Peak Mind Coach — iOS and web · What we collect, how consent controls every use, and your rights
Version 3.0 — presented at account creation · Effective: July 6, 2026 · Prepared July 2026
This Policy is the companion to our Terms of Service (Version 3.0). The Terms govern the rules of using the Service; this Policy describes what data we collect, why, who can see it, and how to control it.
This Policy covers personal data processed through Peak Mind Coach for Performers, Leaders, Engineers, and enterprise organizations. For enterprise deployments, the organization may be an independent controller of some data; the enterprise agreement allocates those responsibilities. This Policy should be read with the Terms of Service and, where applicable, the Consumer Health Data Privacy Policy, your executed Biometric Releases, and the Genomic Data Consent. Because Peak Mind is not a HIPAA-covered entity, we treat ourselves as a vendor of personal health records under the FTC Health Breach Notification Rule: any unauthorized disclosure of your identifiable health information is a reportable breach, and our consent architecture exists to make such disclosures structurally impossible rather than merely prohibited.
We classify everything we collect into the classes below. The class determines the consent required, how long we keep it, how it is de-identified, and who can access it. Together with the purposes in Section 4 and the retention periods in Section 9, this table is our notice at collection under state privacy law.
| Class | Examples | Sensitivity |
|---|---|---|
| Account & identity | Name, email, date of birth (for the 18+ age gate), role, org membership, device/install ID | Personal information |
| Assessment & psychometric | Mental-performance assessments, capacity checks, brain-game and RCI reads | Health-adjacent; consumer health data |
| Daily readiness & check-ins | Readiness scores, mood, stress, sleep-adjacent self-report | Health-adjacent; consumer health data |
| Leader / deployment ratings | Coach observations and deployment ratings about a named Performer | Personal; employment context |
| Narrative & identity work | Free-text reflections, journaling, presenting complaint | Health-adjacent; may embed sensitive data |
| Goals & events | Goals, event debriefs, performance narratives | Personal |
| Biometric — cardiac | Wearable heart rate / HRV via HealthKit (optional) | Sensitive / biometric identifier |
| Biometric — neural | EEG / neural-signal reads (optional sensor) | Sensitive / neural data |
| Biometric — ocular | Eye-tracking data (optional sensor) | Sensitive / biometric identifier |
| Biometric — voice | Voice features extracted on-device (optional) | Sensitive / biometric identifier |
| Genomic | Imported genetic data, e.g., from 23andMe (optional) | Sensitive / genetic; implicates relatives |
| Location & environment | Coarse venue/location and context (optional) | Sensitive if precise; strong re-identification vector |
| Derived / AI outputs | Scores, insights, coaching outputs, labels | Inherits the sensitivity of its sources |
3.1 Per-record consent. Every record we capture is stamped, at the moment of capture, with the consent scopes then active on your account and the version of the consent text you agreed to. Consent changes create new entries in an append-only record; nothing is overwritten. This means we can prove — for any individual record — exactly what you permitted when it was collected, and we can produce that receipt to you, to a regulator, or to an auditor.
3.2 Prospective only. Turning a scope on applies from that moment forward; it never retroactively authorizes use of data captured before you enabled it. Turning a scope off stops the associated collection and excludes your data from all future uses of that scope, as described in Section 5.5.
3.3 Versioned consent text. We retain the exact wording of every consent version you agreed to, and the record of your acceptance of these documents at account creation. Material changes to any purpose require your renewed consent — we do not silently expand what a scope means.
5.1 Cloud AI processing today. Some features send data to cloud AI providers (currently OpenAI) to generate assessments, reads, and coaching outputs. This processing operates under a data-processing agreement on API terms under which the provider does not use our users’ data to train its models. The provider may retain API inputs and outputs for up to 30 days for abuse monitoring before deletion; we disclose this window honestly rather than overstating our current terms, and we are pursuing the provider’s zero-data-retention control for eligible endpoints, whose status is published in our sub-processor register.
5.2 On-device migration. We are migrating sensitive inference to on-device processing (Apple platforms), which keeps health and neural data on your device. HealthKit data is never used for advertising or data-brokering and is handled per Apple’s requirements.
5.3 Commercial Model Development & Dataset Licensing (opt-in). If you enable this scope: (a) your data may be used, in de-identified form, to train and evaluate models Peak Mind commercializes or licenses to third parties; and (b) your data may be included in de-identified datasets licensed to third parties under contracts that prohibit re-identification and any onward disclosure that would enable it. Categorical exclusions that no setting can override: biometric identifiers and biometric information are never sold or licensed in any form; neural data is never sold or licensed; genomic data is never sold or licensed; and consumer health data of residents of Washington, Nevada, and states with equivalent authorization statutes is excluded from licensed datasets, because those statutes condition any sale of consumer health data on a signed, purchaser-specific authorization that a prospective toggle cannot provide. Identified personal data is never sold by anyone, ever: nothing reasonably linkable to you is delivered to any licensee.
5.4 Is that a “sale” or “sharing”? Under some state laws, licensing de-identified data that originated from your personal information may still be treated as a “sale” or “sharing.” We take both protective positions at once. First, our de-identified data qualifies for the statutory de-identification exemption: we maintain technical safeguards and business processes that prohibit re-identification, processes that prevent inadvertent release, and we publicly commit to maintaining and using de-identified data only in de-identified form and never attempting to re-identify it, as California Civil Code §1798.140(m) requires. Second, without relying on that exemption, we treat your opt-in as authorization and honor the corresponding rights at all times: you can opt out of sale/sharing (which turns the scope off), we honor Global Privacy Control signals as an automatic opt-out, and we provide a standing “Do Not Sell or Share My Personal Information” control regardless of your state.
