic data.
  • AI coaching improvement (opt-in): improve Peak Mind’s own coaching models using de-identified data. This scope is internal-only: nothing under it is shared with our AI providers or any other third party.
  • Research scopes (each separately opt-in): internal research; de-identified sharing with named academic partners; aggregate published studies; open dataset contribution.
  • Commercial Model Development & Dataset Licensing (opt-in): described in Section 5.3, with the categorical exclusions listed there.
  • Sensor and genomic scopes (each separately opt-in): collection is per-sensor; a sensor scope authorizes collection and service delivery only — research or commercial use of sensor data additionally requires the corresponding research or commercial scope and is subject to the exclusions in Sections 5.3 and 6.

5. AI Processing, Model Training, and the Commercial Scope

5.1 Cloud AI processing today. Some features send data to cloud AI providers (currently OpenAI) to generate assessments, reads, and coaching outputs. This processing operates under a data-processing agreement on API terms under which the provider does not use our users’ data to train its models. The provider may retain API inputs and outputs for up to 30 days for abuse monitoring before deletion; we disclose this window honestly rather than overstating our current terms, and we are pursuing the provider’s zero-data-retention control for eligible endpoints, whose status is published in our sub-processor register.

5.2 On-device migration. We are migrating sensitive inference to on-device processing (Apple platforms), which keeps health and neural data on your device. HealthKit data is never used for advertising or data-brokering and is handled per Apple’s requirements.

5.3 Commercial Model Development & Dataset Licensing (opt-in). If you enable this scope: (a) your data may be used, in de-identified form, to train and evaluate models Peak Mind commercializes or licenses to third parties; and (b) your data may be included in de-identified datasets licensed to third parties under contracts that prohibit re-identification and any onward disclosure that would enable it. Categorical exclusions that no setting can override: biometric identifiers and biometric information are never sold or licensed in any form; neural data is never sold or licensed; genomic data is never sold or licensed; and consumer health data of residents of Washington, Nevada, and states with equivalent authorization statutes is excluded from licensed datasets, because those statutes condition any sale of consumer health data on a signed, purchaser-specific authorization that a prospective toggle cannot provide. Identified personal data is never sold by anyone, ever: nothing reasonably linkable to you is delivered to any licensee.

5.4 Is that a “sale” or “sharing”? Under some state laws, licensing de-identified data that originated from your personal information may still be treated as a “sale” or “sharing.” We take both protective positions at once. First, our de-identified data qualifies for the statutory de-identification exemption: we maintain technical safeguards and business processes that prohibit re-identification, processes that prevent inadvertent release, and we publicly commit to maintaining and using de-identified data only in de-identified form and never attempting to re-identify it, as California Civil Code §1798.140(m) requires. Second, without relying on that exemption, we treat your opt-in as authorization and honor the corresponding rights at all times: you can opt out of sale/sharing (which turns the scope off), we honor Global Privacy Control signals as an automatic opt-out, and we provide a standing “Do Not Sell or Share My Personal Information” control regardless of your state.

5.5 Revocation and trained models. When you revoke any research or commercial scope: collection for that scope stops immediately; your data is excluded from every future training set and dataset build; and your raw records are deleted or de-linked per Section 9. Models trained while your consent was active are retained — a trained model does not store your raw records, and per-withdrawal retraining is generally infeasible. We disclose this before you opt in so your decision is informed, and our per-record consent ledger preserves proof that every training input was lawfully consented at the time of training. Datasets delivered to licensees before your revocation remain governed by contracts prohibiting re-identification; subsequent deliveries exclude your data.

6. Sharing and Disclosure

  • We do not sell identified personal data. No name-attached, contact-attached, or otherwise reasonably-linkable record is ever sold or licensed. We do not sell, lease, trade, or profit from biometric identifiers or biometric information under any circumstance.
  • Sub-processors: vendors that process data to run the Service (cloud AI, database/backend, hosting, payments, speech, transcription, email, diagnostics) operate under data-processing agreements and appear in our published sub-processor register, which we keep current and review before onboarding any new vendor. Diagnostics payloads are scrubbed of personal information, and no advertising SDK is embedded in the Service.
  • Consented recipients: academic partners (de-identified), publication venues (aggregate only), open-dataset users (de-identified; never sensor or genomic data), and commercial licensees (de-identified; subject to Section 5.3’s exclusions) — each only under its matching opt-in scope.
  • Your Leader / organization: only what your visibility scope permits; genomic data and neural data are excluded from Leader and enterprise visibility in all cases, and organizations are contractually barred from using your data for employment decisions.
  • Legal: we may disclose data to comply with law or valid legal process, and we will notify you unless legally barred.

7. De-Identification — Our Standard and Its Honest Limits

  • De-identification follows a documented method — expert determination and/or a defined k-anonymity threshold for structured fields — moving toward differential-privacy techniques for aggregate releases where feasible. Direct identifiers are removed; quasi-identifiers (location, timestamps, rare patterns) are generalized or suppressed.
  • Every de-identified dataset records the method, parameters, and date used, so the standard applied is provable.
  • Recipients are contractually prohibited from re-identifying data or disclosing it in ways that would enable re-identification, and we publicly commit to never re-identifying de-identified data ourselves.
  • What we will not claim: rich longitudinal, genomic, and neural data carries inherent re-identification risk — genomic data is uniquely identifying, and long time-series of biometric and behavioral signals can act as a fingerprint. That is one reason genomic, neural, and biometric classes are excluded from licensing outright. We never claim de-identified data “cannot be re-identified”; our claim is that it is de-identified to a documented standard that makes re-identification unlikely under defined conditions, backed by contractual prohibitions.

