BrioMon
How It WorksPricingResearchBlog
LoginRequest Access

Privacy Policy

Version 1.4 Effective Date: October 1, 2026 Last Reviewed: September 2026

Applies to residents of the United States, Canada, European Union, United Kingdom, and Australia.

Key points — plain English

  • Upstream Cognitive Architecture: BrioMon is a Mental Capacity Management System (MCMS™) — an active performance discipline, not therapy, clinical psychology, medical advice, or psychiatric treatment.
  • Workplace Privacy Firewall: In corporate deployments, employers and administrators never see an individual employee's Pulse ratings, Assessment answers, or private Journal reflections. Team reporting is strictly aggregated behind an automated minimum threshold of 5 active users.
  • We Do Not Sell Data: We do not sell, rent, monetize, or trade your personal data or Google user data under any circumstance.
  • Two-Tier Data Lifecycle: Daily practice data (journals, pulse entries) is purged within 6 months of account termination. Verified MCMP certification records remain permanently checkable unless you request erasure.
  • Your Payment Data: We never store full card numbers. Payments are handled externally by our Merchant of Record partners, 2Checkout and Paddle — see Section 7.
  • Privacy Contact: For data protection, compliance, and statutory rights requests, email privacy@briomon.com or connect@briomon.com.

Jump to section

1. Who We Are & Regulatory Status 2. Information We Collect 3. How We Use Data & Legal Bases 4. Corporate Anonymity Firewall 5. Google API Compliance 6. Cookies & Tracking 7. Data Sharing & Processors 8. International Transfers 9. Data Retention & Erasure 10. Data Security 11. Your Privacy Rights 12. Children's Privacy 13. Contact & Supervisory Authorities

Privacy requests:

privacy@briomon.com

This Privacy Policy explains how BrioMon Technologies LLC ("BrioMon", "we", "us", or "our") collects, uses, discloses, and protects personal information when you visit briomon.com, use our web portal at app.briomon.com, or use our mobile application (collectively, the "Services"). Please read this policy carefully before using our Services.

Section 1

Who We Are & Regulatory Status


1.1 Corporate Identity

BrioMon is owned and operated by BrioMon Technologies LLC, a Wyoming limited liability company located at 1603 Capitol Avenue, Suite 413, Cheyenne, WY 82001, USA.

1.2 Dual Regulatory Role

Data Controller

For individual subscribers who create an independent personal account directly through briomon.com or mobile applications, BrioMon acts as the Data Controller under GDPR Article 4(7).

Data Processor

For employees and contractors provisioned access under an enterprise agreement, the Corporate Client acts as the Data Controller, and BrioMon acts strictly as the Data Processor under GDPR Article 4(8) and Article 28. In such instances, processing is executed pursuant to an executed Data Processing Agreement (DPA). Your employer cannot see your individual data — only anonymised aggregate team metrics with a minimum of 5 active users (see Section 4).

1.3 Non-Clinical Standing

BrioMon is an upstream cognitive capacity management platform. It does not provide medical services, clinical diagnosis, or therapeutic treatment. Personal journal entries and pulse inputs are processed strictly for self-directed personal development and are not classified as Protected Health Information (PHI) under HIPAA.

Section 2

Information We Collect


2.1 Account & Identity Data

Full name, primary email address, password hash (via secure authentication providers), company affiliation (for corporate users), role title, and chosen community display pseudonyms.

2.2 Mental Capacity Inputs (The Den)

  • Daily Pulse Check: Visual slider ratings representing self-reported mental energy and subjective valence (pleasant/unpleasant).
  • Mind Assessment Data: Interactive, non-clinical behavioral tap responses and reaction distributions.
  • Guided Journal Entries: Freeform text reflections submitted to the Mental Capacity Assessment Engine (MCAE™) to generate contextual restorative recommendations.
  • Growth Telemetry: Active habit streaks, completed practice modules, and 30-day capacity trajectory curves.

2.3 Enterprise Administration Data

Department assignments, organizational seat allocation metrics, cryptographic single-use invitation tokens, and role designations (Super Admin, Admin, Moderator).

2.4 Transactional & Financial Data

Billing address, tax jurisdiction, and payment confirmation records. Full credit card numbers and banking details are never collected or stored on BrioMon servers. Payment processing is handled externally by our Merchant of Record (MoR) partners, 2Checkout and Paddle (see Section 7).

2.5 Technical & Telemetry Data

IP address, device fingerprints, operating system type, browser user-agent, session timestamps, and diagnostic error logs.

