First Light — Privacy Policy
Version: 1.7 Effective Date: September 15, 2026 Originally Effective: August 1, 2026 Last Updated: September 15, 2026
1. Introduction
This Privacy Policy describes how Legacy Build Inc. ("Legacy Build Inc.," "we," "us," or "our") collects, uses, shares, and protects information in connection with the First Light service (the "Service").
First Light is a consumer wellness tool for self-reflection and personal pattern awareness. Because the Service works with health-adjacent information (your check-ins, voice notes, and optional health and wearable data), we treat privacy as a core feature, not an afterthought.
This Privacy Policy applies to information we collect through:
- The First Light website and web application
- The First Light iOS application (when available)
- The First Light Chrome extension
- Any related communications or services we provide
This Privacy Policy does not apply to third-party services you choose to connect (such as Apple Health, Google Health Connect, Oura, WHOOP, or Apple Watch) which are governed by those providers' own privacy policies.
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
Additional information for specific jurisdictions appears in Sections 14–19 at the end of this Policy:
- Section 14 — Washington residents (My Health My Data Act)
- Section 15 — California residents (CCPA/CPRA)
- Section 16 — EU, EEA, UK, and Swiss residents (GDPR)
- Section 17 — Other U.S. state residents
- Section 18 — Nevada residents
- Section 19 — Canadian residents
2. Information We Collect
We collect the following categories of information.
2.1 Information You Provide Directly
Account information: Name or display name, email address, date of birth (optional — so First Light can notice your birthday, and so the AI knows your age when it writes to you; we do not use it to verify your age), password hash, profile preferences. If you choose to capture check-ins by text message or receive text-message reminders, we also collect and store the phone number you link to your account.
Text messages (SMS): If you opt in to text messages from First Light, message and data rates may apply, and message frequency varies with your settings and how often you check in. You can reply STOP to any message to opt out, or HELP for help. Your phone number and your text-message opt-in consent are not shared with third parties or affiliates for marketing purposes.
Subscription and billing information: Billing name, billing address, subscription tier, purchase history. Payment card numbers are collected and stored by Stripe, not by Legacy Build Inc.. We receive only a tokenized reference, the last four digits of the card, the card brand, and the expiration date.
User Content: Everything you record through the Service, including:
- Text-based check-ins and entries
- Voice recordings and their transcripts
- Responses to structured prompts and tags
- Settings, preferences, and selections
- Feedback and correspondence with us
You can submit check-ins inside the app, through our Chrome extension, or — if you enable those capture channels — by sending a text message (SMS) or email to the Service. Content you send this way becomes User Content.
Communications: Emails, support requests, survey responses.
2.2 Health and Wellness Information
This is the most sensitive category of information we handle.
You can connect health and wearable data two ways: (1) on-device sources — Apple Health on iOS or Google Health Connect on Android — which the First Light mobile app reads on your device; and (2) server-side wearables such as Oura, WHOOP, and Fitbit, which you link directly. In both cases the data is received and normalized by Open Wearables, health-data software that we run ourselves rather than a third-party aggregation service. No separate aggregation company receives your health data before we do. The service runs on hosting provided by Railway, which stores it for us in the same way our other infrastructure providers do (Section 5.1). The metrics we collect are:
- Sleep duration and quality
- Heart rate variability (HRV)
- Resting heart rate
- Activity and step count
- Respiratory rate
- Recovery scores
We import history, not only readings made from that day forward. When you link a server-side wearable, we ask for readings that already exist in that device's account — up to three years of them — at the moment you connect, so First Light can tell what is typical for you straight away instead of spending weeks observing you first. These are the same metrics listed above, and the rest of this Policy applies to them identically. How far back we actually receive is set by the device provider, not by us: some permit the full three years, others limit us to as little as thirty days. On-device sources (Apple Health, Google Health Connect) provide no history this way — their data lives on your phone, so those sources begin from the day you connect.
You control which data types we can access, and you can revoke access at any time — in the Apple Health or Google Health Connect permissions for on-device sources, or by disconnecting the wearable in First Light's Settings for server-side sources. Disconnecting stops new readings; it does not delete readings we already hold, including imported history. To have those deleted, delete your account in Settings or make a deletion request (Section 8).
Your check-ins and voice notes may also contain health-adjacent information you choose to share — for example, descriptions of sleep, mood, stress, or symptoms. We treat this content as "Consumer Health Data" as defined by Washington's My Health My Data Act.
2.3 Information We Derive
We create derived information from the above, including:
- AI-generated outputs (prompts, pattern observations, weekly insight reports, morning synthesis messages, song recommendations)
- Detected patterns (e.g., entities and topics mentioned in entries)
- Sentiment and emotional state inferences from voice and text
- Correlations between entries and health metrics
- Depth scores, confidence scores, and similar internal metrics
- Vector embeddings of User Content (used for pattern recognition and retrieval)
2.4 Information Collected Automatically
When you use the Service, we automatically collect:
- Device information: Device type, operating system, browser type, language, time zone
- Usage information: Features used, screens viewed, actions taken, timestamps, session duration
- Log data: IP address, access times, error logs, referring pages
- Approximate location: The city, region, and country associated with your device's internet (IP) address, recorded with each check-in you make from the web app or browser extension, and used to give the patterns and insights we generate context about where you were. We also derive an approximate city/region from your device's time zone setting to select time-of-day background imagery. We do not collect precise (GPS) coordinates, and we never ask your browser or device for location permission. Check-ins you send by text message or email carry no location, because those reach us through our messaging providers rather than from your own device.