8. Your Rights

8.1 Everyone, everywhere. Regardless of where you live, you can: access your data; export it in JSON before deletion; correct it; delete it; and grant or revoke every optional scope in the Consent Center with equal ease. We do not discriminate against you for exercising any right.

8.2 US state rights. Notice at collection: Sections 2, 4, and 9 together constitute our notice at collection. Sensitive personal information (which under California law includes neural data): collected only with your per-scope consent, and you may limit its use to service delivery at any time via “Limit the Use of My Sensitive Personal Information,” which disables all optional uses of those classes. Sale/sharing: see Section 5.4 — the opt-out control and Global Privacy Control support apply at all times. Verification and appeals: we verify requests against your authenticated account and offer an appeal path for denied requests. Authorized agents may act for you as the law provides.

8.3 EU/UK (if applicable). If GDPR/UK GDPR applies to you, you additionally have rights to restriction, objection, and portability, and to lodge a complaint with a supervisory authority. Our legal bases are contract necessity, legitimate interests, and — for special-category data — your explicit consent under Article 9(2)(a). Where processing is high-risk we conduct data protection impact assessments before launch in those markets.

8.4 Consumer health data. If you are in Washington or another state with a consumer-health-data law, the separate Consumer Health Data Privacy Policy applies to readiness, mood, assessment, narrative, biometric, and similar data, including its own consent and rights mechanics. As Section 5.3 states, your consumer health data is never included in licensed datasets if you reside in such a state.

9. Retention and Deletion

Deletion timelines. We acknowledge verified deletion requests promptly and complete them within 45 days (extendable once as the law permits, with notice). Deletion propagates to sub-processors and to backups on their defined rotation cycles, and covers derived records unless de-identified. Deletion does not reach data we are legally required to retain, the consent records above, or models already trained under Section 5.5 — and no deleted row remains reconstructable from our production systems.

Data classBaseline retentionNotes
Account & identityLife of account + limited legal tailDeleted/anonymized after closure following a legal-hold check
Assessments, readiness, goals, eventsLife of accountYou may delete individual items at any time
Narrative / reflections / presenting complaintLife of account; item-level deletableFree text may embed sensitive data; granular deletion supported
Biometric (HR/HRV, EEG, eye, voice)Shortest period serving the disclosed purpose; destroyed on scope revocationPer the published Biometric Retention & Destruction Schedule
GenomicOnly while the genomic scope is activeDestroyed on revocation or deletion request; source-service terms honored
Location & environmentShort retention; coarsened quicklyPrecise location minimized; aggregates preferred
Derived / AI outputsTied to their source recordsDe-linked or deleted with the source unless de-identified
Consent recordsRetained beyond data deletionKept as evidence of lawful basis for uses that occurred while consent was active

10. Security and Breach Notification

We encrypt data in transit and at rest, apply least-privilege and role-based access with row-level security, gate sensitive classes (biometric, neural, genomic) to a minimal set of personnel with documented need, log access to identified and sensitive data in tamper-evident audit logs, time-box and log any support access, and maintain a documented incident-response process. If a breach affects you, we will notify you and regulators within the strictest applicable timeline — including the FTC Health Breach Notification Rule for identifiable health information and the GDPR’s 72-hour authority notification where it applies. Security-framework certification (SOC 2 direction) is in progress and will be reflected in the sub-processor register when audited; we do not display compliance seals we have not earned.

11. International Transfers

If we transfer EU/UK personal data internationally, we rely on Standard Contractual Clauses or the UK IDTA plus a transfer risk assessment, or another valid mechanism. Any business transfer under Section 12 to an acquirer in another jurisdiction must satisfy the same mechanisms. Data-residency options for enterprise customers are documented in the enterprise agreement.

12. Business Transfers

If Peak Mind is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your data and the associated consent records may transfer to the successor. The successor inherits your exact, per-record consent selections and is bound to honor the consent scope and privacy commitments in effect when your data was collected; any materially different use requires notice and choice first. Genomic data receives extra protection: it will not transfer without individualized advance notice and a pre-transfer window in which you can delete it. We will notify you of any such transfer as required by law. In plain terms: an acquirer buys our obligations to you along with the data — your consent travels with your data and binds whoever holds it.

13. Age Requirement

The Service is for adults 18 and older. We use an age gate at account creation, the Service is not directed to children, and we do not knowingly collect data from anyone under 18. If we learn we have collected data from a person under 18, we delete it and close the account.

14. Changes and Contact

Material changes to this Policy are versioned, summarized in a change log, and require your documented acknowledgement before continued use; the text of every version you accepted is retained. Questions and rights requests: Info@Peakmindmechanics.com or in-app. Postal: Peak Mind Mechanics, 455 Market St Ste 1940 PMB 202903, San Francisco, California 94105-2448 US.

© 2025–2026 Peak Mind Mechanics® — Steve Vasco