Legal

Privacy Policy

Last updated 2026-07-05 Effective 2026-07-05 Version 1.3.0

1. Introduction and Data Controller

1.1. This Privacy Policy (“Policy”) explains how we collect, use, store, share, and protect your personal data when you use the Hypnore digital hypnotherapy and mental wellness platform.

1.2. Hypnore is operated by Lab 106, MB, a limited liability company registered in the Republic of Lithuania (registration code 306577111, VAT LT100016937410), with its registered address at Išganytojo g. 4-8, LT-01125 Vilnius, Lithuania (“Company”, “we”, “us”, “our”). We are the data controller for the personal data we collect through the Service.

1.3. This Policy applies whenever you visit the Hypnore Website (https://hypnore.com, including its subdomains), use the Hypnore Mobile App on iOS or Android, contact us by email or other means, or interact with the Service in any way. It applies regardless of how you access the Service or where you are located.

1.4. We process personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other applicable data protection laws in the jurisdictions in which the Service operates.

1.5. Capitalized terms used in this Policy that are not defined here have the meanings given to them in the Hypnore Terms of Service.


2. What This Policy Covers

2.1. In this Policy, you will find information about:

  • what personal data we collect and from which platforms (Section 3)
  • how and why we use your data (Section 4)
  • the legal bases for processing your data under the GDPR (Section 5)
  • how long we retain your data (Section 6)
  • who we share your data with (Section 7)
  • international transfers of your data (Section 8)
  • cookies and tracking technologies (Section 9)
  • marketing communications and your choices (Section 10)
  • your rights under the GDPR (Section 11)
  • additional rights for California residents (Section 12)
  • how we handle children’s data (Section 13)
  • how we protect your data (Section 14)
  • health and medical disclaimer (Section 15)
  • third-party links (Section 16)
  • changes to this Policy (Section 17)
  • how to contact us (Section 18)

2.2. This Policy forms part of the Hypnore legal framework, together with the Terms of Service, the Subscription Terms, and the Account Deletion Policy. Where this Policy references those documents, they are incorporated for context. In the event of any conflict between this Policy and the Terms of Service regarding data protection matters, this Policy shall prevail.

2.3. This Policy is drafted in the English language. We may provide translations into other languages for your convenience. In the event of any inconsistency between the English version and any translation, the English version shall prevail.


3. Data We Collect

3.1. We collect and process the following categories of personal data. The specific data collected may vary depending on how you interact with the Service and which platform you use (Website or Mobile App).

3.1. Account Data

When you create an Account, we collect your name, email address, age, and gender. You may also configure language preferences and notification settings. This data is collected on all platforms (Website, iOS, and Android).

3.2. Personalization Data (Website Only)

If you complete an onboarding or personalization questionnaire on the Website, we may collect your responses. These may include information about your personal goals, preferences, lifestyle, sleep patterns, stress levels, and other wellness-related topics.

Some of this information may constitute special category data (health-related data) within the meaning of Article 9 of the GDPR. By voluntarily completing the questionnaire, you consent to the processing of the data you provide for the purposes described in this Policy. Your responses may be stored to maintain and update your personalized experience. Where responses are stored, you will be informed at the time of collection, including the purpose of storage and a reference to this Policy for information on your rights regarding this data.

This data is collected exclusively through the Website. The Hypnore Mobile App (iOS and Android) does not collect personalization questionnaire data or any health-related data. This is consistent with the data practices declared in the Apple App Store and Google Play Store privacy disclosures for the Hypnore app.

Where Personalization Data is used to generate content recommendations, those recommendations may be displayed to you across all platforms, including the Mobile App. However, the data itself is collected only through the Website.

3.3. Usage Data

When you use the Service, we automatically collect data about your interactions, including total Session time, daily usage streaks, Plan progress, and Session completion states (started, finished, or unfinished). This data is collected on all platforms.

Certain Plans and Sessions within the Service may have titles or descriptions that reference wellness themes, such as sleep, stress, relaxation, or habits. Your selection of a particular Plan or Session is recorded as Usage Data — specifically, as a record of which features of the Service you chose to interact with. We do not treat content selection as health data. We do not infer, record, or store any medical diagnosis, health condition, or sensitive personal information based on which Plans or Sessions you choose to use.

3.4. Purchase Data

When you purchase a Subscription or a paid Single, we collect records of the transaction, including your subscription status, the plan or content purchased, billing dates, and transaction history. For Subscriptions purchased through the Mobile App, purchase records are also maintained by Apple or Google, as applicable.

3.5. Device and Technical Data

When you access the Service, we automatically collect technical information about your device and connection, including device type, operating system and version, app version (for Mobile App users), IP address, browser type and version (for Website users), online identifiers stored in cookies (for Website users — see Section 9), and push notification tokens (for Mobile App users). We may also collect standard mobile analytics data related to app performance and usage patterns.

