First Light — Privacy Policy
Version: 1.0 Effective Date: May 29, 2026 Last Updated: May 29, 2026
1. Introduction
This Privacy Policy describes how Legacy Build Inc. ("Legacy Build Inc.," "we," "us," or "our") collects, uses, shares, and protects information in connection with the First Light service (the "Service").
First Light is a consumer wellness tool for self-reflection and personal pattern awareness. Because the Service works with health-adjacent information (your check-ins, voice notes, and optional health and wearable data), we treat privacy as a core feature, not an afterthought.
This Privacy Policy applies to information we collect through:
- The First Light website and web application
- The First Light iOS application (when available)
- The First Light Chrome extension
- Any related communications or services we provide
This Privacy Policy does not apply to third-party services you choose to connect (such as Apple Health, Google Health Connect, Oura, WHOOP, or Apple Watch) or to Terra's own handling of data before it reaches us, which are governed by those providers' own privacy policies.
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
Additional information for specific jurisdictions appears in Sections 14–19 at the end of this Policy:
- Section 14 — Washington residents (My Health My Data Act)
- Section 15 — California residents (CCPA/CPRA)
- Section 16 — EU, EEA, UK, and Swiss residents (GDPR)
- Section 17 — Other U.S. state residents
- Section 18 — Nevada residents
- Section 19 — Canadian residents
2. Information We Collect
We collect the following categories of information.
2.1 Information You Provide Directly
Account information: Name or display name, email address, date of birth (to verify 18+), password hash, profile preferences. If you choose to capture check-ins by text message or receive text-message reminders, we also collect and store the phone number you link to your account.
Subscription and billing information: Billing name, billing address, subscription tier, purchase history. Payment card numbers are collected and stored by Stripe, not by Legacy Build Inc.. We receive only a tokenized reference, the last four digits of the card, the card brand, and the expiration date.
User Content: Everything you record through the Service, including:
- Text-based check-ins and entries
- Voice recordings and their transcripts
- Responses to structured prompts and tags
- Settings, preferences, and selections
- Feedback and correspondence with us
You can submit check-ins inside the app, through our Chrome extension, or — if you enable those capture channels — by sending a text message (SMS) or email to the Service. Content you send this way becomes User Content.
Communications: Emails, support requests, survey responses.
2.2 Health and Wellness Information
This is the most sensitive category of information we handle.
You can connect health and wearable data two ways: (1) on-device sources — Apple Health on iOS or Google Health Connect on Android — which the First Light mobile app reads on your device; and (2) server-side wearables such as Oura, WHOOP, and Fitbit, which you link directly. In both cases the data is received, normalized, and delivered to us through Terra, our health-data aggregation provider (a subprocessor). The metrics we collect are:
- Sleep duration and quality
- Heart rate variability (HRV)
- Resting heart rate
- Activity and step count
- Respiratory rate
- Recovery scores
You control which data types we can access, and you can revoke access at any time — in the Apple Health or Google Health Connect permissions for on-device sources, or by disconnecting the wearable through Terra for server-side sources.
Your check-ins and voice notes may also contain health-adjacent information you choose to share — for example, descriptions of sleep, mood, stress, or symptoms. We treat this content as "Consumer Health Data" as defined by Washington's My Health My Data Act.
2.3 Information We Derive
We create derived information from the above, including:
- AI-generated outputs (prompts, pattern observations, weekly insight reports, morning synthesis messages, song recommendations)
- Detected patterns (e.g., entities and topics mentioned in entries)
- Sentiment and emotional state inferences from voice and text
- Correlations between entries and health metrics
- Depth scores, confidence scores, and similar internal metrics
- Vector embeddings of User Content (used for pattern recognition and retrieval)
2.4 Information Collected Automatically
When you use the Service, we automatically collect:
- Device information: Device type, operating system, browser type, language, time zone
- Usage information: Features used, screens viewed, actions taken, timestamps, session duration
- Log data: IP address, access times, error logs, referring pages
- Approximate location: Derived from your device's time zone setting (city/region level) to select time-of-day background imagery. We do not perform IP-based geolocation and we do not collect precise (GPS) coordinates.
