Privacy Policy

Cerebrum DAO Association

d/b/a Cortex App

Website: https://www.cerebrumdao.com/cortex-app

Effective Date: 2026-03-01 | Last Updated: 2026-03-19


1. Introduction

Cerebrum DAO Association, doing business as Cortex App (“we,” “us,” or “our”), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our applications, assessments, digital coaching services, and related offerings (collectively, the “Services”).

Our Services include, but are not limited to:

  • Cortex App, a Brain Health App translating Cerebrum DAO's research into real-world tools for neurological wellbeing;
  • The Brain Health Survey (BHS) assessment;
  • Crypto wallet that allows users to store their crypto holdings with many features related to the NEURON token; this is a non-custodial wallet (no funds are held with the company).

This Privacy Policy applies to all users of our Services regardless of location. Certain sections provide additional information required by the laws of specific jurisdictions, including the European Union, United Kingdom, Switzerland, Australia, New Zealand, California, and other U.S. states with comprehensive privacy legislation.

By using our Services, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable law, we will obtain your consent before collecting or processing your personal data. If you do not agree with our practices, please do not use our Services.

2. Data Controller

For the purposes of applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection (FADP), the data controller responsible for your personal data is:

Cerebrum DAO Association d/b/a Cortex App

Email: [email protected]

Website: https://www.cerebrumdao.com/cortex-app

3. Information We Collect

We collect the following categories of information when you use our Services:

3.1 Information You Provide Directly

  • Account Information: Your name, email address, account credentials, and profile preferences.
  • Payment Information: Subscription and payment details, processed by certified third-party payment providers. We do not store full payment card details on our servers.
  • Profile Information: Your preferences, settings, profile picture, and any optional demographic information you choose to provide.
  • Health and Wellness Information: Your BrainHealth Index (BHI) assessment results, including scores, trends, and progress across domains such as focus, stress management, and sleep quality; Brain Care Score data; cognitive assessment responses; and any other brain health or wellness information you voluntarily provide.
  • Communications: Information you provide when you contact us for support, submit feedback, or respond to surveys.

3.2 Information Collected Automatically

  • App and Website Usage Data: Interactions with our applications and website, engagement patterns, completed activities, feature usage, and session duration.
  • Device and Technical Information: IP address, device type, operating system, browser type, device identifiers, and general (non-precise) location derived from your IP address.
  • Cookies and Similar Technologies: Information collected through cookies, pixels, and similar tracking technologies as described in Section 9.

4. How We Use Your Information

4.1 Service Delivery and Performance

  • Delivering and maintaining the Services, including the Brain Health Survey, BrainHealth Index assessments, Staking Mechanism, and related Crypto features and tools.
  • Tracking your progress over time and generating insights based on your BrainHealth Index and activity data.
  • Processing your subscription and payments.

4.2 Communications

  • Sending service-related communications, including updates, reminders, coaching prompts, progress notifications, and support messages.
  • Responding to your inquiries, feedback, and support requests.
  • With your opt-in consent, sending informational communications about new features, research updates, or wellness content. You may unsubscribe at any time.

4.3 Product Improvement, Analytics, and Research

  • Using anonymized and de-identified data to conduct research, generate aggregated insights, and produce data analytics and reporting on brain health trends, outcomes, and population-level insights.
  • Analyzing usage patterns to optimize user experience and improve the quality and effectiveness of our Services.
  • Improving the quality and effectiveness of communication, content, and support.

Note: “De-identified data” means data from which direct identifiers have been removed and which cannot reasonably be used to identify you. “Anonymized data” means data from which all direct and indirect personal identifiers have been permanently removed and which cannot reasonably be used to identify any individual. We maintain technical and organizational safeguards to prevent re-identification.

4.4 Security and Compliance

  • Ensuring the security and integrity of our Services, preventing fraud, and detecting unauthorized access.
  • Complying with applicable legal obligations, including tax, regulatory, and reporting requirements.

4.5 What We Do Not Do

  • No tailored or one-to-one marketing. We do not use your personal data to send you personalized advertisements based on your health data, coaching interactions, or behavioral profile.
  • No sale of personal data for marketing. We will never sell your identifiable personal information to third parties for their marketing or advertising use.
  • No cross-context behavioral advertising. We do not share your personal data with third parties for targeted advertising purposes.