2.5 Cookies and Similar Technologies
We set cookies to keep you signed in, maintain your session, and carry you through checkout, plus one first-party cookie on our marketing site that remembers which of our ads brought you here. We do not use third-party advertising cookies, tracking pixels, or advertising SDKs anywhere, including on our marketing pages, and nothing about your visit is sent to any advertising platform. Section 11 lists every cookie and everything we keep on your device.
2.6 Information From Third Parties
- Payment processors (Stripe): Transaction confirmations, billing status, fraud indicators
- AI providers (Anthropic, OpenAI): Operational metadata, error information
- Analytics providers: Vercel Web Analytics (marketing pages only) — aggregate visit counts; cookieless, and it does not build profiles of individual visitors. PostHog (inside the Service) — counts of four things happening, recorded against an account number rather than a name; see Section 5.1.
- Error monitoring (Sentry): Technical fault reports — the name of the programming fault and where in our code it happened. See Section 5.1 for what is deliberately stripped out first.
- Health data collection and normalization (our own Open Wearables service, hosted by Railway, receiving from Apple Health, Google Health Connect, and connected wearables such as Oura, WHOOP, Fitbit): the metrics you authorize
We do not receive information about you from advertising platforms, data brokers, or lead vendors.
2.7 Information We Do Not Collect
We do not collect:
- Social Security numbers or government ID numbers
- Precise geolocation (GPS) coordinates
- Contents of your other apps, files, or communications
- Information from minors under 18 (knowingly)
- Full payment card numbers, CVVs, or bank account details (held only by Stripe)
3. How We Use Information
We use the information we collect to:
3.1 Provide and Operate the Service
- Create and manage your account
- Process your check-ins, voice notes, and health data
- Generate AI Outputs (prompts, pattern observations, weekly reports)
- Detect patterns in your entries and health data
- Sync data across the web, iOS, and Chrome extension
- Transcribe voice recordings
3.2 Process Payments and Subscriptions
- Charge subscription fees
- Process refunds
- Prevent fraud
- Handle billing inquiries
3.3 Communicate With You
- Send transactional messages (billing, security, legal notices, service availability)
- Send service communications (pattern alerts, weekly reports, notifications — per your preferences)
- Respond to support requests
- Send marketing communications only if you have opted in (and you may unsubscribe at any time)
3.4 Maintain Safety and Security
- Authenticate accounts
- Detect and prevent fraud, abuse, and unauthorized access
- Display crisis resources when specific keywords or patterns are detected (see our Terms of Service §4.5 — this feature is not a crisis monitoring service and we do not guarantee detection)
3.5 Improve the Service
- Understand how users interact with the Service
- Diagnose bugs and improve performance
- Develop new features
- Conduct internal analytics on aggregated or de-identified data
3.6 Legal and Compliance
- Comply with laws, court orders, subpoenas, and legal process
- Enforce our Terms of Service
- Protect the rights, property, and safety of Legacy Build Inc., our users, and others
3.7 Uses We Do Not Engage In
We do not:
- Sell your Personal Information or Consumer Health Data.
- Share your Personal Information or Consumer Health Data for cross-context behavioral advertising.
- Use your User Content, Consumer Health Data, or AI Outputs to train artificial intelligence or machine learning models.
- Use data from Apple HealthKit for any purpose other than providing you the Service's health-related features.
- Use Consumer Health Data for advertising of any kind.
4. Legal Basis for Processing (EU/UK Residents)
If you are in the EU, EEA, UK, or Switzerland, we process your Personal Data on the following legal bases under GDPR:
| Processing Activity | Legal Basis |
|---|---|
| Account creation, Service delivery, billing | Performance of a contract (Art. 6(1)(b)) |
| Marketing communications | Consent (Art. 6(1)(a)) — you may withdraw at any time |
| Security, fraud prevention, product improvement | Legitimate interests (Art. 6(1)(f)) |
| Processing health data | Explicit consent (Art. 9(2)(a)) |
| Processing voice recordings (biometric) | Explicit consent (Art. 9(2)(a)) |
| Legal obligations (e.g., tax records) | Legal obligation (Art. 6(1)(c)) |
You can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
5. How We Share Information
We share information only in the limited ways described below. We do not sell your Personal Information.
5.1 Service Providers
We share information with third-party service providers who perform services on our behalf, under contractual obligations of confidentiality and data protection:
| Provider | Purpose | Categories Shared |
|---|---|---|
| Anthropic | AI processing for generating Outputs | User Content (entries, transcripts, context), derived metadata |
| Stripe | Payment processing | Billing information, transaction data |
| Supabase | Database and infrastructure hosting | All service data |
| OpenAI | Voice-to-text transcription (Whisper) and text embeddings that power search | Voice recordings; the text of your check-ins and entries |
| Resend | Transactional and service emails | Email address, message content |
| Twilio | Inbound text-message capture and outbound SMS notifications/reminders | Phone number, message content |
| Mailgun | Inbound email capture ("email a thought") | Email address, message content |
| Railway | Hosting for the Open Wearables service we run — the software is ours; Railway provides the servers and database it runs on | Connected health & wearable metrics |
| Apple (HealthKit) | On-device health data access (via the mobile app) | Per your HealthKit authorizations |
| Vercel | Website and application hosting; cookieless aggregate visit counts on marketing pages | Standard server logs; aggregate page-view counts (no cookies, no visitor profiles) |
| PostHog (EU region) | Product analytics — how often the Service is used, so we can tell whether it is working | An account number, and four event types (a check-in was saved, a chat message was sent, a weekly report was opened, onboarding finished). The only details attached are: which channel a check-in arrived by; whether it was roughly a line, a paragraph, or a page; and whether a feeling was tapped, yes or no. No entry text, no email address, no name, and no IP address. |
| Sentry | Error monitoring — telling us when something breaks | The programming fault's name (for example TypeError), the file and line in our own code, and a six-character code standing in for the error message. Not the error message itself, not the contents of any request, and no identifier for you. |
One lookup that is not in the table. When First Light recommends a song in your weekly report, our server asks Apple's public iTunes Search service for that song's album artwork. Apple receives the song's title and artist and nothing else — no account number, nothing you wrote, and the request comes from our server rather than from your device. Apple is not a processor of your data; it sees the name of a song.