2.5 Cookies and Similar Technologies
We and our service providers use cookies, pixels, SDKs, and similar technologies to operate the Service, remember your preferences, understand usage, and (on our marketing pages only) measure advertising effectiveness. See Section 11 for details.
2.6 Information From Third Parties
- Payment processors (Stripe): Transaction confirmations, billing status, fraud indicators
- AI providers (Anthropic, OpenAI): Operational metadata, error information
- Analytics providers (Google Analytics 4, Meta, Reddit — on marketing pages only): Aggregated usage data
- Health data aggregation (Terra, receiving from Apple Health, Google Health Connect, and connected wearables such as Oura, WHOOP, Fitbit): the metrics you authorize
2.7 Information We Do Not Collect
We do not collect:
- Social Security numbers or government ID numbers
- Precise geolocation (GPS) coordinates
- Contents of your other apps, files, or communications
- Information from minors under 18 (knowingly)
- Full payment card numbers, CVVs, or bank account details (held only by Stripe)
3. How We Use Information
We use the information we collect to:
3.1 Provide and Operate the Service
- Create and manage your account
- Process your check-ins, voice notes, and health data
- Generate AI Outputs (prompts, pattern observations, weekly reports)
- Detect patterns in your entries and health data
- Sync data across the web, iOS, and Chrome extension
- Transcribe voice recordings
3.2 Process Payments and Subscriptions
- Charge subscription fees
- Process refunds
- Prevent fraud
- Handle billing inquiries
3.3 Communicate With You
- Send transactional messages (billing, security, legal notices, service availability)
- Send service communications (pattern alerts, weekly reports, notifications — per your preferences)
- Respond to support requests
- Send marketing communications only if you have opted in (and you may unsubscribe at any time)
3.4 Maintain Safety and Security
- Authenticate accounts
- Detect and prevent fraud, abuse, and unauthorized access
- Display crisis resources when specific keywords or patterns are detected (see our Terms of Service §4.5 — this feature is not a crisis monitoring service and we do not guarantee detection)
3.5 Improve the Service
- Understand how users interact with the Service
- Diagnose bugs and improve performance
- Develop new features
- Conduct internal analytics on aggregated or de-identified data
3.6 Legal and Compliance
- Comply with laws, court orders, subpoenas, and legal process
- Enforce our Terms of Service
- Protect the rights, property, and safety of Legacy Build Inc., our users, and others
3.7 Uses We Do Not Engage In
We do not:
- Sell your Personal Information or Consumer Health Data.
- Share your Personal Information or Consumer Health Data for cross-context behavioral advertising.
- Use your User Content, Consumer Health Data, or AI Outputs to train artificial intelligence or machine learning models.
- Use data from Apple HealthKit for any purpose other than providing you the Service's health-related features.
- Use Consumer Health Data for advertising of any kind.
4. Legal Basis for Processing (EU/UK Residents)
If you are in the EU, EEA, UK, or Switzerland, we process your Personal Data on the following legal bases under GDPR:
| Processing Activity | Legal Basis |
|---|---|
| Account creation, Service delivery, billing | Performance of a contract (Art. 6(1)(b)) |
| Marketing communications | Consent (Art. 6(1)(a)) — you may withdraw at any time |
| Security, fraud prevention, product improvement | Legitimate interests (Art. 6(1)(f)) |
| Processing health data | Explicit consent (Art. 9(2)(a)) |
| Processing voice recordings (biometric) | Explicit consent (Art. 9(2)(a)) |
| Legal obligations (e.g., tax records) | Legal obligation (Art. 6(1)(c)) |
You can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
5. How We Share Information
We share information only in the limited ways described below. We do not sell your Personal Information.