3.6. Communication Data

If you contact us by email, through a contact form, or by any other means, we collect the content of your message, any attachments, and the metadata associated with your communication (such as your email address, the date and time of the message, and our response).

3.7. Payment Data

When you make a purchase through the Website, our Payment Processors (currently Stripe and PayPal) collect your payment details. We do not directly collect, access, or store your full credit card number, bank account details, or other complete payment credentials. We may receive and store limited payment information from our Payment Processors, such as the payment method type, the last four digits of your card number, the card expiry date, and your billing address, for the purposes of managing your Account and maintaining transaction records.

For purchases made through the Mobile App, payment is processed entirely by Apple (for iOS) or Google (for Android). We do not receive or store any payment details for app store purchases.

3.8. Data We Do Not Collect

For clarity, we do not collect:

(a) health data through the Mobile App — the Mobile App does not include health questionnaires, and no health-related data is collected, inferred, or derived from your use of the Mobile App;

(b) biometric data — we do not collect fingerprints, facial recognition data, or other biometric identifiers;

(c) precise geolocation — we do not track your precise geographic location. We may derive your approximate location (country or region) from your IP address for the purposes of language selection, currency display, and compliance with local laws;

(d) contacts, photos, or files — we do not access your device’s contact list, photo library, camera, microphone, or file system.


4. How We Use Your Data

4.1. Providing the Service. We use your Account Data, Usage Data, and Device and Technical Data to create and manage your Account, authenticate your access, deliver Digital Content, track your Plan progress and daily streaks, and provide the core features of the Service across the Website and the Mobile App.

4.2. Personalizing your experience. If you complete a personalization questionnaire on the Website, we may use your Personalization Data to recommend Plans, Sessions, and other Digital Content tailored to your goals and preferences. These personalized recommendations may be displayed to you across all platforms, including the Mobile App. However, the underlying Personalization Data is collected only through the Website. If your questionnaire responses are stored, you will be informed about this at the time of collection, including the purpose of storage and a reference to this Policy for information on how your data is managed.

4.3. Processing payments. We use your Purchase Data and Payment Data to manage your Subscription, process purchases of paid Singles, handle billing, and communicate with our Payment Processors. For web purchases, payments are processed by Stripe and PayPal. For mobile purchases, payments are processed by Apple (iOS) or Google (Android). We also use this data to handle failed payment retries and to maintain records of your transactions.

4.4. Communications. We use your Account Data and Communication Data to respond to your support requests, inquiries, and feedback. We also use your email address to send you transactional communications that are necessary for the operation of the Service, including purchase confirmations, Subscription renewal notices, failed payment notifications, and Account security alerts. These transactional communications are not marketing and cannot be opted out of while you maintain an active Account.

4.5. Marketing. With your consent, we may use your email address and, where relevant, your purchase history, to send you promotional emails and newsletters about new Digital Content, features, Plans, or offers. You can withdraw your consent and opt out of marketing communications at any time (see Section 10).

4.6. Service improvement. We may aggregate and anonymize Usage Data, Device and Technical Data, and other interaction data to analyze how the Service is used, identify patterns and trends, improve existing Digital Content, develop new features, and conduct internal research. Aggregated and anonymized data does not identify you personally and is not subject to the restrictions that apply to personal data.

4.7. Legal compliance and protection. We may process any of your personal data where necessary to comply with a legal obligation to which we are subject, to respond to lawful requests from public authorities, to establish, exercise, or defend legal claims, to prevent fraud, and to enforce our Terms of Service.

4.8. Technical operations. We use Device and Technical Data to maintain the security and stability of the Service, monitor performance, diagnose and fix technical issues, deliver push notifications (where you have enabled them), and ensure compatibility across devices and operating systems.

4.9. Measuring our own advertising. On our checkout funnel we use online advertising identifiers, device and technical data, and transaction data to measure and optimize the performance of our own advertising campaigns through Meta and Google (see Sections 7.12 and 7.13). We do not use this processing to build profiles of you for third parties’ advertising, and it is not deployed on the Mobile App or on our editorial websites.


5.1. Under the GDPR, we are required to have a valid legal basis for each type of personal data processing we carry out. The legal bases we rely on for the processing activities described in Section 4 are as follows:

Providing the Service — performance of our contract with you (Art. 6(1)(b)).

Personalizing your experience — non-health data — performance of our contract with you (Art. 6(1)(b)).

Personalizing your experience — health-related Personalization Data — your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)).

Processing payments — performance of our contract with you (Art. 6(1)(b)).

Transactional communications — performance of our contract with you (Art. 6(1)(b)).

