Organizations
The anonymized identifier model
The anonymized identifier model means the organization issues each eligible person a code, keeps the code to person mapping entirely on its own side, and never sends that mapping to us. We accept bookings against valid codes and report counts against codes in aggregate.
The result is structural rather than procedural. We cannot tell an organization who used a seat, because we were never told.
How does the identifier actually work?
The organization generates a set of codes, one per eligible person, using a scheme that carries no meaning. No initials, no employee number, no station, no team, no start date. A code that encodes anything is a code that can be reversed.
The organization sends us the set of valid codes and nothing else. When someone books, they give a code and the contact details they want us to use, which can be a personal email and a personal phone. Those contact details are ours to hold and are never sent back to the organization.
- Codes are generated by the organization, not by us.
- Codes carry no embedded information about the person.
- We receive the valid set, never the mapping.
- Personal contact details stay with us and are never returned to the funder.
What can the organization see?
Counts, and only counts. Seats funded, seats used, seats remaining, and how usage moved across the term. Where a cohort is small, figures are suppressed rather than published.
Everything below the count line is invisible to the funder. That includes attendance dates, session notes, self report scales, cancellations, and whether a specific code was ever used at all.
| Item | Shared with the organization | Why |
|---|---|---|
| Seats funded and seats used | Yes | It is what the invoice is based on |
| Usage trend across the term | Yes, in aggregate | Program administration |
| Whether a specific code was used | No | It would identify a person on their side |
| Names or contact details | No | We never hold the mapping |
| Session notes or self report scales | No | They belong to the individual |
| Attendance dates tied to anyone | No | A date plus a roster identifies a person |
How is the boundary enforced rather than promised?
Three ways. First, we do not hold the mapping, so the data an organization would need does not exist on our side. Second, the rider states in writing that no individual level data is shared in either direction, and that we will refuse a request for it. Third, reports are generated at the aggregate level with small group suppression applied before anything leaves us.
We also refuse health information travelling the other way. An organization cannot tell us anything about a person's health as part of a referral, because accepting that would put identifiable information about them in our hands via their employer.
What happens if a manager asks whether someone attended?
We say that we do not answer that question for anyone, and we do not check. The answer is the same whether the person attended or not, which is what makes it safe.
We tell organizations this at the proposal stage so nobody is surprised later, and we ask them to say it plainly in their internal communication too. A program only gets used if people believe the boundary is real.
Questions people ask about this
Please read this
Momentous Neurofeedback is a wellness practice. We use an FDA-cleared biofeedback device indicated for relaxation training and muscle reeducation.
We do not provide medical care and we do not assess or identify health conditions. We make no promise about any outcome, and nothing on this site should be read as one.
Sessions are not a substitute for care from a licensed clinician. If you have a health concern, speak with your own provider. In an emergency, call your local emergency number.
See the boundary in writing
Ask for a proposal and the rider language on anonymity comes with it, so your legal and privacy reviewers can read it before anyone commits.