6. Data Sharing and Disclosure

6.1 Service Providers

We use trusted third-party partners to host data, process payments, manage communications, provide analytics, and perform other essential functions. All service providers are bound by contractual data processing agreements to protect your data and process it only in accordance with our instructions. Examples include:

  • Cloud Hosting and Data Storage: Your information is stored securely on encrypted, cloud-based systems.
  • Analytics Services: We use secure analytics tools to understand how users engage with the Services. Usage information may be collected in aggregated or de-identified form.
  • Payment Processors: Payment information is handled by certified third-party payment providers. We do not store full payment details on our servers.
  • Communication and Scheduling Tools: Secure platforms may process your name, email address, and phone number for coaching scheduling and messaging.

6.2 Coaches and Support Staff

Coaching professionals and support staff may view your assessment results, progress data, session notes, and coaching interaction history to provide personalized guidance and support.

6.3 Anonymized and De-Identified Data

We may share, license, or sell anonymized and de-identified data — data from which all direct and indirect personal identifiers have been permanently removed and which cannot reasonably be used to identify any individual — for the following purposes:

  • Data analytics and reporting on brain health trends, outcomes, and population-level insights.
  • Research collaborations with academic and research institutions.
  • Product development and industry benchmarking.

This anonymized and de-identified data does not constitute “personal data,” “personal information,” or “consumer health data” under applicable privacy laws. We maintain technical and organizational safeguards to prevent re-identification.

6.4 With Your Consent

If you choose to share your data with third parties (e.g., by connecting wearable devices or enabling optional integrations), we will share data in accordance with your consent and the permissions you grant.

6.5 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data.

6.6 Legal Compliance

We may disclose your information if required by law, regulation, legal process, or valid governmental request, or to protect the rights, property, or safety of Cerebrum DAO Association, our users, or the public.

6.7 What We Do Not Share

  • We do not sell your identifiable personal data to any third party for marketing or advertising purposes.
  • We do not share your personal data with third parties for cross-context behavioral advertising or tailored one-to-one marketing.
  • We do not sell or share connected-account or health data with any third parties for advertising or any other unrelated purposes.

7. International Data Transfers

21 Impact Labs, Inc. is based in the United States. If you access our Services from outside the United States, your personal data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

7.1 Transfer Safeguards

Where we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States or other countries, we rely on the following safeguards:

  • EU-U.S. Data Privacy Framework (DPF): Where applicable, we rely on the EU-U.S. Data Privacy Framework and its UK and Swiss extensions for transfers of personal data.
  • Standard Contractual Clauses (SCCs): We enter into European Commission-approved Standard Contractual Clauses with our service providers and partners to ensure appropriate safeguards for international transfers.
  • Adequacy Decisions: Where the European Commission or UK government has issued an adequacy decision recognizing a country as providing adequate data protection, we may rely on that decision.

7.2 Transfers to Australia and New Zealand

If you are located in Australia or New Zealand, we comply with the cross-border disclosure requirements of the Australian Privacy Act 1988 (APP 8) and the New Zealand Privacy Act 2020. We take reasonable steps to ensure that overseas recipients of your personal data comply with privacy obligations substantially similar to those under Australian and New Zealand law.

8. Data Security

All data is encrypted at rest and in transit. We use industry-standard safeguards, including:

  • AES-256 encryption for data at rest
  • TLS 1.2+ encryption for data in transit
  • Secure servers and access controls
  • Multi-factor authentication
  • Regular security assessments and audits

We require all third-party service providers to implement appropriate technical and organizational security measures. We conduct periodic security reviews to ensure ongoing compliance with our security standards.

While we employ robust security measures, no system is completely secure, and we cannot guarantee absolute protection. You are responsible for maintaining the confidentiality of your login credentials and for all activities under your account. If you believe your account has been compromised, please contact us immediately at [email protected].

9. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Maintain login sessions and remember your preferences.
  • Monitor product performance and usage trends.
  • Improve user experience and optimize our Services.
  • Analyze how our Services are used in aggregate.

We do not use cookies or tracking technologies for targeted advertising or cross-context behavioral tracking.

You can manage your cookie preferences through your browser settings or, where available, through our cookie consent tool. Disabling certain cookies may limit some features of our Services.

10. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Services, and thereafter for as long as necessary to fulfill the purposes described in this Privacy Policy.