We use no advertising subprocessors and no cross-site trackers. There is no Google Analytics, Meta Pixel, or Reddit Pixel in this list because we do not use them, anywhere.
About the two providers that measure the Service itself. PostHog and Sentry are the only providers here that exist to watch how First Light behaves rather than to deliver something you asked for, so it is worth being exact about what they are not.
- PostHog never runs in your browser inside the Service; it is called only from our own servers. Sentry is different, because its job is to catch a crash in the very page you are looking at: it runs in the web app and in the browser extension, and its reports leave your browser directly. Those reports follow the same stripped-down rules described below, and each one carries an instruction to Sentry not to record the internet address it arrived from. PostHog's browser library — the one that offers session recording, which would have meant filming somebody writing in their journal — is not merely switched off; it is not installed, and an automated check in our codebase fails the build if anyone adds it.
- PostHog is told an account number and never an email address, a name, or an IP address. It cannot see anything you write.
- Sentry receives a rebuilt fault report rather than a filtered one. We construct the report from a fixed list of technical fields, so anything a future software update might attach arrives in a field we do not copy and is dropped. Error messages are replaced by a six-character code, because an error message can quote the very text that caused it.
- Neither is used for advertising, and neither receives data about you from anyone else.
- On training. Sentry excludes customer data from model training by default and we have not opted in. PostHog's terms are the other way round: they permit PostHog to use de-identified, aggregated customer content to improve its own products, including machine-learning models, unless a customer opts out. We have opted out. What PostHog holds about you could not identify you in any case — an account number and four event names — but we would rather exercise the choice than rely on that.
Anthropic, Stripe, Supabase, Railway, OpenAI, Resend, Twilio, Mailgun, Vercel, PostHog, and Sentry each process your data only to provide services to us, under contractual restrictions. OpenAI receives the text of your entries, chat messages, and search queries (to create the embeddings that power search) as well as your voice recordings (to create transcripts). Under OpenAI's standard API terms, this data is not used to train its models and is retained only transiently for abuse-monitoring purposes before deletion.
5.2 Legal and Compliance
We may disclose information when we believe in good faith that disclosure is necessary to:
- Comply with a law, regulation, legal process, or government request
- Enforce our Terms of Service
- Protect the rights, property, or safety of Legacy Build Inc., our users, or others
- Detect, prevent, or address fraud, security, or technical issues
Where legally permitted, we will notify you of law enforcement requests before disclosure, unless we are legally prohibited or believe doing so would endanger a person.
5.3 Business Transfers
If Legacy Build Inc. is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will require the successor to honor this Privacy Policy, or we will notify you and provide choices (including deletion) before your data is subject to a different privacy policy.
5.4 With Your Consent
We may share information with your consent or at your direction (for example, if you choose to export and share a weekly insight report).
5.5 Aggregated or De-identified Information
We may create and use aggregated or de-identified information that cannot reasonably be used to identify you. We use this information for:
- Internal analytics and Service improvement
- Evaluating feature performance
- Marketing claims in anonymized form (e.g., "a majority of users observed a pattern within their first three weeks")
We do not sell aggregated or de-identified Consumer Health Data, and we do not license or share such data with external research partners without additional explicit consent from affected users.
5.6 What We Do Not Do
We do not:
- Sell your Personal Information or Consumer Health Data to any third party
- Share your Personal Information or Consumer Health Data for advertising purposes
- Disclose HealthKit data to advertising services or sell HealthKit data for any reason (required by Apple)
- Provide your User Content to researchers or partners without explicit opt-in consent
6. Data Retention
We retain Personal Information only for as long as needed for the purposes described in this Policy.
