Privacy Policy
Cerebrum DAO Association
d/b/a Cortex App
Website: https://www.cerebrumdao.com/cortex-app
Effective Date: 2026-03-01 | Last Updated: 2026-03-19
1. Introduction
Cerebrum DAO Association, doing business as Cortex App (“we,” “us,” or “our”), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our applications, assessments, digital coaching services, and related offerings (collectively, the “Services”).
Our Services include, but are not limited to:
- Cortex App, a Brain Health App translating Cerebrum DAO's research into real-world tools for neurological wellbeing;
- The Brain Health Survey (BHS) assessment;
- Crypto wallet that allows users to store their crypto holdings with many features related to the NEURON token; this is a non-custodial wallet (no funds are held with the company).
This Privacy Policy applies to all users of our Services regardless of location. Certain sections provide additional information required by the laws of specific jurisdictions, including the European Union, United Kingdom, Switzerland, Australia, New Zealand, California, and other U.S. states with comprehensive privacy legislation.
By using our Services, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable law, we will obtain your consent before collecting or processing your personal data. If you do not agree with our practices, please do not use our Services.
2. Data Controller
For the purposes of applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection (FADP), the data controller responsible for your personal data is:
Cerebrum DAO Association d/b/a Cortex App
Email: [email protected]
3. Information We Collect
We collect the following categories of information when you use our Services:
3.1 Information You Provide Directly
- Account Information: Your name, email address, account credentials, and profile preferences.
- Payment Information: Subscription and payment details, processed by certified third-party payment providers. We do not store full payment card details on our servers.
- Profile Information: Your preferences, settings, profile picture, and any optional demographic information you choose to provide.
- Health and Wellness Information: Your BrainHealth Index (BHI) assessment results, including scores, trends, and progress across domains such as focus, stress management, and sleep quality; Brain Care Score data; cognitive assessment responses; and any other brain health or wellness information you voluntarily provide.
- Communications: Information you provide when you contact us for support, submit feedback, or respond to surveys.
3.2 Information Collected Automatically
- App and Website Usage Data: Interactions with our applications and website, engagement patterns, completed activities, feature usage, and session duration.
- Device and Technical Information: IP address, device type, operating system, browser type, device identifiers, and general (non-precise) location derived from your IP address.
- Cookies and Similar Technologies: Information collected through cookies, pixels, and similar tracking technologies as described in Section 9.
4. How We Use Your Information
4.1 Service Delivery and Performance
- Delivering and maintaining the Services, including the Brain Health Survey, BrainHealth Index assessments, Staking Mechanism, and related Crypto features and tools.
- Tracking your progress over time and generating insights based on your BrainHealth Index and activity data.
- Processing your subscription and payments.
4.2 Communications
- Sending service-related communications, including updates, reminders, coaching prompts, progress notifications, and support messages.
- Responding to your inquiries, feedback, and support requests.
- With your opt-in consent, sending informational communications about new features, research updates, or wellness content. You may unsubscribe at any time.
4.3 Product Improvement, Analytics, and Research
- Using anonymized and de-identified data to conduct research, generate aggregated insights, and produce data analytics and reporting on brain health trends, outcomes, and population-level insights.
- Analyzing usage patterns to optimize user experience and improve the quality and effectiveness of our Services.
- Improving the quality and effectiveness of communication, content, and support.
Note: “De-identified data” means data from which direct identifiers have been removed and which cannot reasonably be used to identify you. “Anonymized data” means data from which all direct and indirect personal identifiers have been permanently removed and which cannot reasonably be used to identify any individual. We maintain technical and organizational safeguards to prevent re-identification.
4.4 Security and Compliance
- Ensuring the security and integrity of our Services, preventing fraud, and detecting unauthorized access.
- Complying with applicable legal obligations, including tax, regulatory, and reporting requirements.
4.5 What We Do Not Do
- No tailored or one-to-one marketing. We do not use your personal data to send you personalized advertisements based on your health data, coaching interactions, or behavioral profile.
- No sale of personal data for marketing. We will never sell your identifiable personal information to third parties for their marketing or advertising use.
- No cross-context behavioral advertising. We do not share your personal data with third parties for targeted advertising purposes.
5. Legal Basis for Processing (GDPR)
Under applicable data protection laws, including the GDPR, UK GDPR, and FADP, we are required to have a valid legal basis for processing your personal data. The legal basis we rely on depends on the type of information and how we use it.