5.1 Service Providers
We share information with third-party service providers who perform services on our behalf, under contractual obligations of confidentiality and data protection:
| Provider | Purpose | Categories Shared |
|---|---|---|
| Anthropic | AI processing for generating Outputs | User Content (entries, transcripts, context), derived metadata |
| Stripe | Payment processing | Billing information, transaction data |
| Supabase | Database and infrastructure hosting | All service data |
| OpenAI | Voice-to-text transcription (Whisper) and text embeddings that power search | Voice recordings; the text of your check-ins and entries |
| Resend | Transactional and service emails | Email address, message content |
| Firebase Cloud Messaging | Mobile push notifications | Device push tokens |
| Twilio | Inbound text-message capture and outbound SMS notifications/reminders | Phone number, message content |
| Mailgun | Inbound email capture ("email a thought") | Email address, message content |
| Terra | Wearable/health-data aggregation and normalization | Connected health & wearable metrics |
| Apple (HealthKit) | On-device health data access (via the mobile app) | Per your HealthKit authorizations |
| Google Analytics 4 (marketing pages only) | Website analytics | Pseudonymous usage data |
| Meta (Facebook) Pixel (marketing pages only) | Advertising measurement | Pseudonymous identifiers, page events |
| Reddit Pixel (marketing pages only) | Advertising measurement | Pseudonymous identifiers, page events |
Anthropic, Stripe, Supabase, Terra, OpenAI, Resend, Firebase Cloud Messaging, Twilio, and Mailgun each process your data only to provide services to us, under contractual restrictions. [VERIFY: confirm a signed Data Processing Addendum is on file for each subprocessor, especially Twilio and Mailgun.] OpenAI receives the text of your entries, chat messages, and search queries (to create the embeddings that power search) as well as your voice recordings (to create transcripts). Under OpenAI's standard API terms, this data is not used to train its models and is retained only transiently for abuse-monitoring purposes before deletion.
5.2 Legal and Compliance
We may disclose information when we believe in good faith that disclosure is necessary to:
- Comply with a law, regulation, legal process, or government request
- Enforce our Terms of Service
- Protect the rights, property, or safety of Legacy Build Inc., our users, or others
- Detect, prevent, or address fraud, security, or technical issues
Where legally permitted, we will notify you of law enforcement requests before disclosure, unless we are legally prohibited or believe doing so would endanger a person.
5.3 Business Transfers
If Legacy Build Inc. is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will require the successor to honor this Privacy Policy, or we will notify you and provide choices (including deletion) before your data is subject to a different privacy policy. [ATTORNEY REVIEW: confirm notification mechanics required by MHMDA §RCW 19.373.030(6)]
5.4 With Your Consent
We may share information with your consent or at your direction (for example, if you choose to export and share a weekly insight report).
5.5 Aggregated or De-identified Information
We may create and use aggregated or de-identified information that cannot reasonably be used to identify you. We use this information for:
- Internal analytics and Service improvement
- Evaluating feature performance
- Marketing claims in anonymized form (e.g., "a majority of users observed a pattern within their first three weeks")
We do not sell aggregated or de-identified Consumer Health Data, and we do not license or share such data with external research partners without additional explicit consent from affected users. [ATTORNEY REVIEW: MHMDA imposes specific requirements on de-identified consumer health data. Confirm compliance posture.]