| Category | Retention |
|---|---|
| Account profile | For the life of your account |
| User Content (entries, transcripts) | For the life of your account, until you delete it |
| Voice recordings (audio files) | Deleted once the recording has been turned into text. We keep the transcript, not the audio. If you turn on "Keep my voice recordings" in settings, audio you record from then on is kept for the life of your account, until you delete the check-in it belongs to, or your account. Turning the setting off again stops us keeping new recordings; it does not remove the ones we kept while it was on. |
| Health data | For the life of your account, until you delete it or disconnect the source |
| Billing and transaction records | 7 years (tax and financial record requirements) |
| Support communications | 3 years from last contact |
| Log and security data | 12 months |
| Backups | Where backup copies are maintained, deleted information is removed or rendered inaccessible according to our documented backup-rotation process. Consumer health data subject to a verified deletion request will not remain in backup systems longer than permitted by applicable law. |
| Aggregated or de-identified data | Indefinitely |
On account deletion: Your User Content and Consumer Health Data are permanently deleted from active systems immediately upon your request — there is no waiting period, and deletion cannot be undone. Before deleting, you can download everything you wrote, using the export tool in Settings: your check-ins, your conversations with First Light, your weekly reports, your voice recordings, your health readings, and the account and consent records that go with them. One thing is not in that download and you can have it by asking — your written answer to "How did you hear about us?" — because it sits in a table our software can only read as an administrator rather than as you. Email privacy@seefirstlight.com and we will send it. The download lists inside itself everything it leaves out, and why. After deletion, the exceptions are (a) aggregated/de-identified data, (b) database backups on the rolling window described above, (c) data we must retain for legal or financial reasons, and (d) limited operational data retained by our service providers on their own schedules, described below.
Deletion at third-party processors: When you delete a check-in or your account, we remove it from our active systems and, where a provider supports programmatic deletion, we trigger it on the provider's side (for example, revoking your wearable connection at the device provider and deleting your Stripe customer record). Some providers retain limited operational data on their own schedules, which we minimize to the least each allows:
- Twilio (text check-in capture): we enable message-body redaction so the content of texts is discarded, and message records are retained for the shortest window Twilio permits — currently 7 days (Twilio's minimum; the window is configurable up to 400 days).
- Mailgun (email check-in capture): we set message-content retention to the minimum (disabled), so inbound email content is not stored beyond processing; Mailgun's delivery and event logs persist for up to 30 days per plan.
- Stripe (payments): transaction and payment records are retained by Stripe as required by financial and tax law, even after we delete your customer record.
- Resend (outbound email): delivery logs — recipient address and message metadata, not your entries — are retained on Resend's schedule.
- PostHog (product analytics): deletion is propagated. When you delete your account we instruct PostHog to delete the account number itself and every event recorded against it, and we record whether that instruction succeeded. Nothing is left behind for us to reconnect to you.
- Sentry (error monitoring): there is nothing to delete. Sentry is never told who you are — no account number, no email address, no IP address — so no fault report it holds is connected to you in the first place.
7. How We Protect Information
We use administrative, technical, and physical safeguards designed to protect your information, including:
- Encryption in transit (TLS 1.2 or higher)
- Encryption at rest (for database storage via Supabase)
- Access controls: Role-based access, limited personnel access to production data
- Authentication: Password hashing, session management
- Infrastructure: Reputable cloud hosting with SOC 2 certifications
- Monitoring: Logging and anomaly detection
- Vendor due diligence: Subprocessor agreements and security reviews
No security system is perfect. We cannot guarantee absolute security. If we experience a data breach affecting your information, we will notify you and applicable regulators as required by law, including the FTC Health Breach Notification Rule, state breach notification laws, MHMDA, GDPR, and other applicable regimes.
8. Your Rights and Choices (All Users)
Regardless of where you live, you can:
- Access your information through the Service (account settings, weekly reports, entry history)
- Export your information in a portable format via in-app export tools. The download carries everything you wrote; it lists inside itself the few things it leaves out and how to get them (see Section 6)
- Correct inaccurate information in your account settings
- Delete your account via account settings or by emailing privacy@seefirstlight.com
- Disconnect health data sources via Apple Health / Google Health Connect permissions, or by disconnecting a wearable in Settings
- Opt out of marketing emails via the unsubscribe link in any marketing email
- Control notifications via in-app notification preferences
- Stop us keeping voice recordings by turning off "Keep my voice recordings" in settings (it is off by default, so audio is deleted after transcription unless you have turned it on). Turning the setting off again stops us keeping new recordings; it does not remove the ones we kept while it was on. To remove those, delete the check-ins they belong to, or your account.
Specific state and jurisdiction rights are described in Sections 14–19.
To exercise any right, contact us at privacy@seefirstlight.com. We will verify your identity (typically by confirming the email associated with your account) and respond within the time required by applicable law, generally within 45 days.
9. International Data Transfers
We are based in the United States and process data in the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States.
For users in the EU, EEA, UK, and Switzerland, we rely on the following mechanisms for international transfers:
- Standard Contractual Clauses (SCCs) with our service providers
- UK International Data Transfer Addendum for UK transfers
- Swiss Data Protection Authority-approved mechanisms for Swiss transfers
You may request a copy of the applicable transfer mechanism by contacting privacy@seefirstlight.com.
10. Children's Privacy
The Service is not directed to, intended for, or designed for use by anyone under 18. We do not knowingly collect information from anyone under 18. If we learn we have collected information from a person under 18, we will delete it promptly.
If you are a parent or guardian and believe your child under 18 has provided information to the Service, contact us at privacy@seefirstlight.com.
11. Cookies and Similar Technologies
11.1 What We Use
Every cookie we set is our own, and nothing we keep on your device is shared with anyone. We run no third-party advertising cookies, no tracking pixels, and no cross-site trackers, on our marketing pages or inside the Service. All but one of the items below are strictly necessary to deliver something you asked for; the exception is the attribution cookie, explained where it is listed.