Responding to support requests — performance of our contract with you (Art. 6(1)(b)) or our legitimate interest in providing consistent and high-quality support (Art. 6(1)(f)).

Marketing communications — your consent (Art. 6(1)(a)).

Advertising measurement (Meta Business Tools, checkout funnel only) — your consent (Art. 6(1)(a)); see Section 7.12 for the regional consent posture.

Service improvement and analytics — our legitimate interest in understanding how the Service is used and improving it (Art. 6(1)(f)).

Legal compliance — compliance with a legal obligation to which we are subject (Art. 6(1)(c)) or our legitimate interest in establishing, exercising, or defending legal claims (Art. 6(1)(f)).

Technical operations and security — our legitimate interest in maintaining a secure and functioning Service (Art. 6(1)(f)).

5.2. Health-related data. Where your Personalization Data includes information that may be considered health-related (such as responses about sleep patterns, stress levels, or wellness goals), we process that data on the basis of Article 9(2)(a) of the GDPR. By voluntarily completing the personalization questionnaire on the Website, you consent to the processing of the data you provide for the purposes described in this Policy. Your questionnaire responses may be stored to maintain and update your personalized experience. Where responses are stored, you will be informed at the time of collection, including the purpose of storage and a reference to this Policy for information on your rights regarding this data. This legal basis does not apply to data collected through the Mobile App, which does not collect health-related data.

5.3. Legitimate interest. Where we rely on legitimate interest as a legal basis, we have assessed that our interests in the relevant processing activity (such as improving the Service, ensuring security, or preventing fraud) are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interest at any time (see Section 11).

5.4. Withdrawing consent. Where processing is based on your consent (marketing communications or non-essential cookies), you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. To withdraw consent for marketing, see Section 10. To manage cookie preferences, see Section 9. To request deletion of stored Personalization Data, contact us at support@hypnore.com.


6. Data Retention

6.1. We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The specific retention periods for each category of data are set out below.

6.2. Account Data. Retained for the duration of your Account. If you request deletion of your Account in accordance with the Account Deletion Policy, your Account Data is deleted, subject to any legal obligations that require us to retain certain information (see 6.9).

6.3. Personalization Data. Where your questionnaire responses are stored, they are retained for the duration of your Account or until you request their deletion, whichever comes first. If you request deletion of your Personalization Data, it is removed even if your Account remains active. Any content recommendations previously generated from this data may no longer reflect your preferences after deletion.

6.4. Usage Data. Retained for the duration of your Account. Upon Account deletion, your individual Usage Data is deleted. Anonymized, aggregated usage data (which does not identify you personally) may be retained indefinitely for product improvement and research purposes.

6.5. Purchase Data. Retained for up to 10 years after the end of your Subscription, in order to comply with accounting and tax record-keeping obligations under Lithuanian law. This includes transaction records, billing history, and subscription status records.

6.6. Device and Technical Data. Retained for up to 2 years from the date of collection, or for a shorter period where technically appropriate. Push notification tokens are retained for as long as you have the Mobile App installed and notifications enabled.

6.7. Communication Data. Retained for up to 3 years after the date of the last communication in the relevant thread. Communications related to legal claims, complaints, or disputes may be retained for longer, as described in Section 6.9.

6.7a. Newsletter and Marketing Subscriber Data. If you subscribe to our newsletter or other marketing communications, your subscriber record is retained for up to 730 days (24 months), or until you unsubscribe or ask us to erase it, whichever comes first. After that, we delete it and keep only the minimum necessary to ensure we do not contact you again.

6.8. Payment Data. We do not store full payment credentials. Partial payment information (such as the last four digits of your card number and payment method type) is retained together with your Purchase Data for the periods described in Section 6.5.

6.9. Legal retention. Notwithstanding the retention periods above, we may retain any personal data for longer where necessary to comply with a legal obligation, to establish, exercise, or defend legal claims, or to resolve ongoing disputes. In such cases, the data is retained only for as long as the specific legal purpose requires, and access is restricted to those who need it for that purpose.

6.10. Deletion and anonymization. After the applicable retention period expires, personal data is either permanently deleted or irreversibly anonymized so that it can no longer be used to identify you. Anonymized data is no longer personal data and may be used without restriction.


7. Who We Share Your Data With

7.1. We do not sell your personal data to third parties for monetary consideration. We share your personal data only where necessary for the purposes described in this Policy, and only with the categories of recipients set out below. Our use of the Meta Business Tools for advertising measurement (Section 7.12) involves transmitting limited data to Meta and may constitute “sharing” under California law — see Sections 7.12 and 12.4 for what is transmitted and how to opt out.