5.6 What We Do Not Do
We do not:
- Sell your Personal Information or Consumer Health Data to any third party
- Share your Personal Information or Consumer Health Data for advertising purposes
- Disclose HealthKit data to advertising services or sell HealthKit data for any reason (required by Apple)
- Provide your User Content to researchers or partners without explicit opt-in consent
6. Data Retention
We retain Personal Information only for as long as needed for the purposes described in this Policy.
| Category | Retention |
|---|---|
| Account profile | For the life of your account |
| User Content (entries, transcripts) | For the life of your account, until you delete it |
| Voice recordings (audio files) | For the life of your account, until you delete the recording or your account. You can switch voice storage to "transcript only" in settings at any time, after which we keep only the transcript and not the audio. |
| Health data | For the life of your account, until you delete it or disconnect the source |
| Billing and transaction records | 7 years (tax and financial record requirements) |
| Support communications | 3 years from last contact [VERIFY] |
| Log and security data | 12 months [VERIFY] |
| Backups | Deleted data is purged from database backups within 7 days. (Our current hosting plan retains no automated database backups; if backups are enabled, they roll on a window no longer than 7 days.) |
| Aggregated or de-identified data | Indefinitely |
On account deletion: You have 30 days after termination to export your data. After 30 days, your User Content and Consumer Health Data are permanently deleted from active systems, except for (a) aggregated/de-identified data, (b) database backups on the rolling window described above, (c) data we must retain for legal or financial reasons, and (d) limited operational data retained by our service providers on their own schedules, described below.
Deletion at third-party processors: When you delete a check-in or your account, we remove it from our active systems and, where a provider supports programmatic deletion, we trigger it on the provider's side (for example, disconnecting your Terra wearable connection and deleting your Stripe customer record). Some providers retain limited operational data on their own schedules, which we minimize to the least each allows:
- Twilio (text check-in capture): we enable message-body redaction so the content of texts is discarded, and message records are retained for the shortest window Twilio permits — currently 7 days (Twilio's minimum; the window is configurable up to 400 days).
- Mailgun (email check-in capture): we set message-content retention to the minimum (disabled), so inbound email content is not stored beyond processing; Mailgun's delivery and event logs persist for up to 30 days per plan.
- Stripe (payments): transaction and payment records are retained by Stripe as required by financial and tax law, even after we delete your customer record.
- Resend (outbound email): delivery logs — recipient address and message metadata, not your entries — are retained on Resend's schedule.
[VERIFY: confirm Twilio message-body redaction + the 7-day record window, and Mailgun message-content retention = disabled, are configured in the provider dashboards before publication.]
7. How We Protect Information
We use administrative, technical, and physical safeguards designed to protect your information, including:
- Encryption in transit (TLS 1.2 or higher)
- Encryption at rest (for database storage via Supabase)
- Access controls: Role-based access, limited personnel access to production data
- Authentication: Password hashing, session management
- Infrastructure: Reputable cloud hosting with SOC 2 certifications
- Monitoring: Logging and anomaly detection
- Vendor due diligence: Subprocessor agreements and security reviews
No security system is perfect. We cannot guarantee absolute security. If we experience a data breach affecting your information, we will notify you and applicable regulators as required by law, including the FTC Health Breach Notification Rule, state breach notification laws, MHMDA, GDPR, and other applicable regimes.
[ATTORNEY REVIEW: Confirm appropriate level of detail — stating too much creates specific representations that can be basis for claims if breach reveals non-compliance. Standard is to describe measures generally.]
8. Your Rights and Choices (All Users)
Regardless of where you live, you can:
- Access your information through the Service (account settings, weekly reports, entry history)
- Export your information in a portable format via in-app export tools
- Correct inaccurate information in your account settings
- Delete your account via account settings or by emailing privacy@seefirstlight.com
- Disconnect health data sources via Apple Health / Google Health Connect permissions, or by disconnecting a wearable through Terra
- Opt out of marketing emails via the unsubscribe link in any marketing email
- Control notifications via in-app notification preferences
- Revoke voice recording retention by switching voice note storage to "transcript only" in settings
Specific state and jurisdiction rights are described in Sections 14–19.
To exercise any right, contact us at privacy@seefirstlight.com. We will verify your identity (typically by confirming the email associated with your account) and respond within the time required by applicable law, generally within 45 days.
9. International Data Transfers
We are based in the United States and process data in the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States.