The complete list:
- Session cookies (marketing site and application): Keep you signed in and maintain your session
- Checkout cookie (marketing site): Remembers that you chose to subscribe so you land on checkout after signing in. Short-lived
- Attribution cookie (marketing site, named
fl_attr): If you arrive from one of our ads, this remembers which campaign brought you, so that if you later sign up we can tell which ads are working. It holds only the campaign labels from the link you clicked — no identifier for you or your device, and nothing that could be joined back to you afterwards. It lasts 30 days, can be read only by our own servers and not by any script in the page, is scoped to seefirstlight.com and its subdomains so it survives the step from the marketing site to the app, is read once when your account is created, and is never sent to any third party — including the ad platform the click came from - Local device storage (application): Things the apps keep on your own device so they can work, none of which goes anywhere but to us:
- Web app: your place in setup if you leave partway through; and the text and feelings of a check-in you are still writing (including one you started before signing in), so a closed tab or a sign-in redirect does not lose it — cleared once you save or discard it
- Browser extension: your sign-in session; when the extension last checked in with us; the location you chose for the new-tab scenery, if you set one; and small notes the new-tab page keeps so it can draw instantly — your display name, the last line it showed you, and which insights and patterns you have already seen
- Mobile app: your sign-in session; check-ins and voice notes you saved while offline, held only until they reach us; and a marker that you have opened the app before
Analytics: On our marketing pages we use a cookieless analytics provider that counts visits in aggregate. It sets no cookies, stores nothing on your device, and does not build a profile of you or follow you across sites. Inside the Service we count four things — a check-in saved, a chat message sent, a weekly report opened, onboarding finished — using PostHog. Those counts are sent from our servers, not from your browser: no cookie is set, nothing is stored on your device, and no script from PostHog ever runs on a page you are looking at. See Section 5.1 for the full list of what is and is not included.
What we do not do: We do not use Google Analytics, the Meta Pixel, the Reddit Pixel, or any comparable advertising or behavioral-tracking technology — anywhere. We do not send purchase, signup, or other conversion events to advertising platforms, whether from your browser or from our servers.
11.2 Your Choices
- You will not see a cookie banner. Every cookie we set is our own. The session and checkout cookies are strictly necessary to deliver a service you asked for, which is the category that does not require consent. The attribution cookie is not strictly necessary, but it holds no identifier for you or your device, is never shared, and cannot follow you to any other site. We would rather remove tracking than ask you to consent to it
- Browser controls: Most browsers let you block or delete cookies. Blocking our session cookie will sign you out
- Global Privacy Control: We do not sell or share Personal Information for cross-context behavioral advertising, so a GPC signal has nothing to opt you out of. Should that ever change, we will honor GPC and update this policy first
- Mobile device settings: iOS offers "Limit Ad Tracking" and similar controls
12. Third-Party Links and Services
The Service may contain links to third-party websites, apps, or services. We are not responsible for the privacy practices of third parties. When you connect a third-party data source (such as Apple Health), that service's own privacy policy governs how it handles your data before it reaches us.
13. Changes to This Privacy Policy
We may update this Privacy Policy. When we do:
- We will update the "Last Updated" date at the top
- For material changes, we will provide at least 30 days' advance notice by email or in-app notification
- For changes that materially expand how we use your Consumer Health Data, we will seek your renewed consent before applying the change to previously collected data
Corrections take effect when we publish them, and every one is logged.
Sometimes a change here corrects something this Policy said inaccurately, rather than changing what we do. Waiting thirty days to publish a correction would mean leaving a statement we already know to be wrong in front of you for thirty more days, which helps nobody. So corrections take effect on publication.
A change is a correction only if it leaves all four of these untouched: what we collect, how we use it, who receives it, and how long we keep it. A change that alters any of them is not a correction and carries the full notice above — and if it widens any of them, the renewed-consent commitment applies as well. Narrowing what we do, or describing it more accurately, is the only thing this paragraph covers.
Every correction is recorded in the Revision History at the end of this Policy, naming what the previous version said and why it was wrong. That record is the check on this paragraph: it is what stops a correction from being made quietly.
Your continued use of the Service after changes take effect constitutes acceptance. If you do not agree to the changes, you may delete your account and export your data.
14. Washington Residents — My Health My Data Act Notice
Washington's My Health My Data Act (MHMDA), RCW 19.373, is addressed in our standalone Consumer Health Data Privacy Policy, which controls for Consumer Health Data of Washington consumers. This section summarizes it; Washington residents and anyone whose Consumer Health Data is collected in Washington should read the standalone policy in addition to the rest of this Privacy Policy.