7.2. Payment processors. When you make a purchase through the Website, your payment information is shared with our payment processors, currently Stripe and PayPal, to complete the transaction. When you make a purchase through the Mobile App, your payment is processed by Apple (for iOS) or Google (for Android). These processors act as independent data controllers for the payment data they collect. We encourage you to review their respective privacy policies. The full list of processors is set out in Section 7.11.

7.3. Subscription management. For Mobile App purchases (iOS and Android), we use RevenueCat (US) to manage subscription state and receipt validation. RevenueCat receives an internal user identifier and platform-issued purchase metadata (transaction identifiers, subscription status, renewal dates) and does not receive payment credentials. Web purchases are handled separately on the Hypnore Website with Stripe and PayPal as the payment processors (see Section 7.2). See Section 7.11 for the full processor entry.

7.4. Email and communication services. We use SendGrid (Twilio Inc., United States) to deliver our emails and to measure their delivery and engagement (for example, whether a message was delivered, opened, or clicked). Transactional emails (such as purchase confirmations, Subscription renewal notices, and failed payment notifications) are sent on the basis of our contract with you (Art. 6(1)(b)). Marketing emails, including our newsletter, are sent with your consent (Art. 6(1)(a)), which you can withdraw at any time via the unsubscribe link or preference center included in every marketing email. SendGrid processes your email address and the content of the messages sent on our behalf under a Data Processing Agreement. See Section 7.11 for the full processor entry and Section 8 for transfer information.

7.5. Hosting and infrastructure. The Service is hosted on Google Cloud infrastructure (Google LLC), with primary backend storage and server-side processing configured to keep data inside the European Union. See Section 7.11 for processor details and Section 8 for transfer information.

7.6. Analytics and diagnostics. We use Firebase Analytics (Google LLC) to understand how the Service is used in aggregate and Sentry (Sentry Software GmbH) for error and performance monitoring. These tools process Device and Technical Data, Usage Data, anonymized interaction data, and (in the case of Sentry) crash diagnostics, breadcrumbs leading to errors, and limited request metadata. Sentry data is processed and stored inside the European Union. See Section 7.11 for processor details.

7.7. Professional advisors. We may share personal data with our accountants, legal advisors, auditors, and other professional service providers where necessary for the management of our business, compliance with legal obligations, or the establishment, exercise, or defence of legal claims.

7.8. Law enforcement and public authorities. We may disclose personal data to law enforcement agencies, regulatory bodies, courts, or other public authorities where we are required to do so by applicable law, regulation, legal process, or a binding order of a competent authority, or where we reasonably believe disclosure is necessary to protect our rights, your safety, or the safety of others.

7.9. Business transfers. In the event of a merger, acquisition, corporate reorganization, sale of assets, or similar transaction involving all or part of our business, your personal data may be transferred to the acquiring or successor entity as part of that transaction. Where such a transfer occurs, the recipient will be bound by obligations consistent with this Policy.

7.10. All third-party service providers that process personal data on our behalf do so under contractual arrangements that require them to process data only on our instructions, to maintain appropriate security measures, and to comply with applicable data protection law.

7.11. Sub-processor register. The following table enumerates the sub-processors and independent processors involved in the operation of the Service, as required by Article 28 GDPR and Article 30(1)(d) GDPR.

