eno User Privacy Policy

Mindset Innovation II, Inc. (DBA “eno”)

Effective: August 1, 2026

Your brain data is yours. eno makes brain-sensing headphones and adaptive audio. Because we measure brain activity, we hold your data to the highest standards of privacy: we keep your brain data separated from your identity, we process it on your device by default, we never sell it, and the data we use to improve our technology is irreversibly anonymized first. This Policy explains what we collect, how we protect and use it, and the choices you have.

(Plain-language note: EEG measures the brain’s electrical activity to estimate states like focus or calm. It does not read, record, or interpret your thoughts.)

1. Scope and who we are

This Policy applies to our websites, mobile applications (iOS and Android), headphones, and related services (the “Services”). The data controller is Mindset Innovation II, Inc. (DBA “eno”), 6201 Hollywood Boulevard, Los Angeles, CA 90028. Contact: info@getenophone.com.

2. The information we collect

  • a. Information you provide, including contact details, account credentials, billing information, profile details (e.g., age, preferences), and your communications with us.
  • b. Brain, biometric & neural data: when you use eno we collect brain-activity (EEG) signals and related physiological/biometric data, plus session metadata and the audio presented, to estimate your state and adapt the sound. We treat identifiable EEG/biometric data as sensitive personal data, and, where it is generated by measuring your nervous system, as neural data under the laws described in Section 12.
  • c. Automatically collected information includes device type, app/usage and log data, approximate (non-precise) location, and cookies.
  • d. From third parties: health-platform integrations you choose to enable (e.g., Apple Health) and standard website analytics.

3. How we protect your personal data

We handle your brain data in two distinct tiers, and the difference matters:

  • Operational data (tied to your account). To deliver and personalize your experience, your EEG is pseudonymized, stored under an anonymous identifier and kept separate from your identity, with your account as the only place the two are linked. This data is still personal data, and all of your rights in Section 9 apply to it.
  • Improvement data (anonymized). The data we use to develop and improve our technology is first irreversibly anonymized, stripped of identifiers and de-linked so it can no longer be traced back to you, with no retained key. Once data is irreversibly anonymized it is no longer personal data, and we may retain and use it as described in Section 4.

4. How we use your information

To provide, operate, personalize, secure, and improve the Services; to process orders and support you; to communicate with you; and to comply with law.

Research, AI and model development using anonymized data as described above. We use irreversibly anonymized data to conduct research and to develop, train, test, and improve eno’s own models and features. We do not sell your data and do not use your data to train third parties’ models.

5. Consent

  • One-time setup consent (for eno’s own use). When you create your account and accept our Terms, you consent once to our collection and use of your EEG/biometric data to provide and personalize the Services and, on an anonymized basis, for the research and model development in Section 4. We do not re-prompt you every session.
  • Opt out anytime in Settings. You can turn off the use of your data for research and model development at any time. Opting out stops future such use; it does not undo processing already performed or affect data already irreversibly anonymized.
  • Separate, explicit opt-in for any third-party sharing. We share your data with an outside party only with your separate, case-by-case consent, and only on an anonymized basis. See Section 6.

6. How we share information

  • Service providers acting for us (hosting, payments, fulfillment, analytics, support), under confidentiality and data-protection obligations;
  • Third parties. We do not share your brain/sensitive data with third parties except (i) with your separate, explicit, case-by-case consent and only on an anonymized basis, or (ii) where required by law;
  • Legal and safety: to comply with law or protect rights and safety;
  • Business transfer: in a merger, financing, acquisition, or sale of assets; we will give you reasonable notice before your data becomes subject to a materially different policy;
  • At your direction / with your consent.

7. We do not sell your data; no advertising use of health data

We do not sell your personal data, and we do not use your EEG/biometric or other health data for third-party or cross-context behavioral advertising. We honor the Global Privacy Control (GPC) signal as an opt-out of any “sale” or “sharing.”

8. Where we process your data

Most processing happens on your device. Some post-session processing and storage occurs in our cloud as part of delivering and improving the Services. Our architecture is designed to minimize the amount of processing done in the cloud. Where allowed by local law, data may be processed in countries other than yours, with appropriate safeguards (Section 13).

9. Your rights and choices

Wherever you live, you may access, correct, delete, export (portability), and withdraw consent, and ask us to restrict processing. You may opt out of marketing and manage cookies. We honor GPC. We will not discriminate against you for exercising these rights. To exercise any right, contact info@getenophone.com or use in-app Settings; we respond within the timeframe required by your local law (and in any case within 45 days, extendable where law allows). We verify your identity before acting on a request.

10. Security

We use encryption in transit and at rest, access controls limiting staff access to a legitimate need, and pseudonymization/anonymization. No system is perfectly secure, but we treat brain data with heightened safeguards.

11. Data retention and destruction

We retain personal data for the life of your account and as needed to provide the Services. Identifiable biometric/neural data schedule: we retain identifiable EEG/biometric data only as long as needed for the purpose collected, and in no event longer than 3 years after your last interaction, after which we permanently destroy or irreversibly anonymize it. Irreversibly anonymized data is no longer personal data and is not subject to this schedule; we may retain it, including for research and model development.

12. Brain data, the law, and your protections by region

We treat your brain data to a high standard and comply with the laws that govern it, including the following privacy and neural-data laws:

  • California (CCPA/CPRA, incl. SB 1223): “sensitive personal information” now expressly includes neural data. You may know/access/correct/delete, limit the use of your sensitive personal information, opt out of any “sale”/“sharing,” and receive non-discrimination. We do not sell or share for cross-context behavioral advertising.
  • Colorado (Colorado Privacy Act, HB 24-1058): Colorado classifies neural data as sensitive data. We process your neural/EEG data only with your consent, and you may access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling.
  • Washington (My Health My Data Act): your brain/physiological data is “consumer health data”; we collect it with your consent, do not sell it, and honor access/deletion/withdrawal.
  • Illinois (BIPA) and other biometric laws: where they apply, we maintain this written policy, obtain consent before collection, follow the retention/destruction schedule in Section 11, and do not sell or profit from biometric identifiers.
  • EEA/UK (GDPR), where applicable: brain/biometric data is “special category” data processed on your explicit consent (Art. 9), with full data-subject rights.
  • Canada (PIPEDA / applicable provincial law): we handle your data on a consent basis with the rights described above.

13. International transfers

Where we transfer data internationally, we use recognized safeguards (e.g., Standard Contractual Clauses) and transfer only what is necessary.

14. Children

The Services are intended for users 16 and older; we do not knowingly collect data from anyone under 16.

15. Health disclaimer (not a medical device / not HIPAA)

eno is a general-wellness product, not a medical device, and is not intended to diagnose, treat, cure, or prevent any disease. eno is not a HIPAA “covered entity” for its direct-to-consumer Services.

16. Changes to this Policy & how we will tell you

We may update this Policy. We will post the revised Policy, update the version/effective date, and include a short summary of what changed. For material changes we will give advance notice (at least 30 days) by email (if we have your address) and/or in-app notice, and where a change involves new processing of your sensitive/brain data we will ask for your renewed consent before it takes effect.

17. Contact

Mindset Innovation II, Inc. (DBA “eno”) · 6201 Hollywood Boulevard, Los Angeles, CA 90028 · info@getenophone.com