Privacy

Private by design, because it has to be

We built the Immersion SDK so the sensitive parts never leave your app, and what comes out is a behavioral score, not a health record.

Everything is processed inside the Immersion SDK

The Immersion SDK is self-contained. It doesn’t send user data to the cloud for processing. All scoring happens in your app, on the device or machine running it.

One registration call, no PII

The Immersion SDK connects to the internet once at launch to confirm your app is activated. That call carries your company ID, key, and app identifier. No personal information is transmitted or shared.

No personal information is stored or sent

The Immersion SDK doesn’t save, store, write, send, or transmit user personal information. On Professional you may label data with an identity string of your choosing; we ask that you never use anything that could be considered PII.

No health data is retained

Heart rate is the input, but it’s used in memory for the calculation and discarded as soon as processing completes. The Immersion SDK doesn’t save, store, or transmit health data of any kind.

Not a nervous-system measurement, not emotion recognition

Your app sends cardiac data to the Immersion SDK and we return two behavioral predictors from it. It doesn’t identify or infer named emotions. We think most emotion-recognition science is suspect, and we don’t do it. A prediction engine, not an emotion-recognition system.

Not medical advice

Immersion Neuroscience is a technology provider. The Immersion SDK doesn’t render medical care, diagnose, or give medical advice, and it’s not a crisis service. Your users should always consult a qualified professional for health questions.

What we receive, and what we do with it

DataLeaves the device?Why
Heart-rate samplesNoSupplied by your app from its own source. Used in memory to compute scores, then discarded. The Immersion SDK requests no permission to obtain them.
Value and Safety scoresNoReturned to your app. On Professional, stored locally on the device if you choose.
Company ID, key, app identifierOnce, at activationConfirms your app is licensed. Cached afterward so the Immersion SDK works offline.
Anonymous active-device countAggregate onlyPowers the usage chart in your console and monthly billing. Contains no user identity.
Names, emails, locations, contentNever collectedThe Immersion SDK has no API for them.

Your commitment to your users

We expect, and our SDK Agreement requires, that you maintain a clear and upfront privacy policy with your customers when using the Immersion SDK.

  • Keep a clear, upfront privacy and data policy with your own users. Our SDK Agreement requires it.
  • Comply with the data-protection rules that apply to your app and your users, including GDPR, CCPA, and, if your app reads heart rate through them, Apple App Review Guideline 5.1.3 and the Google Play health-permissions policy. The Immersion SDK itself requires neither.
  • Obtain whatever consent your jurisdiction and platform require before reading heart rate from your chosen sensor.
  • On Professional, choose identity labels that aren’t personally identifying.

Regulatory concerns

Five things you can say about the Immersion SDK, each with why it holds and where its limit is. Share these with the person on your team who has to sign off.

ClaimWhy it holdsLimit
Not an emotion-recognition systemThe Immersion SDK doesn’t identify or infer emotions or intentions. It computes Value and Psychological Safety, two predictors of memory and behavior. (EU AI Act Art. 3(39) defines an emotion-recognition system by that inference.)Classification for your specific deployment is a question for your counsel; we’ll support that review.
No biometric identifierNo face, no voice, no fingerprint, no template that can identify a person. Heart rate can’t identify anyone the way a face or voiceprint can, so BIPA-style biometric consent doesn’t apply.This covers identity-based laws such as BIPA and CUBI. The EU AI Act defines biometric data more broadly, including physiological signals like heart rate. Under that law the relevant point is the row above: the Immersion SDK isn’t an emotion-recognition system.
No health data stored or transmittedHeart rate is used in memory and discarded. Nothing leaves the device for processing. One activation call, no PII.On Professional, scores (not heart rate) can persist locally on the device if you enable it.
Not a nervous-system measurementWe measure cardiac rhythm from whatever sensor your app reads and infer a score. Several state neural-data laws exclude data inferred from non-neural information.Definitions vary by state and are changing. Confirm for the states you operate in.
Adds no permission of its ownThe Immersion SDK requires no HealthKit or Health Connect permission and no entitlement. Your app supplies the heart-rate samples from its own source (a BLE sensor needs no health permission at all); the Immersion SDK returns scores. No biometric consent screen, no emotion-recognition disclosure.If your app reads heart rate through HealthKit or Health Connect, that permission is your app's requirement. Your app still needs its own privacy policy and lawful basis, as the Immersion SDK Agreement requires.

For orientation, not legal advice. See how the alternatives compare.

The formal documents

Everything above describes how the Immersion SDK behaves inside your app. The terms for using the Immersion SDK are set by the Immersion SDK Agreement, which is presented when you create a project in the console.

The two documents below cover something different: this website and the developer console, meaning your account, billing, and the data you give us as a customer. They don’t govern the Immersion SDK or your app's users.