Legal & Security

Privacy Policy

Last updated: August 2026. Cryptographic data sovereignty, zero central health databases, and total member ownership.

1. Introduction & Core Philosophy

NeuroVitals Inc. ("NeuroVitals", "we", "our", or "us") is dedicated to protecting your privacy. We believe that physiological, psychological, and biomarker health data is inherently sovereign. Unlike traditional wellness applications that aggregate and monetize sensitive user logs, NeuroVitals is engineered from the ground up on decentralized cryptographic foundations.

2. The atProtocol Architectural Guarantee

Every NeuroVitals member receives a dedicated personal cryptographic server, known as an atServer, addressed by their unique atSign (@member). All sensitive records—including blood biomarker panels, sleep stages, heart rate variability (HRV), daily reflection notes, and habit completions—are encrypted on-device before transmission.

NeuroVitals operates no central database containing unencrypted member health records. Because you hold the private cryptographic keys in your device's Secure Enclave/Keychain, not even NeuroVitals employees or AI models can decrypt your raw health records without explicit, revocable cryptographic consent.

3. Data Isolation Domains

To enforce strict separation of duties and prevent cross-domain contamination, records are segregated into distinct cryptographic domains:

  • health: Physiological telemetry, lab biomarkers, and outcome correlations.
  • habit: Microhabit completion records and circadian timing logs.
  • consent: Granular, cryptographically signed sharing agreements with healthcare providers.
  • profile: App preferences and display settings.
  • community & billing: Strictly isolated roles with zero architectural access to the health domain.

4. Information We Collect for Account Fulfillment

When you join as a Pioneer member, we collect minimal operational information necessary to fulfill your membership:

  • Contact details (e.g. email address provided during Stripe checkout to send your redemption link and receipt).
  • Billing transaction identifiers (processed securely via Stripe; NeuroVitals never handles or stores raw credit card numbers).

5. Your Rights & Data Deletion

Under GDPR, CCPA, and our cryptographic architecture, you possess absolute authority over your records. You may export your keys, revoke sharing grants in real-time, or completely wipe your personal atServer at any time directly through the NeuroVitals mobile client.

6. Contact Us

For privacy inquiries, data subject access requests, or cryptographic audits, contact our Privacy Officer at hello@neurovitalsai.com or write to NeuroVitals Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, United States.