First Light — Consumer Health Data Privacy Policy
Version: 1.7 Effective Date: September 15, 2026 Originally Effective: August 1, 2026 Last Updated: September 15, 2026
For Washington State Residents and Consumers Whose Health Data Is Collected in Washington
This Consumer Health Data Privacy Policy is provided under Washington's My Health My Data Act (RCW 19.373). It describes how Legacy Build Inc. ("we," "us," "our"), the operator of First Light, collects, uses, shares, and protects Consumer Health Data.
This Policy applies to you if:
- You are a Washington State resident, or
- Your Consumer Health Data is collected while you are physically present in Washington State.
This Policy is in addition to our general Privacy Policy and our Terms of Service. Where this Policy differs from the general Privacy Policy with respect to Consumer Health Data of Washington consumers, this Policy controls.
1. What Is "Consumer Health Data"
Under MHMDA, Consumer Health Data means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. It includes, but is not limited to:
- Individual health conditions, treatment, diseases, or diagnoses
- Social, psychological, behavioral, and medical interventions
- Health-related surgeries or procedures
- Use or purchase of prescribed medication
- Bodily functions, vital signs, symptoms, or measurements of the information listed above
- Diagnoses or diagnostic testing, treatment, or medication
- Gender-affirming care information
- Reproductive or sexual health information
- Biometric data
- Genetic data
- Precise location information that could reasonably indicate a consumer's attempt to acquire or receive health services or supplies
- Data that identifies a consumer seeking health care services
- Any information that we or our processor processes to associate or identify a consumer with the data described above that is derived or extrapolated from non-health information
2. Consumer Health Data We Collect
In the course of providing First Light, we collect the following categories of Consumer Health Data:
(a) Health and wellness metrics from your connected devices. You can connect health data two ways: on-device sources (Apple Health on iOS, Google Health Connect on Android), which the First Light mobile app reads on your device; and server-side wearables (such as Oura Ring, WHOOP, Fitbit), which you link directly. In both cases the data is received and normalized by Open Wearables, health-data software that we run ourselves rather than a third-party aggregation service. No separate aggregation company receives your health data before we do. The service runs on hosting provided by Railway. We may collect:
- Sleep duration and quality
- Heart rate variability (HRV)
- Resting heart rate
- Respiratory rate
- Activity, steps, and workout data
- Recovery scores
We import history, not only readings made from that day forward. When you link a server-side wearable, we ask for readings that already exist in that device's account — up to three years of them — at the moment you connect. This is so First Light can tell what is typical for you straight away, instead of spending weeks observing you before it can say anything useful. These are the same categories listed above, and every other section of this Policy applies to them identically.
How far back we actually receive is set by the device provider, not by us, and it varies: some permit the full three years, and others limit us to as little as thirty days. On-device sources (Apple Health, Google Health Connect) provide no history through this route — their data lives on your phone, so those sources begin from the day you connect.
You control which data types are shared and can revoke access at any time — through Apple Health or Google Health Connect permissions for on-device sources, or by disconnecting the wearable in First Light's Settings for server-side sources. Disconnecting stops new readings; it does not delete readings we already hold, including imported history. To have those deleted, delete your account in Settings, or exercise your deletion right under Sections 8 and 9.
(b) Self-reported health-adjacent information. When you submit check-ins, entries, or voice notes, you may include information about your:
- Mental health status, mood, or emotional state
- Physical symptoms or sensations
- Sleep, energy, or fatigue
- Stress, anxiety, or overwhelm
- Medications, treatments, or professional care you are receiving
We process this information as Consumer Health Data regardless of whether you intended it as such.
(c) Voice recordings. If you submit voice notes, the audio recording and its transcription may contain health-adjacent information. We process the full content as Consumer Health Data.
First Light does not use voice recordings to identify or authenticate users and does not create voiceprints or speaker-identification templates.