For users in the EU, EEA, UK, and Switzerland, we rely on the following mechanisms for international transfers:
- Standard Contractual Clauses (SCCs) with our service providers
- UK International Data Transfer Addendum for UK transfers
- Swiss Data Protection Authority-approved mechanisms for Swiss transfers
You may request a copy of the applicable transfer mechanism by contacting privacy@seefirstlight.com.
[ATTORNEY REVIEW: confirm Data Privacy Framework (DPF) certification strategy and whether Legacy Build Inc. should self-certify]
10. Children's Privacy
The Service is not directed to, intended for, or designed for use by anyone under 18. We do not knowingly collect information from anyone under 18. If we learn we have collected information from a person under 18, we will delete it promptly.
If you are a parent or guardian and believe your child under 18 has provided information to the Service, contact us at privacy@seefirstlight.com.
11. Cookies and Similar Technologies
11.1 What We Use
On our marketing website (landing pages):
- Essential cookies: Required for the site to function
- Analytics cookies: Google Analytics 4 — understand how visitors find and use the site
- Advertising cookies: Meta Pixel and Reddit Pixel — measure the effectiveness of advertising campaigns
In the authenticated application (dashboard, iOS app, Chrome extension):
- Essential cookies/storage: Required for authentication, session management, and core functionality
- We do not run advertising or behavioral tracking inside the authenticated application
11.2 Your Choices
- Cookie banner: When you first visit our marketing site from a jurisdiction that requires consent (EU, UK, EEA, certain U.S. states), you will see a cookie consent banner
- Browser controls: Most browsers let you block or delete cookies
- Do Not Track / Global Privacy Control: We honor the Global Privacy Control (GPC) signal as an opt-out of "sale" and "sharing" under applicable state laws
- Mobile device settings: iOS offers "Limit Ad Tracking" and similar controls
[ATTORNEY REVIEW: confirm cookie banner implementation, consent categories, and regional triggering]
12. Third-Party Links and Services
The Service may contain links to third-party websites, apps, or services. We are not responsible for the privacy practices of third parties. When you connect a third-party data source (such as Apple Health), that service's own privacy policy governs how it handles your data before it reaches us.
13. Changes to This Privacy Policy
We may update this Privacy Policy. When we do:
- We will update the "Last Updated" date at the top
- For material changes, we will provide at least 30 days' advance notice by email or in-app notification
- For changes that materially expand how we use your Consumer Health Data, we will seek your renewed consent before applying the change to previously collected data
Your continued use of the Service after changes take effect constitutes acceptance. If you do not agree to the changes, you may delete your account and export your data.
14. Washington Residents — My Health My Data Act Notice
This section serves as the Consumer Health Data Privacy Policy required by Washington's My Health My Data Act (MHMDA), RCW 19.373.020. Washington residents and anyone whose Consumer Health Data is collected in Washington should read this section in addition to the rest of this Privacy Policy.
[ATTORNEY REVIEW: some practitioners recommend a fully separate Consumer Health Data Privacy Policy page. Confirm preferred format.]
