This Privacy Policy explains how BrioMon Technologies LLC ("BrioMon", "we", "us", or "our") collects, uses, discloses, and protects personal information when you visit briomon.com, use our web portal at app.briomon.com, or use our mobile application (collectively, the "Services"). Please read this policy carefully before using our Services.
Who We Are & Regulatory Status
1.1 Corporate Identity
BrioMon is owned and operated by BrioMon Technologies LLC, a Wyoming limited liability company located at 1603 Capitol Avenue, Suite 413, Cheyenne, WY 82001, USA.
1.2 Dual Regulatory Role
Data Controller
For individual subscribers who create an independent personal account directly through briomon.com or mobile applications, BrioMon acts as the Data Controller under GDPR Article 4(7).
Data Processor
For employees and contractors provisioned access under an enterprise agreement, the Corporate Client acts as the Data Controller, and BrioMon acts strictly as the Data Processor under GDPR Article 4(8) and Article 28. In such instances, processing is executed pursuant to an executed Data Processing Agreement (DPA). Your employer cannot see your individual data — only anonymised aggregate team metrics with a minimum of 5 active users (see Section 4).
1.3 Non-Clinical Standing
BrioMon is an upstream cognitive capacity management platform. It does not provide medical services, clinical diagnosis, or therapeutic treatment. Personal journal entries and pulse inputs are processed strictly for self-directed personal development and are not classified as Protected Health Information (PHI) under HIPAA.
Information We Collect
2.1 Account & Identity Data
Full name, primary email address, password hash (via secure authentication providers), company affiliation (for corporate users), role title, and chosen community display pseudonyms.
2.2 Mental Capacity Inputs (The Den)
- Daily Pulse Check: Visual slider ratings representing self-reported mental energy and subjective valence (pleasant/unpleasant).
- Mind Assessment Data: Interactive, non-clinical behavioral tap responses and reaction distributions.
- Guided Journal Entries: Freeform text reflections submitted to the Mental Capacity Assessment Engine (MCAE™) to generate contextual restorative recommendations.
- Growth Telemetry: Active habit streaks, completed practice modules, and 30-day capacity trajectory curves.
2.3 Enterprise Administration Data
Department assignments, organizational seat allocation metrics, cryptographic single-use invitation tokens, and role designations (Super Admin, Admin, Moderator).
2.4 Transactional & Financial Data
Billing address, tax jurisdiction, and payment confirmation records. Full credit card numbers and banking details are never collected or stored on BrioMon servers. Payment processing is handled externally by our Merchant of Record (MoR) partners, 2Checkout and Paddle (see Section 7).
2.5 Technical & Telemetry Data
IP address, device fingerprints, operating system type, browser user-agent, session timestamps, and diagnostic error logs.
2.6 Data We Do Not Collect
BrioMon does not collect and will never request:
- Government identification numbers (Social Security numbers, national ID numbers, passport numbers)
- Financial account numbers, bank account details, or full payment card numbers
- Medical records, clinical diagnoses, or health information as defined under HIPAA
- Biometric data
- Data from children under the age of 18 (our Services are for professionals aged 18 and over)
- Precise real-time GPS location
2.7 Google Sign-In & Google User Data
When you choose to sign in to BrioMon using Google Sign-In, we access basic profile information from your Google Account -- your name, email address, and profile picture -- solely to create and authenticate your BrioMon account. See Section 5 for our full Google API User Data Policy commitments.
How We Use Personal Data & Legal Bases
Under GDPR Article 6, we process personal information strictly under the following lawful bases:
3.1 Performance of a Contract (Art. 6(1)(b))
- Provisioning and maintaining your account and access to the web workspace at app.briomon.com.
- Processing subscription billings, renewals, and invoice distributions.
- Delivering the MCMP Foundation Certification course and issuing verifiable completion certificates.
3.2 Legitimate Interests (Art. 6(1)(f))
- Operating the Mental Capacity Assessment Engine (MCAE™) to analyze sentiment and match targeted performance practices to real-time cognitive friction.
- Maintaining platform stability, monitoring application performance, and preventing fraudulent access.
- Preserving verified alumni certification records so users maintain permanent access to earned credentials.