By default, we delete the underlying audio once it has been transcribed and keep only the transcript. If you choose to keep your recordings (an option you turn on yourself in Settings), we keep the audio you record from then on while your account is active, and delete it when you delete the check-in it belongs to, or your account. Turning the setting off again stops us keeping new recordings; it does not remove the ones we kept while it was on. See Section 13 for our full retention schedule.
(d) Derived and inferred data. We generate derived information from the above, including:
- AI-generated pattern observations, prompts, weekly insight reports, and morning synthesis messages
- Sentiment and emotional state inferences from text and voice
- Observational correlations between your entries and health metrics
- Depth scores, confidence scores, and other internal metrics
- Vector representations of your entries used for pattern recognition
We treat all derived and inferred data that relates to your health status as Consumer Health Data.
The crisis check is not an inference we keep. When the words in a check-in, conversation, inbound message or voice note match a list of crisis-related terms, the Service shows you where to get help. It matches words, not circumstances: it is not a diagnosis, involves no clinical assessment, will miss things, and will sometimes respond when nothing is wrong. It sets no flag on your account and keeps no record beyond the reply itself, which stays in your conversation like any other message. No person reads your entries for it, nobody is alerted when it happens, and we do not contact anyone — not emergency services, not a third party, not a contact of yours.
3. Categories of Sources
We collect Consumer Health Data from:
- You directly — through check-ins, entries, voice notes, responses to prompts, and profile information
- Your connected devices and applications — through our own Open Wearables service, which receives data from Apple Health, Google Health Connect, and connected wearables (Oura, WHOOP, Fitbit, and similar). For server-side wearables this includes readings recorded before you connected, as described in Section 2(a)
- Our own processing — through AI-derived inferences and patterns generated from the above
4. Purposes for Which We Collect and Use Consumer Health Data
We collect and use Consumer Health Data only for the purposes set out in this section — the necessary ones listed immediately below, and the one optional purpose described after them, which is off unless you switch it on.
The following purposes are each necessary to provide the Service you requested:
- Generating daily prompts, pattern observations, weekly insight reports, and morning synthesis messages
- Recognizing patterns within your data over time
- Transcribing voice recordings you submit
- Synchronizing your data across the web app, iOS app, and Chrome extension
- Operating your account, including authentication and payment processing
- Maintaining security, preventing fraud, and protecting against abuse
- Communicating with you about your account and the Service
- Displaying crisis resources when certain keywords or patterns are detected (this feature is not a crisis monitoring service and does not create any duty of care — see our Terms of Service)
- Complying with legal obligations
One further purpose, which is optional, and which is off unless you switch it on.
Measuring how the Service is used — how many people check in, how often they come back, which of the three apps they use — is not necessary to provide the Service, so it is not in the list above and never will be. We ask for it separately, under Section 6, through a single setting in Settings → Health data called "Help us count how First Light is used." It is off for every account by default. Nothing is measured, and nothing is sent to the provider named in Section 5, until you turn it on, and turning it back off stops it.
If you switch it on, what we record is: that a check-in happened and when, roughly how long it was (a line, a paragraph, or a page), whether you tapped a feeling, which of the three apps and which capture method it arrived by, that a chat exchange happened and of what kind, that a weekly report was opened, and that onboarding was completed. Each of these is attached to your account number. We do not record the text of anything you write, which feeling you chose, or any health or wearable metric.
Declining changes nothing else. Check-ins, chat, insights, voice notes, and connected wearables all behave exactly the same way whether this setting is on or off, and we will not ask you again in a way designed to wear you down.