5.5 Revocation and trained models. When you revoke any research or commercial scope: collection for that scope stops immediately; your data is excluded from every future training set and dataset build; and your raw records are deleted or de-linked per Section 9. Models trained while your consent was active are retained — a trained model does not store your raw records, and per-withdrawal retraining is generally infeasible. We disclose this before you opt in so your decision is informed, and our per-record consent ledger preserves proof that every training input was lawfully consented at the time of training. Datasets delivered to licensees before your revocation remain governed by contracts prohibiting re-identification; subsequent deliveries exclude your data.
8.1 Everyone, everywhere. Regardless of where you live, you can: access your data; export it in JSON before deletion; correct it; delete it; and grant or revoke every optional scope in the Consent Center with equal ease. We do not discriminate against you for exercising any right.
8.2 US state rights. Notice at collection: Sections 2, 4, and 9 together constitute our notice at collection. Sensitive personal information (which under California law includes neural data): collected only with your per-scope consent, and you may limit its use to service delivery at any time via “Limit the Use of My Sensitive Personal Information,” which disables all optional uses of those classes. Sale/sharing: see Section 5.4 — the opt-out control and Global Privacy Control support apply at all times. Verification and appeals: we verify requests against your authenticated account and offer an appeal path for denied requests. Authorized agents may act for you as the law provides.
8.3 EU/UK (if applicable). If GDPR/UK GDPR applies to you, you additionally have rights to restriction, objection, and portability, and to lodge a complaint with a supervisory authority. Our legal bases are contract necessity, legitimate interests, and — for special-category data — your explicit consent under Article 9(2)(a). Where processing is high-risk we conduct data protection impact assessments before launch in those markets.
8.4 Consumer health data. If you are in Washington or another state with a consumer-health-data law, the separate Consumer Health Data Privacy Policy applies to readiness, mood, assessment, narrative, biometric, and similar data, including its own consent and rights mechanics. As Section 5.3 states, your consumer health data is never included in licensed datasets if you reside in such a state.
Deletion timelines. We acknowledge verified deletion requests promptly and complete them within 45 days (extendable once as the law permits, with notice). Deletion propagates to sub-processors and to backups on their defined rotation cycles, and covers derived records unless de-identified. Deletion does not reach data we are legally required to retain, the consent records above, or models already trained under Section 5.5 — and no deleted row remains reconstructable from our production systems.
| Data class | Baseline retention | Notes |
|---|---|---|
| Account & identity | Life of account + limited legal tail | Deleted/anonymized after closure following a legal-hold check |
| Assessments, readiness, goals, events | Life of account | You may delete individual items at any time |
| Narrative / reflections / presenting complaint | Life of account; item-level deletable | Free text may embed sensitive data; granular deletion supported |
| Biometric (HR/HRV, EEG, eye, voice) | Shortest period serving the disclosed purpose; destroyed on scope revocation | Per the published Biometric Retention & Destruction Schedule |
| Genomic | Only while the genomic scope is active | Destroyed on revocation or deletion request; source-service terms honored |
| Location & environment | Short retention; coarsened quickly | Precise location minimized; aggregates preferred |
| Derived / AI outputs | Tied to their source records | De-linked or deleted with the source unless de-identified |
| Consent records | Retained beyond data deletion | Kept as evidence of lawful basis for uses that occurred while consent was active |
We encrypt data in transit and at rest, apply least-privilege and role-based access with row-level security, gate sensitive classes (biometric, neural, genomic) to a minimal set of personnel with documented need, log access to identified and sensitive data in tamper-evident audit logs, time-box and log any support access, and maintain a documented incident-response process. If a breach affects you, we will notify you and regulators within the strictest applicable timeline — including the FTC Health Breach Notification Rule for identifiable health information and the GDPR’s 72-hour authority notification where it applies. Security-framework certification (SOC 2 direction) is in progress and will be reflected in the sub-processor register when audited; we do not display compliance seals we have not earned.
If we transfer EU/UK personal data internationally, we rely on Standard Contractual Clauses or the UK IDTA plus a transfer risk assessment, or another valid mechanism. Any business transfer under Section 12 to an acquirer in another jurisdiction must satisfy the same mechanisms. Data-residency options for enterprise customers are documented in the enterprise agreement.
If Peak Mind is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your data and the associated consent records may transfer to the successor. The successor inherits your exact, per-record consent selections and is bound to honor the consent scope and privacy commitments in effect when your data was collected; any materially different use requires notice and choice first. Genomic data receives extra protection: it will not transfer without individualized advance notice and a pre-transfer window in which you can delete it. We will notify you of any such transfer as required by law. In plain terms: an acquirer buys our obligations to you along with the data — your consent travels with your data and binds whoever holds it.
The Service is for adults 18 and older. We use an age gate at account creation, the Service is not directed to children, and we do not knowingly collect data from anyone under 18. If we learn we have collected data from a person under 18, we delete it and close the account.
Material changes to this Policy are versioned, summarized in a change log, and require your documented acknowledgement before continued use; the text of every version you accepted is retained. Questions and rights requests: Info@Peakmindmechanics.com or in-app. Postal: Peak Mind Mechanics, 455 Market St Ste 1940 PMB 202903, San Francisco, California 94105-2448 US.
© 2025–2026 Peak Mind Mechanics® — Steve Vasco