14.1 What Is Consumer Health Data
MHMDA defines "Consumer Health Data" broadly to include personal information that identifies a consumer's past, present, or future physical or mental health status. In the context of First Light, we treat the following as Consumer Health Data:
- Health data you connect via Terra (from Apple Health, Google Health Connect, and connected wearables such as Oura, WHOOP, Fitbit) — sleep, HRV, resting heart rate, activity, recovery, respiratory rate, and similar
- Content of your check-ins, entries, and voice notes to the extent they describe health status, symptoms, mood, stress, emotions, or mental state
- AI-generated outputs derived from the above (patterns, weekly reports, morning synthesis, pulse prompts)
- Derived metrics (emotional state inferences, sentiment scores, depth scores, confidence scores)
- Any information that could be used to infer a health condition
14.2 Categories of Consumer Health Data We Collect
- Health and wellness metrics from connected devices (via Terra, from Apple Health, Google Health Connect, and connected wearables)
- Self-reported mood, emotional state, and mental state (through check-ins)
- Self-reported physical sensations or symptoms (if you choose to share them)
- Voice recordings and transcripts containing health-related content
- Inferences derived from your entries (emotional state, patterns, sentiment)
14.3 Categories of Sources
- Directly from you (check-ins, voice notes, responses)
- From your devices and health data sources (via Terra, from Apple Health, Google Health Connect, and connected wearables)
- Derived by our Service (AI outputs and inferences)
14.4 Purposes for Collection and Use
- To provide the Service (generate check-in prompts, pattern observations, weekly insights, morning synthesis)
- To operate your account and process payment
- To maintain security and prevent fraud
- To communicate with you about the Service
- To comply with legal obligations
14.5 Categories of Consumer Health Data We Share, and With Whom
| Category | Shared With |
|---|---|
| All Consumer Health Data categories | Anthropic (AI processing, under contractual restrictions) |
| All Consumer Health Data categories | Supabase (infrastructure hosting, under contractual restrictions) |
| Text of check-ins, entries, chat messages, and search queries (for search embeddings); voice recordings (for transcripts) | OpenAI (standard API terms — not used for training; retained only transiently for abuse monitoring, then deleted) |
| Content of check-ins sent by text message; phone number | Twilio (SMS capture and delivery, under contractual restrictions) |
| Content of check-ins sent by email; email address | Mailgun (inbound email capture, under contractual restrictions) |
| Connected health & wearable metrics | Terra (aggregation and normalization, under contractual restrictions) |
| No categories | Advertisers |
| No categories | Data brokers |
| No categories | External research partners (without explicit opt-in consent) |
14.6 We Do Not Sell Consumer Health Data
Legacy Build Inc. does not sell Consumer Health Data as that term is defined in MHMDA. We do not exchange Consumer Health Data for monetary or other valuable consideration to any third party. We will not sell Consumer Health Data without a valid authorization that meets MHMDA's requirements, which we have no plans to seek.
14.7 Your MHMDA Rights
If you are a Washington resident or your Consumer Health Data was collected while you were in Washington, you have the right to:
- Confirm whether we are collecting, sharing, or selling your Consumer Health Data, and to access that data
- Delete your Consumer Health Data
- Withdraw consent to further collection or sharing of your Consumer Health Data
- Appeal the denial of any request
14.8 How to Exercise MHMDA Rights
Email privacy@seefirstlight.com with the subject line "Washington Consumer Health Data Request" and describe which right you wish to exercise. We will:
- Verify your identity (typically via your account email)
- Respond within 45 days, extendable by an additional 45 days when reasonably necessary
- Delete your Consumer Health Data from our records, from third parties that processed it on our behalf, and request deletion by affiliates (where applicable)
14.9 Consent
Before we collect Consumer Health Data beyond what is strictly necessary to provide the Service you requested, we will obtain your consent. Before we share Consumer Health Data beyond what is strictly necessary, we will obtain separate consent. [ATTORNEY REVIEW: MHMDA distinguishes between collection/sharing for "necessary" purposes vs. other purposes. Confirm consent flow design — this requires a separate consent checkbox/screen at onboarding, distinct from ToS acceptance.]
14.10 Appeal
If we deny your request, you may appeal by replying to the denial email with "Appeal" in the subject line. We will respond within 45 days. If your appeal is denied, you may contact the Washington Attorney General at https://www.atg.wa.gov/.
14.11 Geofencing
We do not use geofencing around any in-person healthcare facility to identify, track, collect data from, or send notifications to consumers regarding their Consumer Health Data.
15. California Residents — CCPA/CPRA Notice
This section provides information required by the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA").
