Privacy Policy

ERAS Technologies Ltd · Last updated 21 August 2026

ERAS ("we", "us", "our") provides a mobile application for meditation, stress-response monitoring, and longevity-focused wellness (the "App"), including EEG measurement via the UMind Mirror device and heart-rate/recovery data via optional third-party integrations. This policy explains what we collect, why, and the choices you have.

We take the sensitivity of this data seriously: EEG and heart-rate data are special category health data under GDPR and equivalent frameworks. We only process it with your explicit consent, given during onboarding, and you can withdraw that consent and request deletion of your data at any time.

1. Who this applies to

This policy applies to anyone who creates an ERAS account, in any country. We currently operate our infrastructure primarily out of Hong Kong (AWS ap-east-1), and are launching first in Hong Kong and the United Arab Emirates — so this policy is written with Hong Kong's Personal Data (Privacy) Ordinance (PDPO), UAE data-protection law, and the EU/UK GDPR all in mind, since some users may be covered by more than one.

The App is intended for users aged 16 and over. We do not knowingly collect data from anyone younger, and our sign-up flow requires a birth date consistent with this minimum.

2. What we collect

Account & identity data

DataWhy
Email address or phone numberAccount creation and sign-in (via AWS Cognito), passwordless one-time-code verification
Name, date of birth, gender, country of origin/residencePersonalizing your experience and computing age-adjusted longevity scores
Spirituality/faith preference (optional)Tailoring the content style of guided sessions — never shared, used only to select which content set you see
Emergency contact name and phone number (optional)Only used if you choose to reach that contact directly from within the App; never used for any other purpose

Biometric & health data

DataSourceWhy
EEG session dataUMind Mirror device (Bluetooth)Real-time stress/hijack detection and guided-session feedback
Heart rate, HRV, recovery, sleep, strain, SpO2, skin temperature, workout dataWHOOP and/or Amazfit/Zepp, if you connect themEnriching your longevity score and session context
Session interaction data (which guided sessions you use, how you respond)In-appPersonalizing which content is suggested to you
Voice journaling entriesOptional, in-appPersonal reflection — recorded and transcribed entirely on your device; audio and transcript never leave your phone unless you explicitly export or share them yourself
Third-party integrations (WHOOP, Amazfit/Zepp): if you connect one of these accounts, we pull the specific data types listed above via that provider's official API, using a token you can revoke at any time by disconnecting the integration in the App. We do not access anything beyond what's listed here.

Device & usage data

3. Anonymized research data pool

Separately from the account-linked data above, ERAS maintains an anonymized biometric research pool used to improve our on-device and cloud models. Before storage, your user ID and device ID are passed through a one-way cryptographic transform (PBKDF2, with a secret salt) so this pool cannot be linked back to your account. Only your birth year is retained for this purpose — never your full date of birth.

This anonymized collection happens as part of normal use of the App and is separate from the setting below, which governs a different, later question.

4. Sharing with third-party researchers — your choice

From the Data tab in the App, you can choose to opt in to a monthly research-sharing campaign. This is off by default — nothing is shared with any third party until you explicitly turn it on, and turning it on locks in for the remainder of that month's campaign by design. As of this policy's date, no third-party sharing pipeline is active yet; this setting records your preference for when one exists, and we will not activate any sharing without this consent already being on.

This setting does not affect the anonymized research pool described in Section 3, which is used internally regardless of this preference.

5. Data retention

We retain your account and health data for as long as your account remains active. We keep this data because longitudinal history — seeing how your recovery, stress response, and healthspan trend over months and years — is a core part of what the App provides, not incidental storage.

If you request deletion of your account or your data (Section 7), we erase it within 30 days of your request.

We are developing an automated retention policy for accounts that go inactive for an extended period; until that is in place, an inactive account's data is retained the same as an active one, until you request its deletion. We will update this section with a specific inactivity period once that automation ships.

6. Where your data is stored

Our infrastructure runs on Amazon Web Services, in the Hong Kong region (ap-east-1). This is the only region we operate in today — there is no separate UAE- or EU-local hosting.

If you are located in the EU/UK, this means your data is transferred outside your home region. This transfer currently relies on your informed consent to this Privacy Policy, given the absence of an adequacy decision for this transfer; we have not yet formalized AWS's standard contractual clauses or another recognized appropriate-safeguards mechanism for this specific transfer, and are actively working to put one in place.

If you are located in the UAE, your data is likewise processed in Hong Kong rather than in-country. We believe this is consistent with UAE data-protection law for the categories of data the App processes, but because UAE law applies some stricter rules to sensitive health data specifically, we are seeking local legal confirmation of this as an active part of our UAE launch and will update this section if that changes our approach.

7. Your rights

Depending on where you live, you may have the right to:

We aim to respond to any data request within 30 days.

8. Security

We use industry-standard measures including encrypted connections (TLS) for all data in transit, encryption at rest for stored data, and one-way anonymization for the research data pool described in Section 3. No system is completely secure, and we encourage you to use a strong, unique credential for your account.

9. Changes to this policy

We will update the "last updated" date above whenever this policy changes, and notify you in-app for material changes affecting how your health data is used.

10. Contact us

ERAS Technologies Ltd

Privacy & data requests: support@eras.life