3.3 Legal Obligations (Art. 6(1)(c))
- Fulfilling statutory corporate tax reporting, accounting laws, and lawful government directives.
3.4 Consent (Art. 6(1)(a))
- Delivering non-essential product update announcements or optional communications, which can be withdrawn at any time.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects without human review.
The Corporate Anonymity Firewall
4.1 Absolute Individual Privacy
The platform enforces an architectural separation between employee workspaces and administrative dashboards. Corporate administrators, HR personnel, and leadership are strictly barred from viewing:
- Individual Daily Pulse ratings or historical scores.
- Individual Guided Journal entries or freeform text.
- Specific protocols or modules selected and practiced by a given employee.
- The true identity behind any employee post or reaction on the Community Board.
4.2 The 5-User Mathematical Floor
Workforce vitality analytics, team capacity trends, and strain indicators are aggregated and displayed only when a department or team has at least five (5) active members participating. If a team size falls below 5, data is rolled up into the general organization-wide pool to prevent reverse-engineering of individual inputs.
Google API User Data Policy Compliance
When you choose to authenticate or access BrioMon using Google Single Sign-In (OAuth), the following commitments apply:
5.1 Data Accessed
BrioMon accesses only basic Google profile information (your verified email address, full name, and avatar image) strictly to authenticate your account and provision your profile. We do not request or access any other Google data (Gmail, Drive, Calendar, or any other Google service) through this sign-in flow.
5.2 Strict Limitation of Use
- No Advertising: Google user data is never used to serve personalized, retargeted, or interest-based advertisements.
- No Data Brokering: We do not sell, rent, trade, or transfer Google user data to third parties, data brokers, or marketing networks under any circumstance.
- No Surveillance: BrioMon does not use Google user data for employee surveillance or administrative monitoring.
- Human Review Constraints: BrioMon personnel do not read or inspect user data accessed through Google APIs, except where explicitly requested by the user for technical troubleshooting, required by law, or aggregated internally for security investigations.
5.3 Retention & Google Limited Use Disclosure
Google Sign-In data is retained for as long as your BrioMon account remains active and is deleted upon account deletion (see Section 9) or on request to privacy@briomon.com. BrioMon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies & Tracking Technologies
6.1 Strictly Necessary Cookies
BrioMon uses only strictly necessary session and authentication cookies, issued through our infrastructure provider, required to sign you in, maintain your session, and protect against cross-site request forgery (CSRF). These cannot be disabled without breaking core application functionality.
6.2 No Analytics or Marketing Trackers
BrioMon does not currently deploy analytics cookies, third-party advertising pixels, or cross-site behavioral marketing scripts (for example, Google Analytics or the Meta Pixel) on briomon.com or within the authenticated application at app.briomon.com.
6.3 Future Changes
If BrioMon introduces functional, analytics, or marketing cookies in the future, this policy will be updated in advance and, where required by law, your consent will be requested before any non-essential cookie is set. For a full list of every cookie BrioMon and its third-party providers set, see our Cookie Policy.
Data Sharing & Third-Party Processors
We do not sell personal information. We transfer data strictly to vetted service providers acting as subprocessors under formal Data Processing Agreements:
| Cloud Infrastructure, Database & Authentication | Supabase Inc. — encrypted at rest via AES-256 and in transit via TLS 1.3. |
| Application Hosting | Vercel Inc. — hosts and serves the BrioMon web application. |
| Edge Delivery & Security | Cloudflare Inc. — CDN delivery, DDoS protection, edge routing. |
| Transactional Communications | Resend — delivery of account verification links, password resets, and billing/invoice notifications. |
| Payment Handling | Payment processing is handled externally by our Merchant of Record (MoR) partners, 2Checkout and Paddle. BrioMon never processes, stores, or sees full payment card details or banking credentials on its servers. See our Sub-Processors page for which partner handles which product, and our Cookie Policy for the cookies they set. |
| Emergency Crisis Routing | In acute safety scenarios, automated routing links users directly to external, third-party national crisis lines (e.g., the 988 Lifeline). No internal user profile or journal text is transmitted to crisis providers. |
| Legal & Regulatory Bodies | Where required by applicable law, court order, or regulatory authority. We will notify you where legally permitted to do so. |
International Data Transfers
Personal data collected through BrioMon is hosted on secure cloud infrastructure located within the United States.
