Consumer neurotech ships at commercial scale in 2026. A May 2026 advisory from Davis Wright Tremaine points to NextSense’s Smartbuds, the first wireless earbuds with EEG sensors, and to Muse headbands that use real-time brainwave feedback, and it notes that both devices intervene in your neural state instead of only watching it. The legal frame around them is thin. At the federal level, neural data falls under Section 5 of the FTC Act, which bans unfair or deceptive practices but does not require a company to post a privacy policy or to let you access, correct, or delete anything.
This article covers consumer headsets, earbuds, and headphones. Clinical BCIs live in a different world, where HIPAA covers data inside trials and hospital workflows, and defense builds follow their own rules. Your wellness headband has neither. So here are five questions to send the maker before you pay. I’m an editor, not a lawyer, and state laws differ, so treat this as a buyer’s checklist, not legal advice.
1. Where does the signal get processed, and what leaves the device?
A raw EEG stream and a single focus score are as different as a recording and a receipt 🎧. A raw stream lets anyone holding the file run tomorrow’s models on today’s brain. A score does not. Start by asking which one your headset uploads.
Neurable’s MW75 Neuro headphones make a useful case study. Per Neurable’s FAQ, focus metrics sit in the device’s memory chip until a session ends, then travel over Bluetooth to the app and to Neurable’s servers. The company says the data is encrypted, de-identified, and never sold. TechRadar reports that Neurable later clarified that its newer LT model uses cloud processing alongside on-device processing for some metrics, without saying exactly which data goes off-device 🔍. Neurable’s own ethics post says on-device processing reduces the raw neural data that leaves a device, and that its defense use cases run entirely at the edge. One company, two lanes, two architectures 📡. The consumer version is the one that talks to servers.
Raw or derived: does the app upload raw waveforms, band-power numbers, or only a score?
Per-feature routing: which features run on the device and which in the cloud, and does a firmware update change that?
Offline mode: does the device still work if you refuse the upload?
Retention: how long each data type stays on company servers.
2. What can the data reveal, and can it be tied back to me?
Non-invasive EEG does not read your inner monologue, and Neurable says so itself. It does support estimates of states like focus and stress, and those estimates are the product 🧠. Identity is a separate and less comfortable question. A March 2026 study in Information from Koya University recorded 54 validated participants on a 14-channel Emotiv EPOC X at 128 Hz and identified them from short EEG windows with 95.91% accuracy in a neutral state, 94.31% under positive stimuli, and 92.99% under negative ones. The caveats matter: a closed set of 54 people, sessions minutes apart on the same day, and no test of long-term stability. It is a research result, not a demonstrated attack. It still suggests a brainwave carries a signature, so “de-identified” deserves a follow-up question 🪪.
The law adds a twist. Per Davis Wright Tremaine, Colorado’s law reaches neural data only when a company uses or intends to use it to identify a specific person. Definitions differ elsewhere, and a Stanford Law blog post argues that even Chile’s neurorights leave inferred mental data in a gray zone ⚖️. Open your headset’s app and check what it shows you. Raw traces, or only scores? That answer previews what the company keeps.
Definition: does the policy define neural data, and does the definition cover inferred states such as focus or stress scores?
De-identified means what: name removed, or unlinkable to a device or account ID?
Linking: are derived scores stored beside your email, device ID, or location?
Partner rules: does the company bar partners by contract from trying to re-identify?
3. Who else gets the data, and what happens if the company is sold?
The best audit of this question is a bit old. The Neurorights Foundation reviewed the policies of 30 consumer neurotech companies that sell online, and 29 had access to neural data with no meaningful limits. CBC reports that all but one could transfer the data to third parties and fewer than half let users request deletion. STAT reports that fewer than half encrypt data and de-identify users 🤝. Davis Wright Tremaine adds that 73% of the companies posted a privacy policy, yet 60% said nothing specific about neural data. I found no repeat of that audit, so policies may have improved. Verify yours anyway.
Training data is the newer worry 🤖. Per Bass, Berry & Sims, Connecticut’s rules require a privacy notice that says whether data will train large language models, on top of opt-in consent and no dark patterns. Ownership change is the other risk 🏢. Our piece on brain data when a startup shuts down advises watching a company’s funding signals the way you would watch any vendor you depend on, because a startup on its last runway may sell data to whoever is still buying.
Third parties: named categories, and whether “sharing” includes affiliates, analytics vendors, and research partners.
Model training: whether your recordings train the company’s AI or a partner’s, and whether you can opt out.
Sale clause: what the policy says happens to neural data in a merger, acquisition, or bankruptcy.
Consent style: a clear opt-in, or a checkbox buried in terms of service.
4. Can I see it, export it, and delete it for real?
The clearest deletion precedent comes from Chile. The Debrief reports that former senator Guido Girardi bought an Emotiv Insight in 2022, found his brain data locked behind a Pro membership, and sued. On August 9, 2023, the Chilean Supreme Court unanimously ordered Emotiv to delete his data 🗑️. The ruling rests on a 2021 constitutional amendment, and the Stanford post above notes that it is clearer about stored data than about inferred data.
The US has no such rule 🌎. Colorado and Connecticut require opt-in consent for sensitive data, while California offers an opt-out, per Davis Wright Tremaine. Inside BCI says Montana’s SB 163 requires police to get a warrant before accessing neural data, and that the federal MIND Act, which would only order an FTC study, has not advanced beyond committee. Vermont’s H. 814 recognizes neural rights, but the Davis Wright Tremaine advisory says it lacks an enforcement mechanism and a process for exercising them 📜. State bills arrive faster than anyone can read them. If you’re following this area of neurotech professionally, NeurotechMag Pro gives you the structured intelligence feed to go deeper than any single article can. Our own brain data ownership explainer covers why the definitions do not line up.
Test the promise before you buy. Email the company a deletion question and time the reply.
Full deletion: neural data, derived scores, and backups, not only the account.
Timeline: written confirmation and a deadline.
Raw export: your own recordings without a paywall tier.
Governing law: which state or country’s rules the company says apply to you.
5. Who can use it against me?
Consumer neurotech companies typically disclaim medical accuracy and restrict use to personal, non-commercial purposes. Davis Wright Tremaine found no major provider that explicitly bans the use of device outputs in employment decisions, insurance underwriting, or clinical assessments. A “not a diagnosis” disclaimer does not stop an employer from asking, an insurer from underwriting, or a court from issuing a subpoena in a custody case 🏢. HIPAA does not apply to a direct-to-consumer device maker with no covered entity in the data chain, which is the gap between your headband and a clinical trial 🩺. The advisory lists a patchwork of remedies instead: the FTC’s Health Breach Notification Rule, California’s CMIA, Nevada’s law, and Washington’s My Health My Data Act.
The EU AI Act bars emotion recognition in workplaces and schools, and the US has no federal equivalent. Our report on neurotech in schools describes what that gap looks like: BrainCo’s Focus1 headband scores each student’s attention from 0 to 100 on a teacher dashboard 🔐.
Use limits: do the terms bar customers and partners from using outputs for hiring, insurance, or legal decisions?
Employer devices: who owns the account and the recordings if your employer buys the headset?
Legal process: what the company does with a subpoena or warrant, and whether it tells you.
Legal regime: whether the product falls under HIPAA, a state health-data law, or only the FTC Act.
Send all five questions to your headset’s maker this week. If the reply is a link to a generic privacy policy, what does that tell you?