5. How We Share Consumer Health Data, and With Whom
We share Consumer Health Data only with the following categories of third parties, each of whom is bound by a written contract that restricts their use of the data to providing services to us:
| Third Party | Purpose | Categories Shared |
|---|---|---|
| Anthropic | AI processing (the Claude models) that generates First Light's outputs | Text of your check-ins, entries, and chat, plus derived context, as needed for processing |
| Supabase | Data infrastructure hosting | All Consumer Health Data categories, at rest |
| Railway | Hosting for the Open Wearables service we run — the software is ours; Railway provides the servers and database it runs on | Connected health & wearable metrics |
| OpenAI | Voice-to-text transcription (Whisper) and text embeddings that power search | Voice recordings and transcripts; the text of your check-ins, entries, chat messages, and search queries |
| Resend | Transactional emails (which may contain Service-generated content) | Limited Service-generated summaries sent to you |
| Twilio | Inbound text-message capture and outbound SMS notifications | Content of check-ins you send by text; phone number |
| Mailgun | Inbound email capture | Content of check-ins you send by email; email address |
| PostHog (EU region) | Product analytics — counting how often the Service is used. Only if you have switched on "Help us count how First Light is used" in Settings; off by default, and nothing is sent otherwise. | An account number, and: that a check-in happened and when, roughly how long it was, whether a feeling was tapped (yes or no), and which app and capture method it arrived by; that a chat exchange happened and of what kind; that a weekly report was opened; that onboarding was completed. Never the text of anything you write, never which feeling, never any health or wearable metric, and never your name, email address, or IP address. |
About measurement, and why PostHog is in the table above. What PostHog is told is Consumer Health Data, and we want to be direct about that rather than argue the other way. It is not told the text of anything you write, or which feeling you chose, or any metric — but it is told that a particular account made a mental-wellbeing check-in at a particular time, and that is an inference about your health that the law reaches. The account number is not your name, but it is still you: a number that identifies one person consistently is pseudonymous, not anonymous, and we will not describe it as anonymous anywhere.
That is why this one is handled differently from everything else in the table. Every other row is necessary to run the Service you asked for. This one is not, so it is off by default and sends nothing at all until you turn it on — see Section 4 and Section 6. PostHog is contractually our processor, is called only from our servers and never from your browser, is not told your name, email address, or IP address, and is instructed not to derive your location from the connection. Its browser software — the kind that can record what is on screen — is not installed in First Light at all.
Sentry receives reports when our software breaks. It is deliberately not in the table above because it is never told who you are — no account number, no email address, no IP address — and the reports themselves are rebuilt from a fixed list of technical fields before they leave us, so no error message and no request contents ever reach it. See the Privacy Policy, Section 5.1.
How our AI providers handle your data. We send the text of your entries to Anthropic's Claude models through Anthropic's commercial API, and voice recordings to OpenAI's transcription API, in each case solely to generate the outputs you asked First Light for.
Anthropic, PBC — AI processing. We use Anthropic's commercial API to generate certain First Light insights. Anthropic processes this information on our behalf under its Commercial Terms of Service and incorporated Data Processing Addendum. Anthropic states that it does not use commercial API inputs or outputs to train its models unless the customer affirmatively opts in. Under Anthropic's standard API practices, inputs and outputs are generally deleted from its backend within 30 days, subject to exceptions for features with different retention, safety and Usage Policy enforcement, special requirements applicable to certain covered models, legal obligations, or a different written retention arrangement. First Light does not opt in to model training and does not knowingly use a feature with materially different retention without first reviewing the change and updating our disclosures where required.
OpenAI — transcription and search. We use OpenAI's API to turn voice notes into text and to build the search index for your own entries. OpenAI states that API inputs and outputs are not used to train its models unless the customer affirmatively opts in, and First Light does not opt in. We use the transcription endpoint, which OpenAI documents as carrying no abuse-monitoring retention.
We do not share Consumer Health Data with:
- Advertisers
- Data brokers
- Advertising or behavioral-tracking technologies of any kind, on any surface. We do not use Google Analytics, the Meta Pixel, the Reddit Pixel, or anything comparable — not inside the Service, and not on our public marketing pages either
- Any analytics provider that can see what you write. We do use one product-analytics provider inside the Service, PostHog, and it is listed in the table above — and only for accounts that have switched the setting on, which is off by default. What it is told is limited to an account number and the countable facts listed in Section 4: that something happened, when, and which app it came from. It is never sent the text of an entry, never told which feeling, and never sent a health or wearable metric. Its browser software — the kind that can record what is on screen — is not installed in First Light at all, and an automated check in our code prevents it from being added
- Research partners, academic institutions, or other external parties, unless we obtain your separate, explicit opt-in consent
6. Collection, Use, and Sharing That Requires Consent
We ask for your consent to collect and process your Consumer Health Data before you begin using the parts of First Light that create it, through a separate consent step that is not bundled with our Terms of Service. We collect, use, and share Consumer Health Data only for the purposes and with the third parties listed in Sections 4 and 5 above.
