Privacy
This describes what NoeticCog actually stores and who can reach it. It is written to be checked against the product, not to be skimmed.
Last updated 6 September 2026
What this is
NoeticCog records a short daily self-report and turns it into four scores. That record is health information about you, and it is treated as sensitive throughout. NoeticCog is the controller of that data.
What is collected
- Your daily check-in. Energy, stress, hours slept, whether you were ruminating, and how much social contact you had. Optionally a free-text note, which can contain anything you choose to write.
- Scores derived from it. Stability, volatility, burnout risk and spiral risk, computed from your own history by a fixed formula. No model is trained on your data.
- Your account. Email address and a password hash, held by our authentication provider. We never see your password.
- Things you add. Annotations, tags, reminder preferences, and the plan you are on.
- Wearable measurements, only if you connect one. Sleep, resting heart rate and heart-rate variability from Oura, Whoop, Fitbit or Garmin. You can disconnect at any time.
- Push subscriptions, only if you enable notifications.
There is no advertising, no analytics profile, no third-party tracker, and nothing is sold. Your data is not used to train any model.
Who else can see it
By default: nobody but you. Every table is protected by row-level security, so a query for another person’s rows returns nothing rather than being filtered after the fact. Data leaves that boundary in exactly three ways, and you start all three:
- A clinician you invite. You choose the scopes they receive, and each is separate — scores, adherence, notes, medications, experiments. Notes are never included unless you grant that scope specifically. You can revoke access at any time.
- A share link you create. Time-limited and scoped. Anyone holding the link can view what it covers until it expires or you delete it.
- A trusted contact, during a sustained crisis. If you nominate someone and they confirm, they may be emailed when your risk stays elevated for several consecutive days. They are told to check on you. They are never sent your scores or your notes.
Processors we rely on
- Supabase — database, authentication, and storage of everything above.
- Vercel — application hosting. Serves the app; does not store your health data.
- Resend — sends account, reminder and alert email.
- Anthropic — if note analysis is enabled, note text is sent to summarise recurring themes. It is not used for training. Leave notes blank and nothing is ever sent.
- Oura, Whoop, Fitbit, Garmin — only those you connect yourself.
How long it is kept
Indefinitely, until you delete it. That is deliberate: the product is only useful across months, and silently expiring your history would break the thing you came for. Deleting your account removes it immediately and permanently — check-ins, scores, notes, annotations, tags, share links, safety settings and wearable samples. Deletion is not reversible and there is no grace period.
Your rights
You can export everything as JSON or CSV, and delete your account, from Settings — both immediately, without asking us. Beyond that you may request access, correction, or that we restrict processing. Depending on where you live you may also have the right to complain to a data-protection authority.
Security
Traffic is encrypted in transit and data is encrypted at rest by our database provider. Access is enforced in the database itself through row-level security rather than in application code, so a bug in the interface cannot expose another person’s rows. No system is perfect; if we discover a breach affecting your data we will tell you.
Not a medical service
NoeticCog is not a medical device. It does not diagnose or treat any condition and is not a substitute for professional care. Nothing here creates a clinician-patient relationship, including when you share data with a clinician through the product. If you are in immediate danger, contact your local emergency services.
Children
NoeticCog is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will delete it.
Changes
If this policy changes materially we will say so in the app before the change takes effect, rather than quietly updating the date at the top.
Contact
Questions, requests, or complaints: privacy@noeticcog.app. This service is operated from India.