14.1 What Is Consumer Health Data
MHMDA defines "Consumer Health Data" broadly to include personal information that identifies a consumer's past, present, or future physical or mental health status. In the context of First Light, we treat the following as Consumer Health Data:
- Health data you connect through our own Open Wearables service (from Apple Health, Google Health Connect, and connected wearables such as Oura, WHOOP, Fitbit) — sleep, HRV, resting heart rate, activity, recovery, respiratory rate, and similar
- Content of your check-ins, entries, and voice notes to the extent they describe health status, symptoms, mood, stress, emotions, or mental state
- AI-generated outputs derived from the above (patterns, weekly reports, morning synthesis, pulse prompts)
- Derived metrics (emotional state inferences, sentiment scores, depth scores, confidence scores)
- Any information that could be used to infer a health condition
14.2 Categories of Consumer Health Data We Collect
- Health and wellness metrics from connected devices (through our own Open Wearables service, from Apple Health, Google Health Connect, and connected wearables)
- Self-reported mood, emotional state, and mental state (through check-ins)
- Self-reported physical sensations or symptoms (if you choose to share them)
- Voice recordings and transcripts containing health-related content
- Inferences derived from your entries (emotional state, patterns, sentiment)
14.3 Categories of Sources
- Directly from you (check-ins, voice notes, responses)
- From your devices and health data sources (through our own Open Wearables service, from Apple Health, Google Health Connect, and connected wearables)
- Derived by our Service (AI outputs and inferences)
14.4 Purposes for Collection and Use
- To provide the Service (generate check-in prompts, pattern observations, weekly insights, morning synthesis)
- To operate your account and process payment
- To maintain security and prevent fraud
- To communicate with you about the Service
- To comply with legal obligations
14.5 Categories of Consumer Health Data We Share, and With Whom
| Category | Shared With |
|---|---|
| All Consumer Health Data categories | Anthropic (AI processing, under contractual restrictions) |
| All Consumer Health Data categories | Supabase (infrastructure hosting, under contractual restrictions) |
| Text of check-ins, entries, chat messages, and search queries (for search embeddings); voice recordings (for transcripts) | OpenAI (standard API terms — not used for training; retained only transiently for abuse monitoring, then deleted) |
| Content of check-ins sent by text message; phone number | Twilio (SMS capture and delivery, under contractual restrictions) |
| Content of check-ins sent by email; email address | Mailgun (inbound email capture, under contractual restrictions) |
| Connected health & wearable metrics | Railway (hosting for the Open Wearables service we run, under contractual restrictions) |
| No categories | Advertisers |
| No categories | Data brokers |
| No categories | External research partners (without explicit opt-in consent) |
14.6 We Do Not Sell Consumer Health Data
Legacy Build Inc. does not sell Consumer Health Data as that term is defined in MHMDA. We do not exchange Consumer Health Data for monetary or other valuable consideration to any third party. We will not sell Consumer Health Data without a valid authorization that meets MHMDA's requirements, which we have no plans to seek.
14.7 Your MHMDA Rights
If you are a Washington resident or your Consumer Health Data was collected while you were in Washington, you have the right to:
- Confirm whether we are collecting, sharing, or selling your Consumer Health Data, and to access that data
- Delete your Consumer Health Data
- Withdraw consent to further collection or sharing of your Consumer Health Data
- Appeal the denial of any request
14.8 How to Exercise MHMDA Rights
Email privacy@seefirstlight.com with the subject line "Washington Consumer Health Data Request" and describe which right you wish to exercise. We will:
- Verify your identity (typically via your account email)
- Respond within 45 days, extendable by an additional 45 days when reasonably necessary
- Delete your Consumer Health Data from our records, from third parties that processed it on our behalf, and request deletion by affiliates (where applicable)
14.9 Consent
Before we collect Consumer Health Data beyond what is strictly necessary to provide the Service you requested, we will obtain your consent. Before we share Consumer Health Data beyond what is strictly necessary, we will obtain separate consent.
14.10 Appeal
If we deny your request, you may appeal by replying to the denial email with "Appeal" in the subject line. We will respond within 45 days. If your appeal is denied, you may contact the Washington Attorney General at https://www.atg.wa.gov/.
14.11 Geofencing
We do not use geofencing around any in-person healthcare facility to identify, track, collect data from, or send notifications to consumers regarding their Consumer Health Data.
15. California Residents — CCPA/CPRA Notice
This section provides information required by the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA").
15.1 Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of Personal Information:
| CCPA Category | Examples | Sources | Purposes |
|---|---|---|---|
| A. Identifiers | Name, email, IP address | You, devices | Service delivery, security |
| B. California customer records | Name, billing info | You, Stripe | Billing, Service delivery |
| C. Protected classifications | Age (from your optional date of birth) | You | Service delivery (noticing your birthday; giving the AI your age as context) |
| D. Commercial information | Subscription history | Stripe | Billing |
| F. Internet activity | Usage, device info | Devices | Service delivery, analytics |
| G. Geolocation | Approximate (IP-based): city, region, country. No GPS | Devices | Service delivery, security and fraud prevention |
| H. Audio | Voice recordings | You | Service delivery |
| I. Professional info | Not collected | — | — |
| J. Education info | Not collected | — | — |
| K. Inferences | Emotional state and patterns | Derived | Service delivery |
| Sensitive Personal Information | Health data, Consumer Health Data, voice recordings, account credentials | You, devices | Service delivery |
15.2 Sale or Sharing of Personal Information
We do not "sell" or "share" Personal Information as those terms are defined under CCPA. There are no exceptions to this.
We run no advertising pixels or tracking technologies on any surface, and we transmit no conversion events — purchases, signups, or otherwise — to advertising platforms by any method, including server-to-server. We do not upload customer lists to advertising platforms or create audiences from them.
Because we do not sell or share Personal Information, there is nothing for a "Do Not Sell or Share" request or a Global Privacy Control signal to opt you out of.
15.3 Use of Sensitive Personal Information
We use Sensitive Personal Information (health data, voice recordings, account credentials) only for the purposes specified in California Civil Code §1798.121(a) — to provide the Service you requested, to prevent fraud, to ensure security, and to comply with law. The only inferences we draw from it — the emotional-state and pattern observations described in Section 2.3 — are made to provide the Service you requested, and for nothing else.