5.1 Legal Bases Summary
| Processing Activity | Legal Basis |
|---|---|
| Delivering the Services (wallet, assessments, BHI) | Performance of a contract |
| Processing health and wellness data | Explicit consent (Art. 9(2)(a) GDPR) |
| Security, fraud prevention | Legitimate interest |
| Service-related communications | Performance of a contract / Legitimate interest |
| Marketing communications | Consent |
| Tax records, legal compliance | Legal obligation |
5.2 Special Categories of Data (Health Information)
Certain information we collect — including your BrainHealth Index results — qualifies as “special category data” or “sensitive personal data” under GDPR and similar laws. We process this data only with your explicit consent, which we obtain when you:
- Create an account and agree to participate in brain health assessments.
- Consent to share brain health data for assessment, study, and research purposes.
You may withdraw your consent for health data processing at any time by contacting us at [email protected]. Withdrawal of consent will not affect the lawfulness of processing conducted before withdrawal but may limit our ability to provide certain features of the Services.
5.3 Legitimate Interest
Where we rely on legitimate interest as a legal basis, we have conducted a balancing assessment to ensure our interests do not override your fundamental rights and freedoms. Our legitimate interests include:
- Improving, developing, and enhancing our Services.
- Understanding how users interact with our platform to optimize user experience.
- Generating anonymized and de-identified data analytics, reports, and aggregated insights on brain health trends.
- Protecting our Services, users, and business from security threats and fraud.
- Developing new features using de-identified data.
You have the right to object to processing based on legitimate interest. To exercise this right, contact us at [email protected]. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
5.4 Withdrawing Consent
Where we process your data based on consent, you have the right to withdraw that consent at any time. You can do so by:
- Adjusting your preferences in your account settings.
- Clicking “unsubscribe” in marketing emails.
- Disconnecting third-party integrations through your account.
- Contacting us at [email protected].
Withdrawing consent does not affect the lawfulness of any processing we conducted prior to your withdrawal, nor does it affect processing of your personal data under other legal bases.
6. Data Sharing and Disclosure
6.1 Service Providers
We use trusted third-party partners to host data, process payments, manage communications, provide analytics, and perform other essential functions. All service providers are bound by contractual data processing agreements to protect your data and process it only in accordance with our instructions. Examples include:
- Cloud Hosting and Data Storage: Your information is stored securely on encrypted, cloud-based systems.
- Analytics Services: We use secure analytics tools to understand how users engage with the Services. Usage information may be collected in aggregated or de-identified form.
- Payment Processors: Payment information is handled by certified third-party payment providers. We do not store full payment details on our servers.
- Communication and Scheduling Tools: Secure platforms may process your name, email address, and phone number for coaching scheduling and messaging.
6.2 Coaches and Support Staff
Coaching professionals and support staff may view your assessment results, progress data, session notes, and coaching interaction history to provide personalized guidance and support.
6.3 Anonymized and De-Identified Data
We may share, license, or sell anonymized and de-identified data — data from which all direct and indirect personal identifiers have been permanently removed and which cannot reasonably be used to identify any individual — for the following purposes:
- Data analytics and reporting on brain health trends, outcomes, and population-level insights.
- Research collaborations with academic and research institutions.
- Product development and industry benchmarking.
This anonymized and de-identified data does not constitute “personal data,” “personal information,” or “consumer health data” under applicable privacy laws. We maintain technical and organizational safeguards to prevent re-identification.
6.4 With Your Consent
If you choose to share your data with third parties (e.g., by connecting wearable devices or enabling optional integrations), we will share data in accordance with your consent and the permissions you grant.
6.5 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data.
6.6 Legal Compliance
We may disclose your information if required by law, regulation, legal process, or valid governmental request, or to protect the rights, property, or safety of Cerebrum DAO Association, our users, or the public.
6.7 What We Do Not Share
- We do not sell your identifiable personal data to any third party for marketing or advertising purposes.
- We do not share your personal data with third parties for cross-context behavioral advertising or tailored one-to-one marketing.
- We do not sell or share connected-account or health data with any third parties for advertising or any other unrelated purposes.
7. International Data Transfers
21 Impact Labs, Inc. is based in the United States. If you access our Services from outside the United States, your personal data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
7.1 Transfer Safeguards
Where we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States or other countries, we rely on the following safeguards:
- EU-U.S. Data Privacy Framework (DPF): Where applicable, we rely on the EU-U.S. Data Privacy Framework and its UK and Swiss extensions for transfers of personal data.
- Standard Contractual Clauses (SCCs): We enter into European Commission-approved Standard Contractual Clauses with our service providers and partners to ensure appropriate safeguards for international transfers.
- Adequacy Decisions: Where the European Commission or UK government has issued an adequacy decision recognizing a country as providing adequate data protection, we may rely on that decision.
7.2 Transfers to Australia and New Zealand
If you are located in Australia or New Zealand, we comply with the cross-border disclosure requirements of the Australian Privacy Act 1988 (APP 8) and the New Zealand Privacy Act 2020. We take reasonable steps to ensure that overseas recipients of your personal data comply with privacy obligations substantially similar to those under Australian and New Zealand law.
