NoirNeuro
Personal achievement coaching
Back to sign in

Privacy Policy

Effective date: 2026-07-16 · Last updated: 2026-07-16

This Privacy Policy explains what data NoirNeuro accesses, why, how long it is kept, and how you can review, revoke, or delete it — including data accessed through Google APIs (Gmail, Google Calendar) and connected wearables (Fitbit, Apple HealthKit). NoirNeuro is a non-clinical, personal-achievement coaching product. It does not provide medical, mental-health, or diagnostic advice, and this policy does not cover protected health information — NoirNeuro is built to handle non-PHI data only.

Who this policy covers

NoirNeuro is operated by Darden Behavioral Counseling and Coaching, 1280 Creek Ridge Xing, Alpharetta, GA 30005 (“NoirNeuro,” “we,” “us”). This policy applies to the NoirNeuro web and mobile app and to every data source you choose to connect from it.

Data we access, and why

NoirNeuro only accesses the sources below after you explicitly connect them from Settings → Connections, and each one shows its own plain-language consent notice before you connect. Nothing outside your account data is accessed by default.

Gmail (read-only) — restricted Google scope

We read your Gmail messages to understand your current life context and surface commitments, deadlines, and follow-ups as part of your coaching plan. We store only derived text — coarse message counts and short thread summaries — never full message bodies, attachments, or a copy of your inbox. Gmail is never used to send, delete, or modify anything in your mailbox, is never used for advertising, and is never sold or shared with third parties.

Google Calendar (read, and limited write)

We read your Google Calendar to understand your fixed commitments, so scheduling never double-books time you already owe elsewhere. We store only derived event times as scheduling constraints — never event descriptions, locations, guest lists, or attendees. When you schedule a coaching session or commitment inside NoirNeuro, we write that single app-created event back to your connected calendar so it stays in sync with your real calendar; we do not edit or delete events we did not create.

Wearable biometric summaries (Fitbit / Apple HealthKit)

If you separately grant wearable consent (a distinct, itemized consent gate — see Settings → Connections), we store the wearable’s own daily summary numbers you choose to share: resting heart rate, heart-rate variability (HRV), sleep duration and efficiency, step count, active energy, breathing rate, blood-oxygen saturation (SpO2), and logged workouts. We never receive a minute-by-minute or raw sensor stream. This is used only so your coach’s recommendations can reason over real multi-month trends (e.g. sleep debt, recovery) instead of a single coarse reading, and it is visible only to you and, if you have one, your coach.

Other connected messages/comms

Any additional message source you connect (including the Gmail connector above, and any in-development sample/dev source used only for testing) is treated identically: we ingest it only to derive coarse counts and short thread summaries for coaching context, we never store full content, and we never share it.

We separately collect ordinary account data to operate the product: your name/email, a Firebase-issued account identifier, your role (member, coach, or admin), and the goals, schedule, and coaching activity you create directly inside NoirNeuro. That data is not sourced from Google or a wearable and is used solely to provide the coaching product to you.

Google API Services User Data Policy — Limited Use

NoirNeuro’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain language, this means data we obtain through Google APIs (Gmail, Google Calendar):

  • is used only to provide or improve the user-facing features described on this page (life-management analysis, commitment/deadline surfacing, and calendar-aware scheduling) — never for any other purpose;
  • is never used for advertising of any kind, including retargeting or interest-based advertising;
  • is never sold, rented, or transferred to any third party, data broker, or ad network;
  • is never read by a human at NoirNeuro, except: (a) with your affirmative consent for a specific purpose (e.g. support you request); (b) as necessary for security purposes, such as investigating abuse or a suspected security incident; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized;
  • is transferred to another party only as needed to provide or improve these features, or as required by law, and never to facilitate a sale of Google user data.