For data originating in the European Economic Area (EEA), United Kingdom, or Switzerland:
- Transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) under Decision (EU) 2021/914 and, for the UK, the International Data Transfer Addendum to the EU SCCs issued by the ICO.
- All data transfers incorporate mandatory technical and organizational safeguards, including end-to-end TLS 1.3 encryption and restricted role-based administrative access.
Data Retention & Erasure Schedule
9.1 Active Accounts
Personal data, pulse logs, and journal reflections remain available throughout the active duration of your subscription.
9.2 Two-Tier Post-Subscription Lifecycle
| Daily Practice Telemetry | All raw personal reflections, private journal entries, and granular daily pulse records are purged within six (6) months following account cancellation or subscription lapse. |
| MCMP Alumni Registry | Permanent certification records (name, verification token ID, issue date) are maintained indefinitely under legitimate interests to allow alumni to verify credentials via their certificate link, unless an explicit request for complete erasure is submitted. |
| Aggregated Analytics | Historical organizational telemetry retained by Corporate Clients is stripped of individual identifying attributes and retained purely as anonymized aggregate data points. |
9.3 Other Retention Periods
| Payment & Transaction Records | 7 years from the transaction date (required for tax and financial compliance in all operating jurisdictions) |
| Support Communications | 2 years from the date of last contact |
| Marketing Consent Records | Until consent is withdrawn, plus 12 months |
| Security & Server Logs | 90 days |
When data is no longer required for the purposes stated in this policy, we securely delete or irreversibly anonymise it. Anonymised aggregate data, from which no individual can be identified, may be retained indefinitely for research and service improvement.
Data Security & Storage Architecture
- Encryption in Transit: TLS 1.3 for all data in transit.
- Encryption at Rest: AES-256 for all database volumes, backups, and user tables.
- Password Security: Passwords are stored using industry-standard cryptographic hashing and are never stored in plaintext.
- Access Controls: Role-based permissions restrict access to personal data on a need-to-know basis only.
- Logical Separation: Corporate client data is isolated via tenant identifier scoping, preventing cross-organization data leakage.
- Data Processing Agreements: GDPR-compliant DPAs are in place with all third-party subprocessors.
- Incident Response: In the event of a confirmed security breach involving personal data, BrioMon will notify relevant supervisory authorities and affected users within seventy-two (72) hours of verification, in accordance with GDPR Article 33.
No method of transmission or storage over the internet is 100% secure. While we use commercially reasonable measures to protect your personal data, we cannot guarantee absolute security.
Your Statutory Privacy Rights
Depending on your geographic location, you possess specific legal rights regarding your personal data. We respond to all verified requests within 30 days (EU/UK/Australia/Canada) or 45 days (US) of receipt.
11.1 Rights for All Users
| Access | Request a copy of the personal data we hold about you |
| Correction | Request correction of inaccurate or incomplete personal data |
| Deletion | Request deletion of your personal data, subject to legal retention obligations |
| Portability | Receive your journal inputs and progress telemetry in a structured, machine-readable JSON format |
| Withdraw Consent | Withdraw consent for marketing communications at any time without affecting prior processing |
11.2 GDPR & UK GDPR Rights (EEA & UK Residents)
Expand EU / UK Rights
- Right of Access (Art. 15): Request a full copy of the personal data BrioMon holds about you.
- Right to Rectification (Art. 16): Request correction of incomplete or inaccurate data.
- Right to Erasure, "Right to be Forgotten" (Art. 17): Request complete deletion of your personal data, subject to statutory retention exceptions.
- Right to Restriction of Processing (Art. 18): Request restriction of data processing under certain dispute conditions.
- Right to Data Portability (Art. 20): Export your journal inputs and progress telemetry in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing grounded in legitimate interests.
You also have the right to lodge a complaint with your national data protection authority (e.g., your country's DPA in the EU, or the ICO in the UK at ico.org.uk).
11.3 CCPA & CPRA Rights (California Residents)
Expand California Rights
- Right to Know: Disclosure of categories of personal data collected, sources, and commercial purposes.