If we wish to collect, use, or share Consumer Health Data for any purpose beyond what is necessary to provide the Service you requested, we will obtain your separate, affirmative, opt-in consent before doing so. We will not pre-check consent boxes, condition access to unrelated features on consent, or otherwise design the consent request to degrade your choice. You may withdraw your consent at any time in Settings; withdrawal stops further collection and does not affect processing that already occurred.
There is exactly one such purpose today: measurement. It is described in Section 4, and the setting is "Help us count how First Light is used," in Settings → Health data, in the web and mobile apps. It ships off. It is not part of signing up or of onboarding — deliberately, so that agreeing to it can never be a side effect of trying to get started. Nothing is sent while it is off, including for accounts that existed before the setting did. Switching it off later stops any further collection.
7. We Do Not Sell Consumer Health Data
Legacy Build Inc. does not sell Consumer Health Data as that term is defined in MHMDA. We do not exchange Consumer Health Data for monetary or other valuable consideration with any third party. We have no plans to sell Consumer Health Data.
If, in the future, we ever wished to sell Consumer Health Data, we would first obtain a valid authorization from you that meets the requirements of RCW 19.373.030(2), including all required signed statements, the specific data to be sold, the purchaser, the purpose, and an expiration date not to exceed one year. You could revoke that authorization at any time.
8. Your Rights Under MHMDA
You have the right to:
(a) Confirm whether we are collecting, sharing, or selling your Consumer Health Data.
(b) Access your Consumer Health Data, including a list of all third parties and affiliates with whom we have shared or sold your Consumer Health Data, and an active email address or other online mechanism you may use to contact those third parties.
(c) Withdraw consent to our collection and sharing of your Consumer Health Data. Withdrawal of consent does not affect collection or sharing that occurred before the withdrawal.
(d) Delete your Consumer Health Data. Upon your request, we will delete your Consumer Health Data from our records and notify all third parties and affiliates with whom we have shared your Consumer Health Data of your deletion request, so that they delete it as well.
(e) Appeal the denial of any of the above requests.
9. How to Exercise Your MHMDA Rights
Email privacy@seefirstlight.com with the subject line "Washington Consumer Health Data Request". Include:
- The right you wish to exercise (confirm, access, withdraw consent, delete, or appeal)
- The email address associated with your account
- Any other details that help us locate your data
We will:
- Verify your identity (typically by confirming you control the email associated with your account)
- Respond within 45 days of receipt. We may extend the response window by an additional 45 days when reasonably necessary, and we will notify you of any extension and the reason within the first 45 days.
- Honor your request free of charge for the first request within a 12-month period. For subsequent requests within 12 months, we reserve the right to charge a reasonable fee if requests are excessive or manifestly unfounded.
For deletion requests, we will also:
- Delete your Consumer Health Data from our active systems, and remove it from or render it inaccessible in any backup copies on our documented backup cycle — and, for Consumer Health Data subject to a verified deletion request, in no event longer than the six-month outer limit MHMDA permits (RCW 19.373.030)
- Notify all third parties, affiliates, and processors with whom we have shared your Consumer Health Data that you have requested deletion, and direct them to delete accordingly
You can also withdraw consent and delete your data yourself, at any time, from Settings inside First Light.
10. Right to Appeal
If we deny your request, we will notify you in writing of the denial and the reasons. You may appeal by replying to that denial email with the word "APPEAL" in the subject line. We will respond to your appeal within 45 days with a written decision.
