PRIVACY
Privacy Policy
1. Data controller
- The controller of personal data related to NeuroHackingApp.com is BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Długa 2B, 56-416 Twardogóra, Polska. KRS 0000841054; NIP 9112034523; REGON 386056613; Sąd Rejonowy dla Wrocławia-Fabrycznej we Wrocławiu, IX Wydział Gospodarczy KRS; kapitał zakładowy 20 000 zł (the “Controller”).
- Privacy and data-rights contact: [email protected].
- The Controller processes personal data in accordance with the GDPR and other applicable data-protection laws.
2. Scope of this policy
This Policy covers processing connected with the website, Account, self-observation features, reports, first-party analytics, notifications, email verification, and optional Telegram and Web Push integrations.
3. Categories of data
Depending on the functions used, the Controller may process:
- Account data: email address, display name, password hash, Account status and email-verification date;
- session and security data: securely hashed session identifiers, session creation/expiry/revocation times and security events;
- consent and document data: accepted versions of the Terms and Privacy Policy, acceptance source and timestamp;
- self-observation data: values voluntarily entered regarding, for example, sleep, energy, stress, focus, priorities, protocol/experiment completion and journal entries;
- Focus Lab and progress data: session duration, interruptions, completed steps, Academy progress and similar usage data;
- voluntary content: notes and other information entered by the User;
- notification data: timezone, language, quiet hours, enabled channels, delivery statuses and—for Web Push—technical subscription data required to deliver a notification;
- Telegram integration data: a technical hash used for account linking, link status and login events; the web database does not store raw Telegram ID or raw initData;
- first-party analytics data: event type, day, Service area, limited event properties and, for anonymous users, a random browser-session identifier stored in
sessionStorageand hashed server-side; - support correspondence if the User voluntarily contacts the Controller.
4. Health-related and sensitive information
- NeuroHackingApp is not a medical-record system and is not intended to store diagnoses, laboratory results, treatment history, clinical documentation or other medical records.
- Some self-observation fields include subjective scales for sleep, energy and stress. Depending on context, information entered by a User may reveal information related to health or wellbeing.
- Users should not enter special-category data in free-text fields where it is not necessary for the function being used, including diagnoses, test results, genetic information, treatment details or third-party health information.
5. Purposes and legal bases
Personal data may be processed for the following purposes:
- creating and operating the Account, authentication, storing self-observation data, reports and settings — to perform the contract for Electronic Services (Article 6(1)(b) GDPR);
- maintaining security, preventing abuse, protecting system integrity and establishing, exercising or defending legal claims — based on the Controller’s legitimate interests (Article 6(1)(f) GDPR);
- limited first-party analytics for improving product operation and content quality — based on legitimate interests, subject to legal requirements governing storage or access to information on a User’s terminal equipment;
- complying with legal, accounting, tax or lawful authority obligations where applicable (Article 6(1)(c) GDPR);
- sending communications that legally require consent — on the basis of consent where required (Article 6(1)(a) GDPR).
6. Email verification
- During registration, the Service may send a message containing a single-use verification link.
- The verification token is single-use, time-limited and stored server-side only as a hash.
- The link uses the URL fragment so the token is not sent in the initial HTTP request; the verification page removes the fragment from the visible URL and submits the token through a same-origin POST request.
7. Telegram integration
- Telegram integration is optional and activated by the User.
- The web side stores a technical hash of the account-linking identifier rather than raw Telegram ID.
- Data needed to operate Telegram features is also processed by Telegram under its own terms and privacy rules.
- When an Account linked to Telegram is deleted, the Service attempts to delete the linked Telegram-engine profile before deleting the User’s web data.
8. Web Push and notifications
- Web Push requires an active browser-created subscription and User permission for notifications.
- The Service does not automatically trigger the browser’s system permission prompt without User action.
- Notification preferences may include timezone, quiet hours and selected channels.
- Technical Web Push delivery may involve the browser or operating-system vendor’s push service.
9. First-party analytics
- The Service uses its own analytics to measure, for example, page views, reading depth, CTA clicks and the number of results returned by knowledge search.
- Analytics events do not store raw IP address, full User-Agent, email address, raw search query, raw Telegram ID or a device fingerprint.
- For anonymous sessions, an identifier is generated in the browser and stored in
sessionStorage; the server stores only its hash. - Anonymous events are retained for up to 90 days and events associated with an authenticated User for up to 365 days under the current Service retention mechanism.
10. Cookies, sessionStorage and local storage
- The Service uses technical mechanisms necessary for authentication and security, including the
nha_sessionsession cookie and a CSRF mechanism. In production, the session cookie is configured withHttpOnly,SecureandSameSite=Lax. sessionStoragemay hold a random identifier for the current anonymous analytics session and is scoped to the browser tab/session.- The PWA/Service Worker may cache public resources for offline behavior and resilience in accordance with Service configuration.
- The Service does not operate its own device-fingerprinting mechanism.
11. Recipients and technology providers
Data may be disclosed to entities supporting the Controller only to the extent needed for a specific purpose, including infrastructure, hosting, email, network-protection, Web Push and communications-integration providers. Public NeuroHackingApp traffic may currently be protected by Cloudflare, while the optional communications integration uses Telegram.
The Controller periodically verifies provider roles, processor arrangements and the legal basis for any transfers outside the EEA against current provider documentation and contractual arrangements.
12. Retention
- Account and functional data are retained while the Account remains active and for as long as required to perform the service agreement.
- After Account deletion, active-profile data is removed under the Service’s deletion mechanism, subject to data that must remain for legal obligations, legal claims or technical backup-retention cycles.
- Backups follow limited rotating retention and disaster-recovery procedures.
- Anonymous analytics: up to 90 days. Authenticated User analytics: up to 365 days.
- Email-verification tokens are short-lived; the current validity period is 24 hours.
13. Security
The Controller applies technical and organizational measures including HTTPS, access control, secure cookies, CSRF protection, password hashing, verification-token hashing, rate limits, separation of internal interfaces, permission controls, backups and restore testing. No information system can eliminate all security risk.
14. Data-subject rights
Where provided by the GDPR, a person may request access, rectification, erasure, restriction, data portability and may object to processing based on legitimate interests. Where processing is based on consent, consent may be withdrawn without affecting the lawfulness of processing carried out before withdrawal.
Requests may be sent to [email protected]. A data subject also has the right to lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
15. Data export and Account deletion
- The Service provides an Account-data export function that excludes security secrets.
- A User may initiate Account deletion after an additional confirmation step.
- If the Account is linked to Telegram, the Service first attempts to delete the linked profile in the Telegram engine, then deletes the User’s web data and session cookies.
16. Automated decisions and profiling
- The Service may automatically generate recommendations, summaries or simpler suggested actions based on self-observation data.
- These functions personalize the User experience and are not intended to produce legal effects or similarly significant effects on the User.
- The Service does not make automated medical, diagnostic, insurance or employment decisions.
17. Users under 18
The Service is intended for people aged 18 or over. Registration requires minimum-age confirmation. The Controller does not design the Service as a product for children.
18. Changes to this Policy
The Policy may be updated due to changes in law, product functionality, data categories, providers or security measures. For registered Users, the Service may record the accepted document version and request acceptance of a new version where required.
19. Source and draft status
This NeuroHackingApp document uses Bomega.pl’s operator information and legal-document structure as a reference. It is not a copy of Bomega.pl’s Terms or Privacy Policy and excludes Bomega-specific functions such as RSS feeds, classified advertisements and public comments.
20. Effective date
This version was approved by the operator on 28 September 2026 and takes effect when published in the Service.