← Back to Home

Privacy Policy

Last updated: September 16, 2026

1. Introduction

Cogame ("Cogame," "we," "us," or "our") is a cognitive wellness and engagement platform designed for older adults at adult day care centres and senior wellness facilities.

Cogame is operated by youngand Inc. It is intended solely for general wellness, engagement and educational purposes. It is not intended to detect, diagnose, monitor, manage, treat or prevent any medical condition or disease. Cogame's scores, reports and other outputs are not medical advice.

This Privacy Policy explains how personal information is collected, used, disclosed, stored and protected when Cogame is used.

2. Our Role

Care centres decide which participants use Cogame and what participant information is recorded. The centre is primarily responsible for that information.

Cogame processes participant information on behalf of the centre and according to its instructions. In Singapore, Cogame acts as a data intermediary for this processing.

Cogame is separately responsible for information it collects for its own account administration, security, customer support, website operation and legal compliance purposes, such as staff account details, support communications and technical logs.

3. Information We Collect

Participant information

Authorised centre staff may enter or manage:

  • Name and nickname
  • Year of birth and gender
  • Phone number
  • Emergency contact name and phone number
  • A family member's email address, if progress summaries are requested
  • Physical accessibility information, including dominant hand, arm mobility and use of a mobility aid
  • Notes entered by centre staff
  • A synthesised voice greeting generated from the participant's name
  • Results and notes from external cognitive assessments, where the centre chooses to record them

Cogame does not require a participant's full date of birth.

Training and activity information

Cogame may generate and retain:

  • Game scores, accuracy and completion information
  • Session dates, times and duration
  • Response times
  • Performance metrics and changes over time
  • Movement measurements derived from camera-based games
  • Game difficulty and progress information
  • Monthly progress summaries generated from training records

Centre staff information

We may collect:

  • Name and email address
  • Centre and staff role
  • Authentication credentials in securely protected form
  • Login, security and administrative activity

Technical information

We may automatically collect:

  • Browser and device information
  • Page views and feature usage
  • Application version and game type
  • Error, performance and security logs
  • IP address and related request metadata where generated by our infrastructure providers

We configure our monitoring services to minimise the transmission of participant names, contact details, assessment content and report content.

4. Camera Data

Some Cogame games use Google MediaPipe in the participant's browser to detect body or hand positions.

Camera images and video are processed on the device. Camera frames, photographs, facial images and video recordings are not transmitted to or stored on Cogame's servers.

Cogame does not retain camera images, video, or the frame-by-frame body-position coordinates used while a game is running. Those exist only in the browser and are discarded as each round ends. What is saved alongside a session is a small set of summary movement measures calculated from them — for example how smooth and how steady a participant's movement was, and how far they reached. These summaries are used to operate the game and to record session performance. They are not a clinical assessment and are not used to diagnose or screen for any condition.

Cogame does not create or store facial recognition templates from camera data.

5. Voice Features

Cogame may provide two separate voice features.

Spoken greeting

So that Cogame can welcome a participant by name, we send the participant's given name as text to a speech-synthesis provider (ElevenLabs), which returns a short audio file in a synthetic voice. No recording of the participant is made — the greeting is computer-generated, and the only personal information sent for it is the given name. The audio file is stored privately and is played back through a short-lived link; it is deleted when the participant record is deleted, or earlier at the participant's or centre's request.

Voice input and speech recognition

When a participant chooses to use voice input, a short audio stream is securely transmitted to Deepgram and converted into text. The audio may be processed outside the participant's country, including outside Singapore.

Cogame:

  • Does not require voice input to use the core service
  • Does not attach contact details or the internal participant identifier to the audio. Note that where a participant is asked to say their name, that name is necessarily present in the audio and in the text returned
  • Opts eligible Deepgram requests out of model-improvement use
  • Does not store the transmitted audio — it is discarded once the text is returned
  • Does not intentionally retain the transmitted audio or complete transcript in Cogame application logs

Voice input assists the user interface and is not a biometric identification or security-authentication method. Matching is done on the words that were recognised, compared against the names the centre has entered. Cogame does not analyse or store voiceprints, and does not identify anyone from the characteristics of their voice.

6. How We Use Information

Participant information is used on behalf of the relevant centre to:

  • Provide and operate Cogame sessions
  • Identify the participant selected by centre staff
  • Adapt game difficulty
  • Record game activity and progress
  • Generate reports and progress summaries
  • Provide summaries to centre staff
  • Send a summary or notification to a family member when authorised by the centre and participant
  • Maintain the security, availability and proper operation of the service
  • Respond to support requests from the centre

We do not use identifiable participant information to train machine-learning models, and we do not permit third parties to use participant information to train their general models.

Under our agreement with each centre, we may create aggregated and de-identified data sets from technical and training information — anonymised to a standard where re-identification is not reasonably possible — and use them to operate, improve, validate and train Cogame's own models. These data sets do not identify any centre or individual participant.

7. AI-Generated Progress Summaries

Cogame may use Google Gemini to produce draft progress summaries from training information.

Where this feature is used:

  • We minimise the information sent to the AI provider
  • Participant names, contact information and internal identifiers are not intentionally included in the model prompt
  • Names may be inserted into the report only after the generated text is returned
  • Free-text centre notes and external assessment notes are not intentionally sent unless specifically required and authorised
  • The output is intended as a wellness progress summary, not a diagnosis, medical assessment or prediction
  • The centre remains responsible for reviewing and deciding how the summary is used

We use the paid Gemini API, under terms that prohibit Google from using submitted prompts or responses to train its general models. We do not use the free tier for this feature.