If your appeal is denied, you may contact the Washington State Attorney General's Office to submit a complaint:
Washington State Attorney General's Office Consumer Protection Division Online: https://www.atg.wa.gov/file-complaint Phone: 1-800-551-4636
11. No Geofencing
Legacy Build Inc. does not, and will not, implement a geofence around any in-person healthcare facility (including but not limited to hospitals, clinics, medical offices, pharmacies, counseling offices, reproductive health facilities, or gender-affirming care facilities) to:
- Identify or track consumers seeking health care services
- Collect Consumer Health Data from consumers
- Send notifications, messages, or advertisements to consumers related to their Consumer Health Data or health care services
12. Security
We use administrative, technical, and physical safeguards designed to protect Consumer Health Data, including encryption in transit and at rest, role-based access controls, vendor security due diligence, and incident monitoring. Our general Privacy Policy describes these measures in more detail.
13. Consumer Health Data Retention
We keep Consumer Health Data only for as long as it is reasonably needed for the purpose it was collected, and no longer. We use these maximum periods:
- Check-ins, entries, and transcripts — kept while your account is active, because keeping them is the Service (your longitudinal record). When you delete your account, they are removed from our live systems immediately. Export a copy from Settings first if you want to keep it.
- Voice recordings — deleted after transcription by default. If you have turned on keeping your recordings, those recorded while it is on are kept while your account is active and deleted when you delete the check-in it belongs to, or your account. Turning the setting off again stops us keeping new recordings; it does not remove the ones we kept while it was on.
- Derived and inferred insights (weekly reports, pattern observations, sentiment, embeddings) — kept for no longer than the underlying entries they were generated from, and deleted with them.
- Deleted health data in backups — purged or rendered inaccessible on our documented backup cycle, and in no event retained longer than the six-month outer limit MHMDA permits after a verified deletion request.
- Billing and tax records — kept for up to 7 years as required by law, held separately from and stripped of your journal, voice, and health content.
- Consent records — we keep evidence that you gave (or withdrew) consent for as long as needed to establish that we had your permission, but not a duplicate of your health content.
- Security logs — up to 12 months.
- Support communications — up to 3 years from your last contact.
We may retain specific data for longer only where it is subject to a documented legal hold, and only for as long as that hold requires.
14. Children
The Service is not directed at anyone under 18. We do not knowingly collect Consumer Health Data from anyone under 18. If we learn we have, we will delete it.
15. Changes to This Policy
If we change this Policy in a way that materially affects how we collect, use, or share Consumer Health Data, we will:
- Notify you at least 30 days in advance by email and in-app notification
- Obtain your renewed consent before applying the change to Consumer Health Data collected before the change takes effect
- Update the "Last Updated" date above
Corrections take effect when we publish them, and every one is logged.
Sometimes a change here corrects something this Policy said inaccurately, rather than changing what we do. Waiting thirty days to publish a correction would mean leaving a statement we already know to be wrong in front of you for thirty more days, which helps nobody. So corrections take effect on publication.
A change is a correction only if it leaves all four of these untouched: what we collect, how we use it, who receives it, and how long we keep it. A change that alters any of them is not a correction and carries the full notice above — and if it widens any of them, the renewed-consent commitment applies as well. Narrowing what we do, or describing it more accurately, is the only thing this paragraph covers.
Every correction is recorded in the Revision History at the end of this Policy, naming what the previous version said and why it was wrong. That record is the check on this paragraph: it is what stops a correction from being made quietly.
16. Contact Us
Privacy requests: privacy@seefirstlight.com Questions about this Policy: privacy@seefirstlight.com
Legacy Build Inc. 30 N Gould St, Ste R, Sheridan, WY 82801
Revision History
Version 1.7 — effective September 15, 2026
Quiet Mode has been removed from the product, and so from this Policy.
Version 1.5 named a Quiet Mode signal as Consumer Health Data in its own right: a flag our software set when your words matched a list of crisis-related terms, and which made the following week quieter. To exist lawfully it needed its own consent, its own retention rule, and its own place in your data download. We decided that a change of tone for a week was not worth any of that, and removed the feature and the flag entirely on September 15, 2026. The table that held the flag and the consent record for it have been deleted from our systems.
