1. Scope
This Privacy Policy ("Policy") applies to CogniSci Labs, Inc. ("CogniSci," "we," "us") websites, apps, Testing Kits, logistics, wellness reports, dashboards, and related features (the "Services"). U.S. only; 18+.
2. Information We Collect
- Identifiers & contact: name, email, phone, postal address, account IDs.
- Commercial info: orders, subscriptions, transaction details (processed by our payment processors).
- Device/usage: IP, browser, app/device IDs, pages viewed, referring URLs, approximate location, analytics, and logs.
- Communications: emails, support chats, surveys, and SMS preferences.
- Wellness questionnaire data (optional): lifestyle inputs you choose to provide.
- Biological sample & derived wellness data (members using testing): saliva sample status and lab-generated, non-diagnostic wellness signals used to produce informational reports (e.g., CerebralScoreTM). Labs are independent CLIA-certified and/or state-licensed entities.
3. Sources
Directly from you; automatically via your device; service providers (e.g., payment, shipping, analytics); independent laboratories for non-diagnostic processing; optional external identity/verification services if needed.
4. How We Use Information
- Provide and improve the Services; personalize content and dashboards.
- Facilitate lab logistics and deliver informational wellness reports.
- Communicate about orders, results availability, membership, support, and product updates (see SMS).
- Protect against fraud, abuse, and security incidents.
- Comply with law and enforce our Terms.
- Research (optional, separate opt-in): product-improvement research using de-identified data and/or leftover sample.
5. How We Disclose Information
- Service providers & processors: hosting, analytics, payments, shipping, communications, security, and support—under contracts limiting their use.
- Independent labs: to receive/process Samples and produce wellness data for your report.
- With your direction: if you share your report with a clinician or third party.
- Legal & safety: to comply with law, enforce terms, or protect rights/security.
- Business transfers: in a corporate transaction, subject to this Policy.
7. Retention
We retain Personal Information only as reasonably necessary to provide the Services and as required by law. Upon a verified request to privacy@cognisci.ai, we will begin processing deletion, remove or de-identify active copies within ~30 days, and remove or cryptographically isolate routine backups/logs within an additional ~90 days, subject to legal/audit/fraud/security retention needs. De-identified/aggregated data may be retained.
8. Security
We use technical and organizational safeguards designed to protect Personal Information. No method of transmission or storage is perfectly secure. If we learn of a security incident affecting your data, we will notify you as required by law.
9. Children
The Services are for adults 18+. We do not knowingly collect Personal Information from children under 18.
10. Transfers
We process data in the U.S. and may transfer to other locations via vetted service providers subject to appropriate contractual safeguards.
11. Health Data Categories, Purposes, Sharing & Rights (WA/NV style)
What's covered. Some information we handle in connection with our wellness Services may be considered "consumer health data" under certain state laws (e.g., Washington My Health My Data, Nevada Consumer Health Data). This section describes our practices for that data.
Categories
- Wellness-related information you provide (e.g., optional questionnaire inputs you choose to share).
- Biological sample logistics (e.g., kit activation status, shipping, receipt) and derived non-diagnostic wellness data returned by independent labs.
- Device/usage data that could be associated with wellness interactions (e.g., when you access your dashboard).
Purposes
- Provide the Services (collect, route, and process Samples; generate your informational wellness report).
- Maintain security, integrity, and quality; troubleshoot and improve features.
- Comply with law and respond to lawful requests.
- Optional research (only if you opt in).
Sharing/Processing
- Processors: cloud hosting, analytics, communications, and independent CLIA-certified labs—under contracts limiting use to our instructions.
- No geofencing advertising: we do not use geofencing to infer or target health status for advertising.
- No "sale" of health data as defined by these laws.
Your Choices & Rights
- Access, delete, or withdraw consent to specific processing where applicable. Contact: privacy@cognisci.ai.
- If you opted into research, you may withdraw (prior uses in completed analyses may not be retrievable).
12. Genetic / Biometric Information (e.g., CA GIPA, IL BIPA)
Purpose. For members using testing, your saliva Sample is routed to an independent CLIA-certified and/or state-licensed lab on a non-diagnostic basis to generate informational wellness signals for your report (e.g., CerebralScoreTM). We do not sell biometric identifiers or "genetic information."
Consent
- By activating your kit and submitting a Sample, you consent to processing your Sample and derived data for the wellness purposes described in this Policy and our Terms.
- Any optional research use requires your separate opt-in.
Retention & Destruction
- We retain Personal Information only as long as reasonably necessary for the purposes described or as required by law. See Retention.
- Leftover Sample is handled by the Lab under its policies and applicable law. Where you have opted into research, leftover Sample may be stored up to 10 years or until exhausted and then destroyed using lab-standard methods.
Disclosure
- We disclose to independent labs and service providers as described in How We Disclose. We do not disclose genetic/biometric information for advertising or marketing without consent.
13. Access, Deletion, Correction, Portability & Opt-Outs
Depending on where you live (e.g., CA, CO, CT, VA, UT), you may have rights to request: access/know, deletion, correction, portability, and to opt out of certain processing (e.g., "sale," "sharing" for cross-context behavioral advertising, targeted advertising, or significant profiling).
- Submit a request: email privacy@cognisci.ai from your account email and specify your request type.
- Verification: we may ask for reasonable information to verify you (and proof for authorized agents).
- Appeals: if we deny your request, you may appeal by replying to our decision email; we'll respond as required by your state law.
14. Do Not Sell/Share & Targeted Ads
Current status: we do not sell Personal Information and do not share it for cross-context behavioral advertising as those terms are defined by applicable laws. If this changes, we will update this Policy and provide appropriate opt-out mechanisms (including honoring Global Privacy Control where required).
For cookie-based analytics/ads signals (if enabled in the future), you can use browser settings, in-product controls, and (where required) the "Your Privacy Choices" link we would provide.
15. SMS Disclosures (Transactional)
If you provide a mobile number, we may send transactional texts (e.g., orders, results availability, account). Message frequency varies; message/data rates may apply. Reply STOP to unsubscribe and HELP for help. Marketing texts require separate opt-in and can be opted out at any time.
16. Changes to this Policy
We may update this Policy and will post the effective date at the top. For material changes, we will provide additional notice where required (e.g., email or in-product) at least 30 days before the effective date when practicable.
17. Contact & Controller
Controller: CogniSci Labs, Inc.
330 S Second AveSuite 200 1364
Minneapolis, MN 55401
Privacy: privacy@cognisci.ai | Support: support@cognisci.ai