8. How We Disclose Information

We do not sell personal information. We do not use or disclose participant information for third-party advertising.

We may disclose limited information to service providers as necessary to operate Cogame, including:

  • Supabase — database, authentication and file storage
  • Vercel — application hosting, delivery and technical analytics
  • Sentry — error and performance monitoring
  • Deepgram — optional speech recognition
  • Google Gemini or Google Cloud — generation of progress summaries
  • ElevenLabs — generation of spoken prompts, where enabled
  • Resend or another SMTP provider — authentication and notification emails

These providers may process information in the United States or other countries where they or their subprocessors operate.

We may also disclose information:

  • To authorised staff of the relevant centre
  • To a family member designated by the participant or centre
  • When required by applicable law, regulation, court order or valid legal process
  • To protect participants, Cogame, centres or others from fraud, security threats or unlawful activity

Service providers are contractually restricted to processing information for authorised service purposes and are required to apply appropriate security protections.

9. International Data Transfers

Cogame's primary database is hosted by Supabase on AWS infrastructure in the United States.

Some information may also be processed outside the participant's country by Vercel, Sentry, Deepgram, Google, ElevenLabs, Resend and their authorised subprocessors.

Where personal information is transferred outside Singapore, we and the relevant centre take reasonable steps, including contractual safeguards, to ensure that the recipient provides a standard of protection comparable to that required by Singapore's Personal Data Protection Act 2012.

Data does not have to remain in Singapore for Cogame to operate, but overseas processing is limited to what is reasonably necessary to provide and protect the service.

10. Data Security

We apply reasonable administrative, technical and organisational measures designed to protect personal information, including:

  • Encryption in transit
  • Encryption at rest where supported by the infrastructure provider
  • Centre-based access controls
  • Row-Level Security policies designed to prevent one centre from accessing another centre's records
  • Role-based staff permissions
  • Restricted access to production systems
  • Private storage and controlled access for synthesised greeting audio
  • Error-log filtering and data minimisation
  • Security monitoring and incident-response procedures

No internet service can guarantee absolute security. Centres must also protect their staff accounts, devices and login credentials.

11. Data Retention and Deletion

We retain participant information while the relevant centre maintains an active account or for as long as it is reasonably required for the authorised purposes.

Following termination of a centre's account, participant records are deleted or de-identified within 30 days, subject to:

  • Applicable legal requirements
  • Security and fraud-prevention needs
  • Temporary retention in backups until they are removed through the ordinary backup cycle

A centre administrator may request or initiate deletion of an individual participant's records. Cogame will delete or de-identify associated records across the service, subject to the limited exceptions above.

Technical, security and support records may be retained for a limited period appropriate to their purpose.

12. California Privacy Rights

To the extent the California Consumer Privacy Act, as amended ("CCPA"), applies to Cogame, California residents may have the right to:

  • Know what personal information is collected, used and disclosed
  • Request access to specific personal information
  • Request correction of inaccurate personal information
  • Request deletion, subject to applicable exceptions
  • Opt out of the sale or sharing of personal information
  • Limit certain uses and disclosures of sensitive personal information, where applicable
  • Exercise their rights without unlawful discrimination

Cogame does not sell personal information or share it for cross-context behavioural advertising as those terms are defined by the CCPA.

Requests may be submitted through the relevant centre or by emailing contact@cogame.ai. We may need to verify the requester's identity and authority before completing a request.

13. Singapore Privacy Rights

This section applies to participants and centres in Singapore under the Personal Data Protection Act 2012 ("PDPA").

Participants may contact their centre to:

  • Ask what personal information the centre holds
  • Request access to or correction of their information
  • Withdraw consent, subject to reasonable notice and applicable consequences
  • Request deletion where appropriate
  • Raise a question or complaint about the handling of their information

The centre is the primary point of contact because it decides what participant information is collected and how it is used.

If the centre cannot resolve the matter, or if the individual prefers to contact Cogame, the individual may contact our Data Protection Officer.

Data Protection Officer
Email: andrew@cogame.ai
We aim to respond or provide an update within 30 days.

If a participant is not satisfied with the response, they may contact the Personal Data Protection Commission of Singapore at pdpc.gov.sg.

14. Family Members and Emergency Contacts

A participant or centre may provide information about a family member or emergency contact.

Centres are responsible for ensuring that they have an appropriate basis for providing this information. Cogame uses it only for the authorised purpose, such as sending an agreed progress notification or enabling the centre to maintain emergency contact details.

Where possible, progress information should be provided through a secure link rather than included directly in an email attachment or message.

15. Children's Privacy

Cogame is designed for adults aged 60 and older. We do not knowingly collect personal information from children under 13.

If we learn that a child's information has been provided without an appropriate legal basis, we will take reasonable steps to delete it.

16. Changes to This Policy

We may update this Privacy Policy to reflect changes to Cogame, our service providers or applicable law.

We will update the date at the top of this policy and notify centre administrators of material changes where appropriate.

17. Contact Us

For questions, complaints or privacy requests, contact:

youngand Inc.
General enquiries: contact@cogame.ai
Data Protection Officer: andrew@cogame.ai