15.1 Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of Personal Information:
| CCPA Category | Examples | Sources | Purposes |
|---|---|---|---|
| A. Identifiers | Name, email, IP address | You, devices | Service delivery, security |
| B. California customer records | Name, billing info | You, Stripe | Billing, Service delivery |
| C. Protected classifications | Age (to verify 18+) | You | Eligibility |
| D. Commercial information | Subscription history | Stripe | Billing |
| F. Internet activity | Usage, device info | Devices | Service delivery, analytics |
| G. Geolocation | Approximate (IP-based) | Devices | Fraud prevention |
| H. Audio | Voice recordings | You | Service delivery |
| I. Professional info | Not collected | — | — |
| J. Education info | Not collected | — | — |
| K. Inferences | Emotional state, patterns | Derived | Service delivery |
| Sensitive Personal Information | Health data, Consumer Health Data, voice recordings, account credentials | You, devices | Service delivery |
15.2 Sale or Sharing of Personal Information
We do not "sell" or "share" Personal Information as those terms are defined under CCPA, except as follows:
- On our marketing website (landing pages) only, we use Meta Pixel and Reddit Pixel, which may constitute "sharing" for cross-context behavioral advertising under CCPA. You can opt out via our cookie banner and by enabling Global Privacy Control (GPC) in your browser.
Inside the authenticated Service (where Consumer Health Data is processed), we do not share Personal Information with any advertising providers.
15.3 Use of Sensitive Personal Information
We use Sensitive Personal Information (health data, voice recordings, account credentials) only for the purposes specified in California Civil Code §1798.121(a) — to provide the Service you requested, to prevent fraud, to ensure security, and to comply with law. We do not use it for inferences about characteristics. You have the right to limit our use of Sensitive Personal Information, but because our use is already limited to these purposes, the right has no additional effect.
15.4 California Rights
You have the right to:
- Know what Personal Information we collect, use, disclose, and sell/share
- Delete your Personal Information (subject to limited exceptions)
- Correct inaccurate Personal Information
- Opt out of "sale" and "sharing" (for the marketing pages; we don't sell or share elsewhere)
- Limit use of Sensitive Personal Information (as described above)
- Non-discrimination for exercising your rights
- Authorize an agent to act on your behalf
15.5 How to Exercise California Rights
Email privacy@seefirstlight.com with "California Privacy Request" in the subject line. We may need to verify your identity. Authorized agents must provide written authorization.
15.6 California Shine the Light
California Civil Code §1798.83 permits California residents to request information about disclosures of Personal Information to third parties for direct marketing. We do not disclose Personal Information to third parties for their direct marketing purposes.
15.7 Metrics
[ATTORNEY REVIEW: If Legacy Build Inc. processes PI of 10M+ Californians, annual metrics disclosure is required under CCPA regulations. Not currently applicable but flag for monitoring.]
16. EU, EEA, UK, and Swiss Residents — GDPR Notice
16.1 Controller
Legacy Build Inc. is the controller of your Personal Data.
Legacy Build Inc. 30 N Gould St, Ste R, Sheridan, WY 82801 Email: privacy@seefirstlight.com
16.2 EU Representative
First Light is offered to United States residents only at launch and does not target the EU/EEA. Before offering the Service to EU/EEA residents or monitoring their behavior, we will appoint an EU Representative under GDPR Article 27 and publish their contact details here.
16.3 UK Representative
First Light is offered to United States residents only at launch and does not target the UK. Before offering the Service to UK residents, we will appoint a UK Representative under UK GDPR Article 27 and publish their contact details here.
16.4 Data Protection Officer
A DPO is not currently required under GDPR Art. 37 based on our scale and processing profile. [ATTORNEY REVIEW: confirm ongoing DPO assessment as user base grows]
16.5 Your GDPR Rights
You have the right to:
- Access the Personal Data we hold about you
- Rectify inaccurate Personal Data
- Erase your Personal Data ("right to be forgotten")
- Restrict processing
- Data portability — receive your data in a portable format and transmit it to another controller
- Object to processing based on legitimate interests or for direct marketing
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with your local data protection authority
To exercise any right, contact privacy@seefirstlight.com. We will respond within 30 days (extendable to 90 days for complex requests).