We do not use Sensitive Personal Information for advertising, for profiling beyond the Service, or for any other purpose a limitation request would restrict. Because our use is confined to purposes permitted under §1798.121(d) and the CCPA regulations, we are not required to offer a separate "Limit the Use of My Sensitive Personal Information" mechanism. If you ask us to limit it anyway, we will honor the request.
15.4 California Rights
You have the right to:
- Know what Personal Information we collect, use, disclose, and sell/share
- Delete your Personal Information (subject to limited exceptions)
- Correct inaccurate Personal Information
- Opt out of "sale" and "sharing" (for the marketing pages; we don't sell or share elsewhere)
- Limit use of Sensitive Personal Information (as described above)
- Non-discrimination for exercising your rights
- Authorize an agent to act on your behalf
15.5 How to Exercise California Rights
Email privacy@seefirstlight.com with "California Privacy Request" in the subject line. We may need to verify your identity. Authorized agents must provide written authorization.
15.6 California Shine the Light
California Civil Code §1798.83 permits California residents to request information about disclosures of Personal Information to third parties for direct marketing. We do not disclose Personal Information to third parties for their direct marketing purposes.
15.7 Metrics
16. EU, EEA, UK, and Swiss Residents — GDPR Notice
16.1 Controller
Legacy Build Inc. is the controller of your Personal Data.
Legacy Build Inc. 30 N Gould St, Ste R, Sheridan, WY 82801 Email: privacy@seefirstlight.com
16.2 EU Representative
First Light is offered to United States residents only at launch and does not target the EU/EEA. Before offering the Service to EU/EEA residents or monitoring their behavior, we will appoint an EU Representative under GDPR Article 27 and publish their contact details here.
16.3 UK Representative
First Light is offered to United States residents only at launch and does not target the UK. Before offering the Service to UK residents, we will appoint a UK Representative under UK GDPR Article 27 and publish their contact details here.
16.4 Data Protection Officer
A DPO is not currently required under GDPR Art. 37 based on our scale and processing profile.
16.5 Your GDPR Rights
You have the right to:
- Access the Personal Data we hold about you
- Rectify inaccurate Personal Data
- Erase your Personal Data ("right to be forgotten")
- Restrict processing
- Data portability — receive your data in a portable format and transmit it to another controller
- Object to processing based on legitimate interests or for direct marketing
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with your local data protection authority
To exercise any right, contact privacy@seefirstlight.com. We will respond within 30 days (extendable to 90 days for complex requests).
16.6 Automated Decision-Making
AI-generated outputs from the Service — prompts, pattern observations, weekly insight reports — are suggestions for your reflection. They produce no legal or similarly significant effects and are not automated decisions within the meaning of GDPR Art. 22.
The one automated check the Service runs on your words is the crisis check described in Section 3.4 and in Section 4.5 of our Terms of Service: when a check-in or a message matches a list of crisis-related terms, the Service shows you where to get help. It changes nothing else. It does not affect your account status, what you are charged, your eligibility, or your access to any part of the Service; it sets no flag on your account, and the only record of it is the reply itself, which stays in your conversation like any other message; no person reads your entries for it; no one is notified when it happens; and we do not contact anyone.
If you believe something about how the Service treats you was decided by software rather than offered as a suggestion, write to privacy@seefirstlight.com and a person will look at what happened and explain it. That review is done by a person, not an automated reply.
16.7 International Transfers
Your Personal Data is transferred to the United States. We rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK transfers) with our service providers.
17. Other U.S. State Residents
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Florida, Iowa, Indiana, Tennessee, New Jersey, New Hampshire, Nebraska, Minnesota, Rhode Island, Maryland, and Kentucky have rights substantially similar to the California rights described in Section 15 under their respective state privacy laws, which may include:
- The right to access Personal Data
- The right to delete Personal Data
- The right to correct Personal Data
- The right to data portability
- The right to opt out of targeted advertising, sale, and certain profiling
- The right to appeal
To exercise any right, contact privacy@seefirstlight.com with the subject line "State Privacy Request — [Your State]." We will respond within the time required by your state's law, generally 45 days.
If we deny your request, you may appeal by replying to the denial email. If your appeal is denied, you may contact your state Attorney General.
18. Nevada Residents
Nevada residents have the right to opt out of the sale of certain Personal Information under Nevada Revised Statutes Chapter 603A. We do not sell Personal Information as defined under Nevada law. If you have questions, contact privacy@seefirstlight.com.
19. Canadian Residents
If you are in Canada, we process your Personal Information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial laws including Quebec's Law 25. Canadian residents have rights to access, correct, and withdraw consent. Contact privacy@seefirstlight.com to exercise these rights.
20. Biometric Information Disclosure (Illinois, Texas, Washington)
We collect voice recordings as part of the Service, and we create transcripts and sentiment/emotion inferences from them. We do not use voice recordings to identify any individual, and we do not create or store voiceprints, voice templates, or other biometric identifiers for identification purposes.
If voice recordings nonetheless constitute "biometric information," "biometric identifiers," or similar categories under your state's law (including Illinois' Biometric Information Privacy Act, Texas' Capture or Use of Biometric Identifier Act, and Washington's biometric statute), you consent by using the Service and submitting voice recordings. You may withdraw consent by turning off "Keep my voice recordings" in settings (audio is deleted after transcription unless you have turned it on), deleting the check-ins that hold existing recordings, or deleting your account.