Sub-processorRegionApplies toPurposeData categoriesLawful basisRole
Sentry (Sentry Software GmbH)EUMobile App, WebsiteError and performance monitoring, crash diagnosticsDevice and Technical Data; breadcrumbs leading to errors; user-agent strings; truncated request metadataLegitimate interest — Art 6(1)(f) (see LIA note below)Processor
RevenueCat (RevenueCat, Inc.)United StatesMobile App (iOS, Android)Subscription state management and receipt validationAn internal user identifier; platform-issued transaction identifiers; subscription status, plan, renewal datesContract — Art 6(1)(b)Processor
Firebase Authentication (Google LLC)Globally distributedMobile App, WebsiteUser identity and authenticationEmail address; hashed authentication credentials; sign-in metadataContract — Art 6(1)(b)Processor
Firebase Firestore (Google LLC)EUMobile App, WebsitePrimary backend storage for Account Data, Usage Data, subscription stateAccount Data, Usage Data, subscription stateContract — Art 6(1)(b)Processor
Firebase Cloud Functions (Google LLC)EUMobile App, WebsiteServer-side application logicSame data categories as FirestoreContract — Art 6(1)(b)Processor
Firebase Storage (Google LLC)EUMobile App, WebsiteHosting of audio session assetsPublic assets only — no user-identifying data is stored at this layerContract — Art 6(1)(b)Processor
Firebase Analytics (Google LLC)United StatesMobile App, WebsiteAggregate usage analyticsDevice and Technical Data; anonymized event dataLegitimate interest — Art 6(1)(f); consent where required for non-essential analytics — Art 6(1)(a)Processor
Cloudflare (Cloudflare, Inc.)United StatesWebsiteEdge hosting/CDN; storage of newsletter and marketing contact recordsEmail address; consent and subscription status; online identifiersContract — Art 6(1)(b) (hosting); Consent — Art 6(1)(a) (newsletter/marketing contacts)Processor
SendGrid (Twilio Inc.)United StatesMobile App, WebsiteTransactional and marketing email delivery, including delivery and engagement measurementEmail address; message contentContract — Art 6(1)(b) (transactional); Consent — Art 6(1)(a) (marketing)Processor
Apple App Store (Apple, Inc.)United StatesMobile App (iOS)iOS in-app purchase, receipt validation, app distributionApple ID-linked purchase dataContract — Art 6(1)(b) (independent controller for purchase data Apple collects)Independent controller
Google Play (Google LLC)United StatesMobile App (Android)Android in-app purchase, receipt validation, app distributionGoogle account-linked purchase dataContract — Art 6(1)(b) (independent controller for purchase data Google collects)Independent controller
Stripe (Stripe, Inc. and Stripe Payments Europe Ltd)EU and United StatesWebsite onlyWeb payment processingPayment card details, billing addressContract — Art 6(1)(b) (independent controller for payment data Stripe collects)Independent controller
PayPal (PayPal, Inc. and PayPal (Europe) S.à r.l. et Cie, S.C.A.)EU and United StatesWebsite onlyWeb payment processingPayPal account dataContract — Art 6(1)(b) (independent controller for payment data PayPal collects)Independent controller
Meta (Meta Platforms Ireland Ltd; Meta Platforms, Inc.)EU (Ireland) and United StatesWebsite — checkout funnel onlyAdvertising measurement, campaign optimization, and audience building (see Section 7.12)Online advertising identifiers; IP address; browser user-agent; a pseudonymous website identifier derived from our first-party session cookie (SHA-256 hashed); country code (SHA-256 hashed); funnel interaction events, with order or plan value and currency; email address (SHA-256 hashed — sign-up and purchase events only). Questionnaire answers and health data are never transmitted (see 7.12(b)).Consent — Art 6(1)(a) where consent is required; see Section 7.12 for the regional consent postureJoint controller (collection and transmission); independent controller for Meta’s subsequent processing
Google (Google Ireland Limited; Google LLC)EU (Ireland) and United StatesWebsite — checkout funnel onlyMeasurement and optimization of our own Google Ads advertising (see Section 7.13)Transaction identifier; purchase value and currency; online advertising identifiers; email address (SHA-256 hashed); consent statusConsent — Art 6(1)(a)Independent controller

Sub-processor notes. Sub-processors marked “Processor” handle personal data only on our instructions under a Data Processing Agreement; entities marked “Independent controller” determine some or all purposes themselves and operate under their own privacy notices. Stripe and PayPal apply only to Web purchases; Mobile App purchases are processed directly by Apple App Store or Google Play. Sentry processing relies on legitimate interest (Art 6(1)(f)) for the sole purpose of detecting and resolving product defects affecting users; you may object to it at any time under Art 21 GDPR (see Section 11.7). For the Meta Business Tools row, we and Meta Platforms Ireland Ltd act as joint controllers under Art 26 GDPR for the collection and transmission of the listed data (per the Fashion ID line of case law and Meta’s Controller Addendum); Meta’s subsequent processing is governed by its own privacy policy. When we add, remove, or change a sub-processor, this register and the policy version are updated.

7.12. Advertising measurement and audiences (Meta Business Tools). On the Hypnore checkout funnel we use Meta Business Tools to measure and optimize our own advertising campaigns and to build audiences so we can show our own ads to people who engaged with the funnel but did not subscribe. Where applicable law requires prior consent, this processing takes place only after you grant advertising consent (see (c)).

(a) What is transmitted. When active, these tools transmit to Meta: online advertising identifiers stored in first-party cookies; a pseudonymous identifier derived from our own first-party session cookie (transmitted only in SHA-256-hashed form); your IP address and browser user-agent; your country (transmitted only as a SHA-256 hash); and interaction events reflecting your progress through the funnel and any purchase, together with order or plan value and currency. These events carry only structural, non-content labels — never the questions, your answers, or the health topic a funnel addresses. For sign-up and purchase events, your email address is additionally transmitted in SHA-256-hashed form only. Recurring subscription renewal charges are not transmitted to Meta.

(b) What is never transmitted. We never transmit your quiz or questionnaire answers, your wellness- or health-related responses, the specific wellness topic that a funnel addresses, session content, or account credentials to Meta. The interaction events in (a) are content-blind by design: they carry only structural, non-health labels (a step-type and a count, or a plan identifier and a price), never the content of an answer or the health condition a funnel is about. We apply technical safeguards so that only permitted, content-blind fields are transmitted and any value that could reveal a health topic is removed before transmission.