- Right to Delete: Request deletion of personal information collected from you, subject to exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: BrioMon does not sell or share personal information for cross-context behavioral advertising; therefore, no opt-out is required.
- Right to Limit Use of Sensitive Personal Information: Limit the use and disclosure of sensitive personal information.
- Non-Discrimination: BrioMon will never deny services, alter prices, or downgrade service quality for exercising statutory privacy rights.
To submit a California privacy request: privacy@briomon.com
11.4 Rights — Australian & Canadian Residents
Expand Australia / Canada Rights
Australia: Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), you have the right to access and correct your personal information and to make a complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Canada: Under PIPEDA, you have the right to access and correct your personal information. Complaints may be directed to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
How to Submit a Rights Request
Email privacy@briomon.com with the subject line "Data Subject Rights Request". State your full name, registered email address, and the specific right you wish to exercise. Identity verification will be performed prior to data disclosure or modification.
Children's Privacy
BrioMon is designed exclusively for adult professionals and working teams. The platform is not intended for individuals under 18 years of age. We do not knowingly collect, solicit, or process personal data from children. If we discover that an individual under 18 has submitted personal information, we will immediately deactivate the account and permanently delete all associated data from our servers. If you believe we have inadvertently collected data from a minor, please contact privacy@briomon.com immediately.
Contact & Supervisory Authority Details
If you have questions, feedback, or concerns regarding this Privacy Policy or our data protection practices, please contact us:
Contact BrioMon
BrioMon Technologies LLC
1603 Capitol Avenue, Suite 413
Cheyenne, WY 82001, USA
Data Protection Inquiries: privacy@briomon.com
General Communications: connect@briomon.com
Legal Operations: legal@briomon.com
Website: briomon.com
13.1 Supervisory Authorities
If you are not satisfied with our response, you have the right to complain to the supervisory authority in your jurisdiction:
| European Union | Your national Data Protection Authority — see edpb.europa.eu |
| United Kingdom | Information Commissioner's Office (ICO) — ico.org.uk |
| Australia | Office of the Australian Information Commissioner — oaic.gov.au |
| Canada | Office of the Privacy Commissioner — priv.gc.ca |
| United States | Federal Trade Commission — ftc.gov; California: CPPA at cppa.ca.gov |
13.2 How We Update This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Effective Date" and "Last Reviewed" date at the top of this policy, display a prominent notice on briomon.com for at least 30 days, and send an email notification to all registered users. Your continued use of the Services after the effective date of any updated policy constitutes your acceptance of the changes. If you do not agree with the revised policy, you may close your account by contacting privacy@briomon.com.
| Version 1.4 — September 2026 | Simplified Section 2.4 and Section 7 to name our Merchant of Record partners (2Checkout, Paddle) without mapping each to a specific product -- that level of detail now lives on the Sub-Processors page, which is the single source of truth for it. |
| Version 1.3 — September 2026 | Updated Section 2.4 and Section 7 to name 2Checkout/2Monetize and Paddle as the active Merchant of Record partners for individual and corporate payments respectively, replacing the prior manual-invoicing description, and cross-referenced the new Cookie Policy for the cookies these processors set. |
| Version 1.2 — September 2026 | Restructured and rewritten in full: added a dedicated Corporate Anonymity Firewall section, expanded Google API/OAuth compliance detail, added an Emergency Crisis Routing disclosure, corrected the subprocessor list (removed an inaccurate reference to a payment processor and a webinar vendor that are not integrated, added Supabase and Vercel), and clarified the data retention lifecycle for daily practice data versus permanent MCMP certification records. |
| Version 1.1 — September 2026 | Added Section 2.4 (Google Sign-In & Google User Data), disclosing what Google Account data BrioMon accesses via Sign in with Google, why, and confirming it is never sold or used for advertising, per the Google API Services User Data Policy. |
| Version 1.0 — July 2026 | Initial policy. Covers US, Canada, EU, UK, and Australia. GDPR, CCPA/CPRA, PIPEDA, and Australian Privacy Act 1988 compliance. B2B Data Processor provisions. Cookie framework pending final vendor selection. |