Data CategoryRetention Period
Account and Profile DataDuration of your account plus up to 3 years after closure (for reactivation or legal obligations)
Health and Assessment DataDuration of your account. After closure, de-identified or deleted within 2 years unless legally required
Payment RecordsAs required by applicable tax and financial reporting laws
Usage DataRetained in identifiable form for up to 2 years; then aggregated or deleted
De-Identified and Anonymized DataMay be retained indefinitely for research, analytics, and product improvement (no longer constitutes personal data)

You can request deletion of your data at any time (see Section 11). We may retain certain limited information as necessary to comply with our legal obligations, resolve disputes, or enforce our agreements.

11. Your Rights

Depending on your location, you may have the following rights under applicable data protection laws:

11.1 Rights Under GDPR (EU/EEA, UK, Switzerland)

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to certain exceptions.
  • Right to Restrict Processing: Request that we limit the processing of your personal data in certain circumstances.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object: Object to processing based on legitimate interest or for direct marketing purposes.
  • Right to Withdraw Consent: Withdraw consent at any time where consent is the legal basis for processing.
  • Right to Lodge a Complaint: Lodge a complaint with a supervisory authority (see Section 11.4).
  • Rights Related to Automated Decision-Making: Request human review of decisions made solely by automated means that produce legal or similarly significant effects.

11.2 Rights Under Australian and New Zealand Privacy Laws

Residents of Australia and New Zealand have rights to access, correct, and in certain circumstances request deletion of their personal information under the Australian Privacy Act 1988 and New Zealand Privacy Act 2020. You also have the right to lodge a complaint with the relevant commissioner (see Section 11.4).

11.3 Exercising Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond to verified requests within the timeframes required by applicable law (generally within 30 days for GDPR requests). We may need to verify your identity before processing your request.

11.4 Supervisory Authorities

If you believe we have processed your personal data in violation of applicable law, you have the right to lodge a complaint with the relevant supervisory authority:

  • EU/EEA: The data protection authority in your country of residence (list available at edpb.europa.eu).
  • United Kingdom: Information Commissioner's Office (ICO) at ico.org.uk.
  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
  • Australia: Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
  • New Zealand: Office of the Privacy Commissioner at privacy.org.nz.

We encourage you to contact us first at [email protected] so we can try to resolve your concern directly.

12. Additional Information for California Residents

This section provides additional information for California residents pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, “CCPA”).

12.1 Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information:

CategoryExamples
IdentifiersName, email address, account credentials, IP address, device identifiers
Customer RecordsPayment and subscription information
Commercial InformationSubscription history, purchased services
Internet or Network ActivityApp interactions, engagement patterns, feature usage, browsing history within our Services
Geolocation DataGeneral (non-precise) location derived from IP address
Sensitive Personal InformationHealth data including BHI results, cognitive assessments, Brain Care Score, and Web3 features
InferencesPersonalized coaching recommendations, progress assessments, and brain health insights

Sources: Directly from you; automatically through your use of the Services; from third parties (connected health integrations, analytics providers).

Business Purposes: Service delivery, personalized coaching, product improvement (using de-identified data), security, and legal compliance.

Disclosure: Service providers (cloud hosting, payment processing, analytics), coaches and support staff, professional advisors, and government authorities (when required by law).

12.2 Sale and Sharing of Personal Information

We do not sell your personal information. We have not sold personal information in the preceding 12 months and do not have plans to sell personal information.

We do not share your personal information for cross-context behavioral advertising.

Our use of anonymized and de-identified data for analytics and reporting does not constitute a “sale” or “sharing” of personal information under the CCPA, as such data cannot reasonably identify any individual.

12.3 Sensitive Personal Information

We collect sensitive personal information, specifically health information related to your brain health assessments, and wellness data from connected devices. We use this sensitive personal information only for:

  • Providing the Services you have requested.
  • Delivering personalized brain health recommendations.
  • Improving our Services using de-identified and aggregated data.
  • Ensuring the security and integrity of our Services.

Because we limit our use of sensitive personal information to these necessary service purposes, you do not need to exercise a separate right to limit use under the CCPA.