(c) Consent posture. Where applicable law requires prior consent (for example, in the EEA and the United Kingdom), neither tool processes your data until you grant advertising consent via the cookie banner. In jurisdictions that follow an opt-out model, the tools may be active by default and you can opt out at any time via the cookie preferences on the funnel. If advertising consent is not given (or is withdrawn or opted out), no interaction events are sent to Meta, and any purchase event that is transmitted carries no data that identifies you and is flagged with Meta’s Limited Data Use option, which restricts Meta’s processing of the event. In this state the transmission carries no data that identifies you.

(d) Roles. For the collection and transmission of the data described in (a), we and Meta Platforms Ireland Ltd act as joint controllers; Meta’s subsequent processing as an independent controller is described in Meta’s privacy policy at https://www.facebook.com/privacy/policy/. This processing applies to the checkout funnel only — it is not deployed on the Hypnore Mobile App or on our editorial websites.

7.13. Advertising measurement (Google Ads). Where you have given the required advertising consent, we may share with Google (Google Ireland Limited / Google LLC) limited conversion data about purchases on the checkout funnel — online advertising identifiers, a purchase reference and value, and your email address in SHA-256-hashed form only, together with your consent status — so that we can measure and optimize our own Google Ads advertising. You can withdraw consent at any time via the cookie preferences on the funnel; Section 7.12(c) applies equally to this processing.


8. International Data Transfers

8.1. The Company is established in the Republic of Lithuania, within the European Economic Area (EEA). However, some of the third-party service providers we work with, including our payment processors, may be located outside the EEA, including in the United States. This means that your personal data may be transferred to, stored in, or processed in countries that may not provide the same level of data protection as the EEA.

8.2. Where your data is processed by third-party service providers outside the EEA, we rely on the data protection safeguards that those providers have implemented as part of their own compliance obligations, which may include EU Standard Contractual Clauses (SCCs), adherence to adequacy decisions by the European Commission, or other legally recognized transfer mechanisms under the GDPR.

8.3. Transfer mechanisms. Where personal data is transferred outside the EEA, we rely — per recipient — on either the recipient’s self-certification under the EU-U.S. Data Privacy Framework (an adequacy decision under Art. 45 GDPR), or the EU Standard Contractual Clauses (SCCs, Art. 46 GDPR), together with supplementary measures where appropriate. Specific destinations per sub-processor are listed in the Region column of the register at Section 7.11.

8.4. Your right to a copy of safeguards. You can request a copy of the relevant SCCs or other transfer-mechanism documentation by contacting us using the details in Section 18.


9. Cookies and Tracking Technologies

9.1. The Hypnore Website uses cookies and similar tracking technologies to provide essential functionality, remember your preferences, understand how the Website is used, and, where applicable, support marketing activities. This Section applies to the Website only. The Mobile App does not use browser cookies, but may use standard mobile analytics tools and push notification tokens as described in Section 3.5.

9.2. A cookie is a small text file that is placed on your device by a web server when you visit a website. Cookies allow the website to recognize your device and store certain information about your preferences or past actions.

9.3. We use the following categories of cookies:

(a) Strictly necessary cookies. These cookies are essential for the Website to function properly. They enable core features such as user authentication, session management, shopping cart functionality, and security. These cookies cannot be disabled without impairing the basic operation of the Website. They do not require your consent.

(b) Functional cookies. These cookies allow the Website to remember choices you make, such as your language preference or region, and provide enhanced, more personalized features. These cookies are set based on your consent.

(c) Analytics and statistics cookies. These cookies collect information about how you use the Website, such as which pages you visit and whether you encounter errors. This data is used in aggregate to help us understand usage patterns and improve the Website. These cookies are set based on your consent.

(d) Marketing and targeting cookies. Where applicable, these cookies may be used to deliver advertisements that are relevant to you, or to track the effectiveness of marketing campaigns. On the checkout funnel this category currently comprises first-party marketing cookies used with the Meta Business Tools (see Section 7.12), with a lifetime of up to 24 months. Where applicable law requires prior consent (for example, in the EEA and the United Kingdom), these cookies are set only after you grant advertising consent through the cookie banner; in jurisdictions that follow an opt-out model they may be set by default, and you can withdraw them at any time through the cookie preferences on the funnel or by deleting them in your browser.

9.4. Where non-essential cookies (functional, analytics, or marketing categories) are deployed on the Website, you can control them through a cookie preferences mechanism. In jurisdictions whose law requires prior consent (for example, the EEA and the United Kingdom), non-essential cookies are not set until you accept them via the cookie banner. In jurisdictions that follow an opt-out model, some non-essential cookies (including the marketing cookies described in Section 9.3(d)) may be set by default, and you can decline or withdraw them at any time through the same preferences mechanism. You will always be able to change your preferences after your initial choice.