2.6 Data We Do Not Collect

BrioMon does not collect and will never request:

  • Government identification numbers (Social Security numbers, national ID numbers, passport numbers)
  • Financial account numbers, bank account details, or full payment card numbers
  • Medical records, clinical diagnoses, or health information as defined under HIPAA
  • Biometric data
  • Data from children under the age of 18 (our Services are for professionals aged 18 and over)
  • Precise real-time GPS location

2.7 Google Sign-In & Google User Data

When you choose to sign in to BrioMon using Google Sign-In, we access basic profile information from your Google Account -- your name, email address, and profile picture -- solely to create and authenticate your BrioMon account. See Section 5 for our full Google API User Data Policy commitments.

Section 3

How We Use Personal Data & Legal Bases


Under GDPR Article 6, we process personal information strictly under the following lawful bases:

3.1 Performance of a Contract (Art. 6(1)(b))

  • Provisioning and maintaining your account and access to the web workspace at app.briomon.com.
  • Processing subscription billings, renewals, and invoice distributions.
  • Delivering the MCMP Foundation Certification course and issuing verifiable completion certificates.

3.2 Legitimate Interests (Art. 6(1)(f))

  • Operating the Mental Capacity Assessment Engine (MCAE™) to analyze sentiment and match targeted performance practices to real-time cognitive friction.
  • Maintaining platform stability, monitoring application performance, and preventing fraudulent access.
  • Preserving verified alumni certification records so users maintain permanent access to earned credentials.

3.3 Legal Obligations (Art. 6(1)(c))

  • Fulfilling statutory corporate tax reporting, accounting laws, and lawful government directives.

3.4 Consent (Art. 6(1)(a))

  • Delivering non-essential product update announcements or optional communications, which can be withdrawn at any time.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects without human review.

Section 4

The Corporate Anonymity Firewall


4.1 Absolute Individual Privacy

The platform enforces an architectural separation between employee workspaces and administrative dashboards. Corporate administrators, HR personnel, and leadership are strictly barred from viewing:

  • Individual Daily Pulse ratings or historical scores.
  • Individual Guided Journal entries or freeform text.
  • Specific protocols or modules selected and practiced by a given employee.
  • The true identity behind any employee post or reaction on the Community Board.

4.2 The 5-User Mathematical Floor

Workforce vitality analytics, team capacity trends, and strain indicators are aggregated and displayed only when a department or team has at least five (5) active members participating. If a team size falls below 5, data is rolled up into the general organization-wide pool to prevent reverse-engineering of individual inputs.

Section 5

Google API User Data Policy Compliance


When you choose to authenticate or access BrioMon using Google Single Sign-In (OAuth), the following commitments apply:

5.1 Data Accessed

BrioMon accesses only basic Google profile information (your verified email address, full name, and avatar image) strictly to authenticate your account and provision your profile. We do not request or access any other Google data (Gmail, Drive, Calendar, or any other Google service) through this sign-in flow.

5.2 Strict Limitation of Use

  • No Advertising: Google user data is never used to serve personalized, retargeted, or interest-based advertisements.
  • No Data Brokering: We do not sell, rent, trade, or transfer Google user data to third parties, data brokers, or marketing networks under any circumstance.
  • No Surveillance: BrioMon does not use Google user data for employee surveillance or administrative monitoring.
  • Human Review Constraints: BrioMon personnel do not read or inspect user data accessed through Google APIs, except where explicitly requested by the user for technical troubleshooting, required by law, or aggregated internally for security investigations.

5.3 Retention & Google Limited Use Disclosure

Google Sign-In data is retained for as long as your BrioMon account remains active and is deleted upon account deletion (see Section 9) or on request to privacy@briomon.com. BrioMon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Section 6

Cookies & Tracking Technologies


6.1 Strictly Necessary Cookies

BrioMon uses only strictly necessary session and authentication cookies, issued through our infrastructure provider, required to sign you in, maintain your session, and protect against cross-site request forgery (CSRF). These cannot be disabled without breaking core application functionality.

6.2 No Analytics or Marketing Trackers

BrioMon does not currently deploy analytics cookies, third-party advertising pixels, or cross-site behavioral marketing scripts (for example, Google Analytics or the Meta Pixel) on briomon.com or within the authenticated application at app.briomon.com.

6.3 Future Changes

If BrioMon introduces functional, analytics, or marketing cookies in the future, this policy will be updated in advance and, where required by law, your consent will be requested before any non-essential cookie is set. For a full list of every cookie BrioMon and its third-party providers set, see our Cookie Policy.