What has gone from this Policy: the Quiet Mode bullet and the six paragraphs that followed it in Section 2. In their place, one paragraph describes the crisis check that remains and states what it does not do.
What has not changed. The crisis check itself. When your words match the list, the Service shows you where to get help, exactly as before, and Settings still carries a permanent link to a directory of free crisis lines. That check sets no flag, keeps no record beyond the reply in your conversation, tells no one, and contacts no one.
Why this document goes from 1.5 to 1.7. The three policies carry one version number between them. Version 1.6 changed the Privacy Policy and the Terms of Service only (text-message disclosures) and did not touch this document, which is why there is no 1.6 entry here.
How this version is classified under the change-notice commitment. A correction paired with a narrowing: it removes a processing activity and the data it produced, and it widens nothing about what we collect, how we use it, who receives it, or how long we keep it. No renewed consent is required. No advance notice was owed in any case: First Light has no users yet, so there is nobody whose agreement predates this version.
Version 1.5 — effective September 9, 2026
We were not telling you about a decision our software makes about you.
If a check-in or a conversation mentions self-harm or suicide, our software sets a flag on your account, by itself, and for the next seven days First Light behaves differently toward you — fewer prompts, no daily question, a gentler reply, no patterns surfaced, no reminders. It has worked this way since launch. Nothing in the product told you it had happened, and this Policy described it only under the general heading of AI-derived inferences.
Two external law firms independently identified this as the most significant gap in our disclosures. Section 2 now names the Quiet Mode signal as Consumer Health Data in its own right and describes in full what it does, what it never does, that it is not a diagnosis, that no person reviews it, and how to see it and switch it off. Section 2.8 of the Privacy Policy carries the same description, and Section 16.6 there sets out the GDPR safeguards.
In the product, at the same time: Quiet Mode is now something you turn on rather than something that happens to you — we ask for it separately, it is off unless you say otherwise, and you can change that in Settings whenever you like. While it is on, your dashboard says so and Settings explains it and offers a switch; switching it off keeps it off for the rest of that week. The record is deleted once the week ends, so no history accumulates, and your data download shows it only while it is active. An internal severity score, recorded and never used for anything, has been removed entirely.
Nothing about what we collect, keep, delete or share has changed. Quiet Mode is not new; describing it is.
How this version is classified under the change-notice commitment. Most of what changed here is a correction as newly defined: it alters what we say, not what we do. The exceptions are three, and all three narrow what we do rather than widen it — Quiet Mode now requires your consent before it can happen at all, its record is now deleted rather than kept, and an internal score was removed. Nothing here expands what we collect, how we use it, who receives it, or how long we keep it, so no renewed consent is required. And no advance notice was owed in any case: First Light has no users, so there is nobody whose agreement predates this version.
Version 1.4 — effective September 7, 2026
We replaced the company that used to sit between your wearable and us.
Until now, health data from a connected device reached us through Terra, a separate health-data aggregation company. Terra received your readings, normalized them, and passed them on. We have replaced Terra with Open Wearables — health-data software that we run ourselves. The practical effect is that one fewer company receives your health data: what used to be an outside service is now software under our own control, and no aggregation provider sits in front of us any more.
The software runs on servers provided by Railway, which is now listed as a service provider in the same way our other hosting and database providers are. Railway stores the data for us; it is not a health-data company and does nothing with it.
Nothing about what we collect, how long we keep it, or what we do with it has changed. The list of who we share Consumer Health Data with is shorter as a result, not longer.
No advance notice was owed for this change: First Light has no users yet, so there is nobody whose agreement predates it. Once the Service has users, material changes carry thirty days' notice as described in this Policy.
Version 1.3 — effective September 5, 2026
An audit compared every statement in this Policy against the software as it runs. This version corrects the two statements in this Policy that did not match, and spells out one thing it had left unsaid. Nothing here changes what we collect or share; it changes what we say, to match.