12.4 Your California Privacy Rights

  • Right to Know: Request disclosure of the categories and specific pieces of personal information collected, sources, purposes, and third-party recipients.
  • Right to Delete: Request deletion of personal information, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: We do not sell or share your personal information, so this right does not currently apply.
  • Right to Limit Use of Sensitive Personal Information: Because we use sensitive personal information only for necessary service purposes, this right does not currently require action.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

12.5 Exercising Your California Rights

To exercise your rights, submit a verifiable consumer request by emailing [email protected]. You may submit a request up to twice in a 12-month period. We will verify your identity by matching information you provide against information on file. You may designate an authorized agent to submit a request on your behalf with written permission or a valid power of attorney.

12.6 Financial Incentives

We may offer discounts, promotions, or other incentives in exchange for the collection, retention, or use of your personal information. When we offer such programs, we will provide specific terms describing the program and how to opt in or withdraw. The value of your data is reasonably related to the value of any incentive offered.

13. Additional Information for Washington Residents

This section provides additional information for Washington State residents pursuant to the Washington My Health My Data Act (“MHMDA”).

13.1 Consumer Health Data We Collect

Under the MHMDA, “consumer health data” includes personal information linked or reasonably linkable to a consumer that identifies past, present, or future physical or mental health status. For our Services, this includes:

  • BrainHealth Index assessment results and scores.
  • Cognitive assessment data across focus, stress, and sleep domains.
  • Health and fitness data shared through connected integrations.
  • Sleep, stress, and wellness metrics.
  • Inferences drawn about your health status based on the above.

13.2 Consent and Your Rights

We obtain your affirmative consent before collecting consumer health data, separately from our general Terms of Service. You may withdraw your consent at any time by contacting us at [email protected].

We do not sell your consumer health data. Under the MHMDA, we will not sell consumer health data without first obtaining your separate, valid authorization.

As a Washington resident, you have the right to:

  • Confirm and access whether we are collecting, sharing, or selling your consumer health data.
  • Withdraw consent to collection and sharing.
  • Request deletion of your consumer health data, subject to certain exceptions.

To exercise these rights, contact us at [email protected]. We will respond within the timeframes required by Washington law.

13.3 Geofencing

We do not use geofencing technology to identify or track consumers who visit healthcare facilities.

14. Additional Information for Virginia, Colorado, Connecticut, and Other U.S. State Residents

This section provides additional information for residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other U.S. states with comprehensive privacy legislation, including Texas, Oregon, Montana, Utah, Iowa, Indiana, and Tennessee.

14.1 Sensitive Data

Under these state laws, health data — including BrainHealth Index results, cognitive assessments, and data from connected health integrations — is considered “sensitive data.” We obtain your opt-in consent before processing sensitive data.

14.2 Your Rights

Residents of these states generally have the following rights:

  • Right to Access: Confirm whether we are processing your personal data and access that data.
  • Right to Correct: Request correction of inaccuracies.
  • Right to Delete: Request deletion of personal data, subject to exceptions.
  • Right to Portability: Obtain a copy of your data in a portable, readily usable format.
  • Right to Opt Out of Sale: We do not sell personal data.
  • Right to Opt Out of Targeted Advertising: We do not engage in targeted advertising.
  • Right to Opt Out of Profiling: Our assessments and recommendations do not produce legal or similarly significant effects.
  • Right to Withdraw Consent: Withdraw consent where consent is the legal basis for processing.

14.3 Exercising Your Rights and Right to Appeal

To exercise your rights, contact us at [email protected]. We will respond within 45 days (60 days for Colorado residents).

If we decline your request, you have the right to appeal by emailing us with the subject line “Privacy Rights Appeal.” If your appeal is denied, you may contact your state's Attorney General.

14.4 Non-Discrimination

We will not discriminate against you for exercising your privacy rights under any applicable state law.

15. Children's Privacy

Our Services are not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us at [email protected] so we can promptly delete the information.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, data practices, or legal requirements. When we make significant updates, we will notify you by email or through the Services before they take effect, and we will update the “Effective Date” and “Last Updated” dates at the top of this page.

Your continued use of the Services after such updates constitutes acknowledgment of the revised Privacy Policy. We encourage you to review this Policy periodically.

17. Contact Us

If you have any questions, requests, or concerns about this Privacy Policy or how we handle your data, please contact us:

Cerebrum DAO Association d/b/a Cortex App

Email: [email protected]

Address: Unter Altstadt 28, c/o Mercandor AG, 6300 Zug, Switzerland

Website: www.cerebrumdao.com/cortex-app