Section 7

Data Sharing & Third-Party Processors


We do not sell personal information. We transfer data strictly to vetted service providers acting as subprocessors under formal Data Processing Agreements:

Cloud Infrastructure, Database & AuthenticationSupabase Inc. — encrypted at rest via AES-256 and in transit via TLS 1.3.
Application HostingVercel Inc. — hosts and serves the BrioMon web application.
Edge Delivery & SecurityCloudflare Inc. — CDN delivery, DDoS protection, edge routing.
Transactional CommunicationsResend — delivery of account verification links, password resets, and billing/invoice notifications.
Payment HandlingPayment processing is handled externally by our Merchant of Record (MoR) partners, 2Checkout and Paddle. BrioMon never processes, stores, or sees full payment card details or banking credentials on its servers. See our Sub-Processors page for which partner handles which product, and our Cookie Policy for the cookies they set.
Emergency Crisis RoutingIn acute safety scenarios, automated routing links users directly to external, third-party national crisis lines (e.g., the 988 Lifeline). No internal user profile or journal text is transmitted to crisis providers.
Legal & Regulatory BodiesWhere required by applicable law, court order, or regulatory authority. We will notify you where legally permitted to do so.
Section 8

International Data Transfers


Personal data collected through BrioMon is hosted on secure cloud infrastructure located within the United States.

For data originating in the European Economic Area (EEA), United Kingdom, or Switzerland:

  • Transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) under Decision (EU) 2021/914 and, for the UK, the International Data Transfer Addendum to the EU SCCs issued by the ICO.
  • All data transfers incorporate mandatory technical and organizational safeguards, including end-to-end TLS 1.3 encryption and restricted role-based administrative access.
Section 9

Data Retention & Erasure Schedule


9.1 Active Accounts

Personal data, pulse logs, and journal reflections remain available throughout the active duration of your subscription.

9.2 Two-Tier Post-Subscription Lifecycle

Daily Practice TelemetryAll raw personal reflections, private journal entries, and granular daily pulse records are purged within six (6) months following account cancellation or subscription lapse.
MCMP Alumni RegistryPermanent certification records (name, verification token ID, issue date) are maintained indefinitely under legitimate interests to allow alumni to verify credentials via their certificate link, unless an explicit request for complete erasure is submitted.
Aggregated AnalyticsHistorical organizational telemetry retained by Corporate Clients is stripped of individual identifying attributes and retained purely as anonymized aggregate data points.

9.3 Other Retention Periods

Payment & Transaction Records7 years from the transaction date (required for tax and financial compliance in all operating jurisdictions)
Support Communications2 years from the date of last contact
Marketing Consent RecordsUntil consent is withdrawn, plus 12 months
Security & Server Logs90 days

When data is no longer required for the purposes stated in this policy, we securely delete or irreversibly anonymise it. Anonymised aggregate data, from which no individual can be identified, may be retained indefinitely for research and service improvement.

Section 10

Data Security & Storage Architecture


  • Encryption in Transit: TLS 1.3 for all data in transit.
  • Encryption at Rest: AES-256 for all database volumes, backups, and user tables.
  • Password Security: Passwords are stored using industry-standard cryptographic hashing and are never stored in plaintext.
  • Access Controls: Role-based permissions restrict access to personal data on a need-to-know basis only.
  • Logical Separation: Corporate client data is isolated via tenant identifier scoping, preventing cross-organization data leakage.
  • Data Processing Agreements: GDPR-compliant DPAs are in place with all third-party subprocessors.
  • Incident Response: In the event of a confirmed security breach involving personal data, BrioMon will notify relevant supervisory authorities and affected users within seventy-two (72) hours of verification, in accordance with GDPR Article 33.

No method of transmission or storage over the internet is 100% secure. While we use commercially reasonable measures to protect your personal data, we cannot guarantee absolute security.

Section 11

Your Statutory Privacy Rights


Depending on your geographic location, you possess specific legal rights regarding your personal data. We respond to all verified requests within 30 days (EU/UK/Australia/Canada) or 45 days (US) of receipt.

11.1 Rights for All Users

AccessRequest a copy of the personal data we hold about you
CorrectionRequest correction of inaccurate or incomplete personal data
DeletionRequest deletion of your personal data, subject to legal retention obligations
PortabilityReceive your journal inputs and progress telemetry in a structured, machine-readable JSON format
Withdraw ConsentWithdraw consent for marketing communications at any time without affecting prior processing

11.2 GDPR & UK GDPR Rights (EEA & UK Residents)

Expand EU / UK Rights
  • Right of Access (Art. 15): Request a full copy of the personal data BrioMon holds about you.
  • Right to Rectification (Art. 16): Request correction of incomplete or inaccurate data.
  • Right to Erasure, "Right to be Forgotten" (Art. 17): Request complete deletion of your personal data, subject to statutory retention exceptions.
  • Right to Restriction of Processing (Art. 18): Request restriction of data processing under certain dispute conditions.
  • Right to Data Portability (Art. 20): Export your journal inputs and progress telemetry in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to processing grounded in legitimate interests.

You also have the right to lodge a complaint with your national data protection authority (e.g., your country's DPA in the EU, or the ICO in the UK at ico.org.uk).