How long we keep it

  • Gmail-derived context (message counts, thread summaries): retained on a rolling basis, currently about 30 days, then aged out.
  • Calendar-derived scheduling constraints: retained on a rolling basis, currently about 30 days, then aged out.
  • Wearable biometric summaries: retained for 90 days from the date each number was recorded, then automatically expired and purged. Nothing older ever accumulates.
  • Account/coaching data you create directly in NoirNeuro (goals, schedule, coaching activity) is retained for as long as your account is active, or as otherwise described below.

Retention windows are enforced in the product and may be adjusted over time; if we materially change a retention period we will update this page and, where required, ask you to re-consent.

Revoking access and deleting your data

You are always in control of every connected source, and every control below is self-serve from Settings → Connections — no support ticket required:

  • Disconnect Gmail or Google Calendarat any time — this immediately clears the derived context we had imported and stops any further access. You can also revoke NoirNeuro’s access directly from your Google Account permissions page, which immediately invalidates our stored token.
  • Delete all ingested message contextwith a single “Delete all” action on the Connections screen.
  • Revoke wearable consent at any time; by default this also deletes every wearable number already stored, or you may choose to keep your history — either way, nothing new is collected once revoked.
  • Delete your account: contact us at privacy@dardenbehavioralcounseling.com to request full account deletion. We complete account-deletion requests within 30 days.

Storage and security

  • OAuth credentials (Gmail, Google Calendar, Fitbit) are exchanged server-to-server only — the client secret and the resulting token never reach your browser. Refresh tokens are written to a managed secret store (Google Secret Manager) rather than a general-purpose database; our application database stores only an opaque reference to that secret, never the token itself.
  • Data in transit is encrypted (HTTPS/TLS). Your account data, connector-derived context, and wearable summaries are scoped to your account and are not visible to other members; a coach can see a member’s data only where that member has an active coaching relationship.
  • NoirNeuro runs on Google Cloud Platform, so your data benefits from Google Cloud’s independently audited infrastructure: SOC 1, SOC 2, and SOC 3 audited controls; ISO/IEC 27001 (information security), 27017 (cloud-specific security), and 27018 (protection of personal data in the cloud) certification; and HIPAA-eligible infrastructure. All data is encrypted at rest (AES-256) and in transit (TLS), and every tenant’s data is logically isolated from every other tenant. In plain terms: this is the same class of infrastructure banks and hospitals rely on, and NoirNeuro is built on top of it. (This describes the certified infrastructure NoirNeuro runs on — it is not itself an independent certification of the NoirNeuro application.)

Sharing and disclosure

We do not sell your data. We do not use Gmail, Calendar, or wearable data for advertising. We share data only in these limited cases:

  • With service providers who help us operate NoirNeuro (e.g. cloud hosting, authentication), bound by confidentiality and data-processing terms, and only to the extent needed to provide the product.
  • With your coach, if you have one, limited to the coaching context described above.
  • If required by law, legal process, or to protect the rights, safety, or security of NoirNeuro or our members.
  • As part of a merger, acquisition, or asset sale, subject to this policy continuing to apply to your data.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these directly in the product (see “Revoking access and deleting your data” above), or by contacting us at privacy@dardenbehavioralcounseling.com. If you are a California resident, these rights include those described in the California Consumer Privacy Act (CCPA/CPRA); if you are located in the EU/UK, these rights include those described in the General Data Protection Regulation (GDPR). We do not sell or share personal data as defined under CCPA/CPRA.

Children's privacy

NoirNeuro is not directed to children and is not knowingly used by anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

If we make a material change — for example, a new data source, a new purpose, or a retention change — we will update this page and, where required for restricted Google scopes or wearable consent, ask you to re-consent before continuing to collect that data.

Contact us

Questions about this policy or your data — attn. Ahkeem Darden, Privacy Contact: privacy@dardenbehavioralcounseling.com.
Darden Behavioral Counseling and Coaching, 1280 Creek Ridge Xing, Alpharetta, GA 30005.

See also our Disclaimers & About page for what NoirNeuro is (and is not).