8. Data Security
All data is encrypted at rest and in transit. We use industry-standard safeguards, including:
- AES-256 encryption for data at rest
- TLS 1.2+ encryption for data in transit
- Secure servers and access controls
- Multi-factor authentication
- Regular security assessments and audits
We require all third-party service providers to implement appropriate technical and organizational security measures. We conduct periodic security reviews to ensure ongoing compliance with our security standards.
While we employ robust security measures, no system is completely secure, and we cannot guarantee absolute protection. You are responsible for maintaining the confidentiality of your login credentials and for all activities under your account. If you believe your account has been compromised, please contact us immediately at [email protected].
10. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Services, and thereafter for as long as necessary to fulfill the purposes described in this Privacy Policy.
| Data Category | Retention Period |
|---|---|
| Account and Profile Data | Duration of your account plus up to 3 years after closure (for reactivation or legal obligations) |
| Health and Assessment Data | Duration of your account. After closure, de-identified or deleted within 2 years unless legally required |
| Payment Records | As required by applicable tax and financial reporting laws |
| Usage Data | Retained in identifiable form for up to 2 years; then aggregated or deleted |
| De-Identified and Anonymized Data | May be retained indefinitely for research, analytics, and product improvement (no longer constitutes personal data) |
You can request deletion of your data at any time (see Section 11). We may retain certain limited information as necessary to comply with our legal obligations, resolve disputes, or enforce our agreements.
11. Your Rights
Depending on your location, you may have the following rights under applicable data protection laws:
11.1 Rights Under GDPR (EU/EEA, UK, Switzerland)
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data, subject to certain exceptions.
- Right to Restrict Processing: Request that we limit the processing of your personal data in certain circumstances.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interest or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time where consent is the legal basis for processing.
- Right to Lodge a Complaint: Lodge a complaint with a supervisory authority (see Section 11.4).
- Rights Related to Automated Decision-Making: Request human review of decisions made solely by automated means that produce legal or similarly significant effects.
11.2 Rights Under Australian and New Zealand Privacy Laws
Residents of Australia and New Zealand have rights to access, correct, and in certain circumstances request deletion of their personal information under the Australian Privacy Act 1988 and New Zealand Privacy Act 2020. You also have the right to lodge a complaint with the relevant commissioner (see Section 11.4).
11.3 Exercising Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond to verified requests within the timeframes required by applicable law (generally within 30 days for GDPR requests). We may need to verify your identity before processing your request.
11.4 Supervisory Authorities
If you believe we have processed your personal data in violation of applicable law, you have the right to lodge a complaint with the relevant supervisory authority:
- EU/EEA: The data protection authority in your country of residence (list available at edpb.europa.eu).
- United Kingdom: Information Commissioner's Office (ICO) at ico.org.uk.
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
- Australia: Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
- New Zealand: Office of the Privacy Commissioner at privacy.org.nz.
We encourage you to contact us first at [email protected] so we can try to resolve your concern directly.
12. Additional Information for California Residents
This section provides additional information for California residents pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, “CCPA”).
12.1 Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information:
| Category | Examples |
|---|---|
| Identifiers | Name, email address, account credentials, IP address, device identifiers |
| Customer Records | Payment and subscription information |
| Commercial Information | Subscription history, purchased services |
| Internet or Network Activity | App interactions, engagement patterns, feature usage, browsing history within our Services |
| Geolocation Data | General (non-precise) location derived from IP address |
| Sensitive Personal Information | Health data including BHI results, cognitive assessments, Brain Care Score, and Web3 features |
| Inferences | Personalized coaching recommendations, progress assessments, and brain health insights |
Sources: Directly from you; automatically through your use of the Services; from third parties (connected health integrations, analytics providers).
Business Purposes: Service delivery, personalized coaching, product improvement (using de-identified data), security, and legal compliance.
Disclosure: Service providers (cloud hosting, payment processing, analytics), coaches and support staff, professional advisors, and government authorities (when required by law).
12.2 Sale and Sharing of Personal Information
We do not sell your personal information. We have not sold personal information in the preceding 12 months and do not have plans to sell personal information.
We do not share your personal information for cross-context behavioral advertising.
Our use of anonymized and de-identified data for analytics and reporting does not constitute a “sale” or “sharing” of personal information under the CCPA, as such data cannot reasonably identify any individual.
12.3 Sensitive Personal Information
We collect sensitive personal information, specifically health information related to your brain health assessments, and wellness data from connected devices. We use this sensitive personal information only for:
- Providing the Services you have requested.
- Delivering personalized brain health recommendations.