11.3 CCPA & CPRA Rights (California Residents)

Expand California Rights
  • Right to Know: Disclosure of categories of personal data collected, sources, and commercial purposes.
  • Right to Delete: Request deletion of personal information collected from you, subject to exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: BrioMon does not sell or share personal information for cross-context behavioral advertising; therefore, no opt-out is required.
  • Right to Limit Use of Sensitive Personal Information: Limit the use and disclosure of sensitive personal information.
  • Non-Discrimination: BrioMon will never deny services, alter prices, or downgrade service quality for exercising statutory privacy rights.

To submit a California privacy request: privacy@briomon.com

11.4 Rights — Australian & Canadian Residents

Expand Australia / Canada Rights

Australia: Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), you have the right to access and correct your personal information and to make a complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Canada: Under PIPEDA, you have the right to access and correct your personal information. Complaints may be directed to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

How to Submit a Rights Request

Email privacy@briomon.com with the subject line "Data Subject Rights Request". State your full name, registered email address, and the specific right you wish to exercise. Identity verification will be performed prior to data disclosure or modification.

Section 12

Children's Privacy


BrioMon is designed exclusively for adult professionals and working teams. The platform is not intended for individuals under 18 years of age. We do not knowingly collect, solicit, or process personal data from children. If we discover that an individual under 18 has submitted personal information, we will immediately deactivate the account and permanently delete all associated data from our servers. If you believe we have inadvertently collected data from a minor, please contact privacy@briomon.com immediately.

Section 13

Contact & Supervisory Authority Details


If you have questions, feedback, or concerns regarding this Privacy Policy or our data protection practices, please contact us:

Contact BrioMon

BrioMon Technologies LLC
1603 Capitol Avenue, Suite 413
Cheyenne, WY 82001, USA
Data Protection Inquiries: privacy@briomon.com
General Communications: connect@briomon.com
Legal Operations: legal@briomon.com
Website: briomon.com

13.1 Supervisory Authorities

If you are not satisfied with our response, you have the right to complain to the supervisory authority in your jurisdiction:

European UnionYour national Data Protection Authority — see edpb.europa.eu
United KingdomInformation Commissioner's Office (ICO) — ico.org.uk
AustraliaOffice of the Australian Information Commissioner — oaic.gov.au
CanadaOffice of the Privacy Commissioner — priv.gc.ca
United StatesFederal Trade Commission — ftc.gov; California: CPPA at cppa.ca.gov

13.2 How We Update This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Effective Date" and "Last Reviewed" date at the top of this policy, display a prominent notice on briomon.com for at least 30 days, and send an email notification to all registered users. Your continued use of the Services after the effective date of any updated policy constitutes your acceptance of the changes. If you do not agree with the revised policy, you may close your account by contacting privacy@briomon.com.

Version 1.4 — September 2026Simplified Section 2.4 and Section 7 to name our Merchant of Record partners (2Checkout, Paddle) without mapping each to a specific product -- that level of detail now lives on the Sub-Processors page, which is the single source of truth for it.
Version 1.3 — September 2026Updated Section 2.4 and Section 7 to name 2Checkout/2Monetize and Paddle as the active Merchant of Record partners for individual and corporate payments respectively, replacing the prior manual-invoicing description, and cross-referenced the new Cookie Policy for the cookies these processors set.
Version 1.2 — September 2026Restructured and rewritten in full: added a dedicated Corporate Anonymity Firewall section, expanded Google API/OAuth compliance detail, added an Emergency Crisis Routing disclosure, corrected the subprocessor list (removed an inaccurate reference to a payment processor and a webinar vendor that are not integrated, added Supabase and Vercel), and clarified the data retention lifecycle for daily practice data versus permanent MCMP certification records.
Version 1.1 — September 2026Added Section 2.4 (Google Sign-In & Google User Data), disclosing what Google Account data BrioMon accesses via Sign in with Google, why, and confirming it is never sold or used for advertising, per the Google API Services User Data Policy.
Version 1.0 — July 2026Initial policy. Covers US, Canada, EU, UK, and Australia. GDPR, CCPA/CPRA, PIPEDA, and Australian Privacy Act 1988 compliance. B2B Data Processor provisions. Cookie framework pending final vendor selection.
BrioMon

A gym membership for the brain. Cognitive training and workplace resilience for modern tech teams.

Product
  • How It Works
  • For Corporate Admins
  • For Employees
  • Pricing
Company
  • About
  • Research
  • Blog
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • GDPR
  • Data Rights
  • Sub-Processors
  • Cookie Policy
© 2026 BrioMon Technologies LLC · 1603 Capitol Avenue, Suite 413, Cheyenne, WY 82001, USA. All rights reserved.
Built with ❤️ for the modern workforce.