9.5. You can also manage cookies through your browser settings. Most browsers allow you to view, block, or delete cookies. Please note that disabling certain cookies may affect the functionality of the Website. Instructions for managing cookies in common browsers:


10. Marketing Communications

10.1. We may send you marketing communications by email, including information about new Digital Content, Plans, features, promotions, and other updates related to the Service. We will only send you marketing communications where you have given your consent to receive them.

10.2. You can withdraw your consent and opt out of marketing communications at any time by clicking the unsubscribe link included in every marketing email, or by contacting us at support@hypnore.com. We will process your opt-out request without undue delay.

10.3. Opting out of marketing communications does not affect transactional or Service-related communications that are necessary for the operation of your Account and Subscription. These include purchase confirmations, Subscription renewal notices, failed payment notifications, and Account security alerts. You will continue to receive these communications as long as you maintain an active Account.

10.4. We do not sell your personal data to third parties for their own marketing purposes, and we do not share your personal data with third parties for direct marketing by those third parties. Separately from direct marketing, we share limited technical and transactional data with Meta for the purpose of measuring and optimizing our own advertising campaigns, as described in Sections 7.12 and 9.3(d); where consent is required, this happens only after you grant advertising consent, and you can withdraw at any time.


11. Your Rights Under the GDPR

11.1. If you are located in the European Union or the European Economic Area, the GDPR provides you with certain rights regarding your personal data. These rights are subject to the conditions, limitations, and exceptions set out in the GDPR.

11.2. Right of access. You have the right to obtain confirmation as to whether we process personal data concerning you and, where that is the case, to request access to that data together with information about how it is processed.

11.3. Right to rectification. You have the right to request correction of personal data that is inaccurate, and to have incomplete personal data completed.

11.4. Right to erasure. You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, or where you withdraw consent on which the processing is based. This right is subject to legal exceptions — for example, we may retain certain data where required by law or for the establishment, exercise, or defence of legal claims. For information on how to delete your Account and the data associated with it, please refer to the Account Deletion Policy.

11.5. Right to restriction of processing. You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where you have objected to processing pending verification of our legitimate grounds.

11.6. Right to data portability. Where our processing of your personal data is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

11.7. Right to object. You have the right to object to the processing of your personal data where we rely on legitimate interest as a legal basis. Upon receiving your objection, we will cease processing your data for the relevant purpose unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where the processing is necessary for the establishment, exercise, or defence of legal claims. You also have the right to object to processing of your personal data for direct marketing purposes at any time (see Section 10).

11.8. Right to withdraw consent. Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

11.9. Automated decision-making. We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

11.10. How to exercise your rights. To exercise any of the rights described in this Section, please contact us by email at support@hypnore.com. We will respond to your request within one (1) month of receiving it. This period may be extended by up to two (2) additional months where necessary, taking into account the complexity and number of requests. If we extend the response period, we will inform you of the extension and the reasons for it within the initial one-month period. We may ask you to verify your identity before processing your request.

11.11. Right to lodge a complaint. If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. You may do so in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement.


12. California Privacy Rights

12.1. If you are a resident of California, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) provides you with certain additional rights regarding your personal information. This Section supplements the rest of this Policy and applies only to California residents.

12.2. Right to know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected that information, the business or commercial purposes for which we collected it, and the categories of third parties with whom we shared it. The relevant information is set out in Sections 3, 4, and 7 of this Policy.

12.3. Right to delete. You have the right to request that we delete the personal information we have collected from you, subject to certain exceptions permitted by the CCPA/CPRA (such as where retention is necessary to complete a transaction, comply with a legal obligation, or detect security incidents).

12.4. Right to opt-out of sale or sharing. We do not sell your personal information for monetary consideration. However, our use of Meta Business Tools on the checkout funnel (Section 7.12) and our Google Ads conversion measurement (Section 7.13) — transmitting online identifiers, device information, and hashed purchase data to Meta or Google for advertising measurement — may constitute “sharing” of personal information for cross-context behavioral advertising as defined by the CPRA. You have the right to opt out of this sharing at any time: use the cookie/advertising preferences on the checkout funnel (which stops the sharing with Meta and Google described in Sections 7.12 and 7.13), or contact us at support@hypnore.com. Consistent with the CCPA/CPRA, we do not sell or share the personal information of consumers under 16 years of age without affirmative opt-in consent, and the Service is not directed to anyone under 18 (see Section 13).

12.5. Right to non-discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you the Service, charge you different prices, provide a different quality of Service, or suggest that you will receive any of these as a consequence of exercising your rights.