16.6 Automated Decision-Making
We do not use Personal Data for automated decision-making that produces legal or similarly significant effects on you. AI-generated outputs from the Service are suggestions for your reflection and do not constitute automated decisions within the meaning of GDPR Art. 22.
16.7 International Transfers
Your Personal Data is transferred to the United States. We rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK transfers) with our service providers. [ATTORNEY REVIEW: consider DPF self-certification]
17. Other U.S. State Residents
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Florida, Iowa, Indiana, Tennessee, New Jersey, New Hampshire, Nebraska, Minnesota, Rhode Island, Maryland, and Kentucky have rights substantially similar to the California rights described in Section 15 under their respective state privacy laws, which may include:
- The right to access Personal Data
- The right to delete Personal Data
- The right to correct Personal Data
- The right to data portability
- The right to opt out of targeted advertising, sale, and certain profiling
- The right to appeal
To exercise any right, contact privacy@seefirstlight.com with the subject line "State Privacy Request — [Your State]." We will respond within the time required by your state's law, generally 45 days.
If we deny your request, you may appeal by replying to the denial email. If your appeal is denied, you may contact your state Attorney General.
[ATTORNEY REVIEW: confirm applicability thresholds for each state and whether specific disclosures are required]
18. Nevada Residents
Nevada residents have the right to opt out of the sale of certain Personal Information under Nevada Revised Statutes Chapter 603A. We do not sell Personal Information as defined under Nevada law. If you have questions, contact privacy@seefirstlight.com.
19. Canadian Residents
If you are in Canada, we process your Personal Information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial laws including Quebec's Law 25. Canadian residents have rights to access, correct, and withdraw consent. Contact privacy@seefirstlight.com to exercise these rights.
20. Biometric Information Disclosure (Illinois, Texas, Washington)
We collect voice recordings as part of the Service, and we create transcripts and sentiment/emotion inferences from them. We do not use voice recordings to identify any individual, and we do not create or store voiceprints, voice templates, or other biometric identifiers for identification purposes.
If voice recordings nonetheless constitute "biometric information," "biometric identifiers," or similar categories under your state's law (including Illinois' Biometric Information Privacy Act, Texas' Capture or Use of Biometric Identifier Act, and Washington's biometric statute), you consent by using the Service and submitting voice recordings. You may withdraw consent by switching voice note storage to "transcript only" in settings, deleting existing recordings, or deleting your account. [ATTORNEY REVIEW: BIPA requires specific written consent and a publicly-available schedule; confirm whether current posture is adequate or whether additional consent mechanics are required]
21. Apple HealthKit Disclosure
If you connect Apple Health, we collect the health and fitness data types you authorize. In accordance with Apple's HealthKit Framework Agreement and App Review Guideline 5.1.3:
- We use HealthKit data only to provide you with First Light's health and fitness features (daily prompts, pattern observations, weekly reports, morning synthesis)
- We do not use HealthKit data for advertising or marketing
- We do not sell HealthKit data
- We do not disclose HealthKit data to any third party except our service providers (Terra, which normalizes the data, and Anthropic, Supabase, and similar) that process it on our behalf to provide the Service, under contractual restrictions prohibiting their use of the data for other purposes
- We do not use HealthKit data to derive information for purposes beyond providing the Service
You can revoke our access to HealthKit data at any time in the Apple Health app under Sources → First Light.
22. Contact Us
For questions, concerns, or requests:
- Privacy requests: privacy@seefirstlight.com
- Security issues: legal@seefirstlight.com
- General support: questions@seefirstlight.com
Legacy Build Inc. 30 N Gould St, Ste R, Sheridan, WY 82801
Version 1.0 — effective May 29, 2026. © Legacy Build Inc.