- Where the measurement setting is. Section 6 said "Help us count how First Light is used" is in Settings on all three apps. The browser extension has no such setting; the web and mobile apps do. Corrected. The setting still ships off, and the extension sends nothing either way.
- Firebase removed. Section 5 named Firebase Cloud Messaging as a recipient of push notifications. Nothing in the software sends anything to Firebase — mobile reminders are set locally on your phone. A recipient that receives nothing has been removed from the table.
- Turning off "Keep my voice recordings." Sections 2(c) and 13 said kept audio is deleted when you delete the recording or your account, and said nothing about what turning the setting off does. They now say it: turning the setting off stops us keeping new recordings; the ones kept while it was on stay until you delete the check-ins they belong to, or your account.
On the 30 days' notice promised in Section 15. No notice was given for these changes, and none was owed, for the same reason recorded under Versions 1.1 and 1.2: First Light still has no users. The only accounts in existence belong to the operator, testing the Service before launch. There is no consumer to notify, and no earlier-collected consumer health data to which a change could be applied. We are recording that here rather than leaving it to be inferred. The Section 15 commitment stands unchanged and applies in full from the first real user onward.
Version 1.2 — effective September 2, 2026
- We import history when you connect a wearable, and now we say so. Section 2(a) previously listed what a connected device contributes and was silent on how far back. That was accurate while First Light only ever received readings a device made after you linked it. It stopped being accurate when we began requesting up to three years of readings that already exist in the device's account at the moment you connect. The categories collected have not changed; the reach of the collection has, and the reach is part of what you are agreeing to rather than a detail beneath it. Section 2(a) now states the three-year request, that the provider — not us — decides how much of it we actually receive, and that on-device sources (Apple Health, Google Health Connect) contribute no history at all.
- What disconnecting does, and does not do. Section 2(a) now says plainly that disconnecting a wearable stops new readings but does not delete readings we already hold, and points to the deletion right in Sections 8 and 9. This was already true and already governed by those sections; it was not stated where somebody deciding whether to disconnect would read it.
- Section 3 now notes that the connected-device source includes pre-connection readings, so the sources list does not imply a start date the collection section contradicts.
On the 30 days' notice promised in Section 15. No notice was given for this change, and none was owed, for the same reason recorded under Version 1.1: First Light still has no users. The only accounts in existence belong to the operator, testing the Service before launch. There is no consumer to notify, and no earlier-collected consumer health data to which this change could be applied — nobody has connected a wearable to a First Light account except the operator. We are recording that here rather than leaving it to be inferred. The Section 15 commitment stands unchanged and applies in full from the first real user onward.
Version 1.1 — effective August 28, 2026
Consolidates every change made since Version 1.0 took effect on August 1, 2026:
- Deletion timing. Corrected a promise of up to 30 days to export your data before deletion; deletion is immediate, and the export is available beforehand rather than during a wait.
- Two processors we had not named. Added Sentry (error reporting) and PostHog (product analytics) to our disclosures, and stated plainly that we run no advertising or behavioral-tracking technology on any surface.
- Measurement became a stated purpose. Removed a sentence asserting that PostHog "is not sent Consumer Health Data." That framing was wrong: the events are keyed to an account number, and a number that identifies one person consistently is pseudonymous, not anonymous. Section 4 now separates the purposes necessary to run the Service from the one optional purpose — measurement — which is off by default and sends nothing until you switch it on in Settings. Section 5 describes exactly what is sent, and Section 6 names the setting.
On the 30 days' notice promised in Section 15. Section 15 commits us to 30 days' advance notice, and to renewed consent, before a material change applies to Consumer Health Data collected earlier. No such notice was given for any of the changes above, and none was owed: First Light had no users during this period. The only accounts in existence belonged to the operator, testing the Service before launch, so there was no consumer to notify and no earlier-collected consumer data to which a change could be applied. We are recording that here rather than leaving it to be inferred.
The Section 15 commitment stands unchanged and applies in full to every version from this one onward.
Version 1.0 — effective August 1, 2026. Initial published policy.