12.6. How to submit requests. To exercise your rights under the CCPA/CPRA, please contact us by email at support@hypnore.com. We will verify your identity before processing your request and will respond within the timeframes required by applicable law.


13. Children’s Privacy

13.1. The Service is intended for individuals who are at least 18 years of age. Users between the ages of 13 and 17 may use the Service only with the consent of a parent or legal guardian, as described in the Terms of Service (Section 3).

13.2. We do not knowingly collect personal data from children under the age of 13. The Service is not directed at children under 13, and we do not intentionally gather information from any person we know to be under that age.

13.3. If we become aware that we have collected personal data from a child under 13 without verified parental consent, we will take prompt steps to delete that data from our systems. If you believe that a child under 13 has provided us with personal data, please contact us at support@hypnore.com so that we can investigate and take appropriate action.

13.4. For users in the United States, our practices regarding children’s data are consistent with the requirements of the Children’s Online Privacy Protection Act (COPPA).


14. Data Security

14.1. We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, loss, or destruction.

14.2. These measures include, among others, encryption of data in transit using SSL/TLS, restricted access to personal data on a need-to-know basis, secure hosting environments, and confidentiality obligations for personnel with access to personal data.

14.3. Payment data is handled by our Payment Processors (Stripe and PayPal for web purchases; Apple and Google for mobile purchases), which maintain their own security standards, including compliance with the Payment Card Industry Data Security Standard (PCI DSS). We do not process or store full payment credentials on our own systems.

14.4. While we implement measures designed to protect your personal data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, and any transmission of personal data to us is at your own risk.

14.5. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly in accordance with Article 34 of the GDPR, unless one of the exceptions set out in that Article applies.


15. Health and Medical Disclaimer

15.1. Hypnore is not a medical device. Hypnore is not intended to diagnose, treat, cure, or prevent any disease. Hypnore is not a substitute for professional medical, psychological, or psychiatric care.

15.2. Where Personalization Data is collected through the Website (see Section 3.2), it may include information related to your wellness goals, sleep patterns, stress levels, or similar topics. This data is processed solely to personalize the Digital Content recommendations within the Service. It is never used for medical diagnosis, treatment, clinical assessment, or any other healthcare purpose. This data is not collected through the Mobile App.

15.3. The Hypnore Mobile App collects only standard personal data (name, email, age, gender), Usage Data, Purchase Data, Device and Technical Data, and Payment Data. No health-related or sensitive personal data is collected through the Mobile App. This is consistent with the data practices declared in the Apple App Store and Google Play Store privacy disclosures for the Hypnore app.

15.4. Usage Data — including Session completion states, daily streaks, and Plan progress — is not health data on any platform and is not processed as special category data under the GDPR.

15.5. Certain Plans and Sessions within the Service may have titles or descriptions that reference wellness themes, such as sleep, stress, relaxation, or habits. Your selection of a particular Plan or Session is recorded as Usage Data — specifically, as a record of which features of the Service you chose to interact with. We do not treat content selection as health data. We do not infer, record, or store any medical diagnosis, health condition, or sensitive personal information based on which Plans or Sessions you choose to use.

15.6. For additional information about the nature and limitations of the Service, please refer to Section 6 (Health and Medical Disclaimer) of the Terms of Service.


16.1. The Service and communications from us may contain links to websites, applications, or services operated by third parties that are not owned or controlled by the Company. This Policy does not apply to the practices of those third parties.

16.2. We are not responsible for the privacy practices, content, or security of any third-party website or service. We recommend that you review the privacy policy of any third-party website before providing personal data to it or engaging in transactions through it.


17. Changes to This Policy

17.1. We may update this Policy from time to time to reflect changes to our data practices, the Service, applicable law, or for other reasons we consider appropriate. When we make changes, we will publish the revised Policy on the Website and within the Mobile App, and update the effective date shown at the top of this Policy.

17.2. If we make material changes that significantly affect how we collect, use, or share your personal data, we will notify you by publishing a notice on the Website or by sending a notification to the email address associated with your Account.

17.3. Your continued use of the Service after the updated Policy has been published constitutes your acceptance of the changes. If you do not agree with the revised Policy, you should stop using the Service and, if applicable, cancel your Subscription in accordance with Section 11 of the Terms of Service.


18. Contact Information

18.1. This Policy is managed by:

Lab 106, MB Registration code: 306577111 VAT: LT100016937410 Išganytojo g. 4-8, LT-01125 Vilnius Republic of Lithuania

Email: support@hypnore.com

Get the Hypnore app

Your sessions live in the app. Download it on iOS or Android and begin whenever you're ready.

Download on theApp StoreGet it onGoogle Play