- Improving our Services using de-identified and aggregated data.
- Ensuring the security and integrity of our Services.
Because we limit our use of sensitive personal information to these necessary service purposes, you do not need to exercise a separate right to limit use under the CCPA.
12.4 Your California Privacy Rights
- Right to Know: Request disclosure of the categories and specific pieces of personal information collected, sources, purposes, and third-party recipients.
- Right to Delete: Request deletion of personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: We do not sell or share your personal information, so this right does not currently apply.
- Right to Limit Use of Sensitive Personal Information: Because we use sensitive personal information only for necessary service purposes, this right does not currently require action.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
12.5 Exercising Your California Rights
To exercise your rights, submit a verifiable consumer request by emailing [email protected]. You may submit a request up to twice in a 12-month period. We will verify your identity by matching information you provide against information on file. You may designate an authorized agent to submit a request on your behalf with written permission or a valid power of attorney.
12.6 Financial Incentives
We may offer discounts, promotions, or other incentives in exchange for the collection, retention, or use of your personal information. When we offer such programs, we will provide specific terms describing the program and how to opt in or withdraw. The value of your data is reasonably related to the value of any incentive offered.
13. Additional Information for Washington Residents
This section provides additional information for Washington State residents pursuant to the Washington My Health My Data Act (“MHMDA”).
13.1 Consumer Health Data We Collect
Under the MHMDA, “consumer health data” includes personal information linked or reasonably linkable to a consumer that identifies past, present, or future physical or mental health status. For our Services, this includes:
- BrainHealth Index assessment results and scores.
- Cognitive assessment data across focus, stress, and sleep domains.
- Health and fitness data shared through connected integrations.
- Sleep, stress, and wellness metrics.
- Inferences drawn about your health status based on the above.
13.2 Consent and Your Rights
We obtain your affirmative consent before collecting consumer health data, separately from our general Terms of Service. You may withdraw your consent at any time by contacting us at [email protected].
We do not sell your consumer health data. Under the MHMDA, we will not sell consumer health data without first obtaining your separate, valid authorization.
As a Washington resident, you have the right to:
- Confirm and access whether we are collecting, sharing, or selling your consumer health data.
- Withdraw consent to collection and sharing.
- Request deletion of your consumer health data, subject to certain exceptions.
To exercise these rights, contact us at [email protected]. We will respond within the timeframes required by Washington law.
13.3 Geofencing
We do not use geofencing technology to identify or track consumers who visit healthcare facilities.
14. Additional Information for Virginia, Colorado, Connecticut, and Other U.S. State Residents
This section provides additional information for residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other U.S. states with comprehensive privacy legislation, including Texas, Oregon, Montana, Utah, Iowa, Indiana, and Tennessee.
14.1 Sensitive Data
Under these state laws, health data — including BrainHealth Index results, cognitive assessments, and data from connected health integrations — is considered “sensitive data.” We obtain your opt-in consent before processing sensitive data.
14.2 Your Rights
Residents of these states generally have the following rights:
- Right to Access: Confirm whether we are processing your personal data and access that data.
- Right to Correct: Request correction of inaccuracies.
- Right to Delete: Request deletion of personal data, subject to exceptions.
- Right to Portability: Obtain a copy of your data in a portable, readily usable format.
- Right to Opt Out of Sale: We do not sell personal data.
- Right to Opt Out of Targeted Advertising: We do not engage in targeted advertising.
- Right to Opt Out of Profiling: Our assessments and recommendations do not produce legal or similarly significant effects.
- Right to Withdraw Consent: Withdraw consent where consent is the legal basis for processing.
14.3 Exercising Your Rights and Right to Appeal
To exercise your rights, contact us at [email protected]. We will respond within 45 days (60 days for Colorado residents).
If we decline your request, you have the right to appeal by emailing us with the subject line “Privacy Rights Appeal.” If your appeal is denied, you may contact your state's Attorney General.
14.4 Non-Discrimination
We will not discriminate against you for exercising your privacy rights under any applicable state law.
15. Children's Privacy
Our Services are not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us at [email protected] so we can promptly delete the information.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, data practices, or legal requirements. When we make significant updates, we will notify you by email or through the Services before they take effect, and we will update the “Effective Date” and “Last Updated” dates at the top of this page.
Your continued use of the Services after such updates constitutes acknowledgment of the revised Privacy Policy. We encourage you to review this Policy periodically.
17. Contact Us
If you have any questions, requests, or concerns about this Privacy Policy or how we handle your data, please contact us:
Cerebrum DAO Association d/b/a Cortex App
Email: [email protected]
Address: Unter Altstadt 28, c/o Mercandor AG, 6300 Zug, Switzerland
Website: www.cerebrumdao.com/cortex-app