21. Apple HealthKit Disclosure
If you connect Apple Health, we collect the health and fitness data types you authorize. In accordance with Apple's HealthKit Framework Agreement and App Review Guideline 5.1.3:
- We use HealthKit data only to provide you with First Light's health and fitness features (daily prompts, pattern observations, weekly reports, morning synthesis)
- We do not use HealthKit data for advertising or marketing
- We do not sell HealthKit data
- We do not disclose HealthKit data to any third party except our service providers (Railway, which hosts the Open Wearables service that normalizes the data, and Anthropic, Supabase, and similar) that process it on our behalf to provide the Service, under contractual restrictions prohibiting their use of the data for other purposes
- We do not use HealthKit data to derive information for purposes beyond providing the Service
You can revoke our access to HealthKit data at any time in the Apple Health app under Sources → First Light.
22. Contact Us
For questions, concerns, or requests:
- Privacy requests: privacy@seefirstlight.com
- Security issues: legal@seefirstlight.com
- General support: questions@seefirstlight.com
Legacy Build Inc. 30 N Gould St, Ste R, Sheridan, WY 82801
Revision History
Version 1.7 — effective September 15, 2026
Quiet Mode has been removed from the product, and so from this Policy.
Version 1.5 described a feature that, when a check-in or a conversation matched a list of crisis-related terms, set a flag on your account and made the following week quieter. To exist lawfully it needed its own consent, its own retention rule, its own place in your data download, and disclosures in three documents. We decided that a change of tone for a week was not worth any of that, and removed the feature and the flag entirely on September 15, 2026. The table that held the flag and the consent record for it have been deleted from our systems.
What has gone from this Policy: the quiet-mode bullet in Section 2.3; Section 2.8 in full; the Quiet Mode row in the retention table and the mention in the download description in Section 6; the two Quiet Mode mentions in the California categories table in Section 15.1 and the two in Section 15.3; and the Quiet Mode paragraphs in Section 16.6, which now describes the one automated check that remains.
What has not changed. The crisis check itself. When your words match the list, the Service shows you where to get help, exactly as before (Section 3.4; Terms Section 4.5), and Settings still carries a permanent link to a directory of free crisis lines. That check sets no flag, keeps no record beyond the reply in your conversation, tells no one, and contacts no one.
How this version is classified under the change-notice commitment. A correction paired with a narrowing: it removes a processing activity and the data it produced, and it widens nothing about what we collect, how we use it, who receives it, or how long we keep it. No renewed consent is required. No advance notice was owed in any case: First Light has no users yet, so there is nobody whose agreement predates this version.
Version 1.6 — effective September 15, 2026
Section 2.1 said nothing about text messages beyond the phone number itself.
It now carries a short Text messages (SMS) paragraph: message and data rates may apply; message frequency varies with your settings and how often you check in; reply STOP to opt out or HELP for help; and your phone number and your opt-in consent are not shared with third parties or affiliates for marketing purposes. That last sentence has always been how First Light works (Section 5 already says every processor works only on our behalf, and Section 15.2 that we do not sell or share personal information), but the US toll-free messaging registry requires it to be stated in so many words, here and in the Terms, before a business number may text anyone at all.
Nothing about what we collect, keep, delete or share has changed.
How this version is classified under the change-notice commitment. A correction: it alters what we say, not what we do, and narrows nothing and widens nothing. No advance notice was owed in any case: First Light has no users yet, so there is nobody whose agreement predates this version.
Version 1.5 — effective September 9, 2026
We were not telling you about a decision our software makes about you.
If a check-in or a conversation mentions self-harm or suicide, our software sets a flag on your account, on its own. For the seven days that follow, the Service behaves differently toward you: fewer prompts, no daily question, a gentler reply, no patterns or signals surfaced, no reminders. It has worked this way since the Service launched. Nothing in the product told you it had happened, and nothing in this Policy described it. It was covered only by the general statement that we derive insights from your entries — which describes something we show you, not something we decide about you.
Two external law firms independently identified this as the most significant gap in our disclosures. This version closes it, alongside changes to the product that shipped at the same time:
- New Section 2.8 describes Quiet Mode in full: what sets it off, what it changes, what it never changes, that it is not a diagnosis, that no person reviews it, and how to see it and stop it.
- Section 16.6 previously said, without qualification, that we do not use personal data for automated decision-making. It now names Quiet Mode as something our software sets rather than suggests, states plainly that it does not affect your account, price, eligibility or access, and gives you three things regardless: you can see it, you can switch it off, and you can ask a person to review it — someone able to examine what happened, explain it, and turn it off, not an automated reply.
- Section 15.1 lists it in both places it belongs in the California table: as an inference, and as sensitive personal information, because an inference about mental health is sensitive in its own right. Section 15.3 names it among the inferences we draw.
- Section 2.3 names it alongside the other things we derive.
In the product, at the same time: while Quiet Mode is on, your dashboard says so and Settings explains it and offers a switch that turns it off — and turning it off keeps it off for the rest of that week. An internal severity score, which was recorded and never used for anything, has been removed entirely.
Section 6 also stops overstating the download. It said you could "export a complete copy of your data". The download is thorough, and it now includes your Quiet Mode history in plain language, but it is not literally everything we hold: your written answer to "How did you hear about us?" sits in a table our software can only read as an administrator, and is available by emailing privacy@seefirstlight.com. Section 6 now describes what the download actually contains; Section 8's export bullet points at it. The download has always printed its own list of what it leaves out — the Policy did not.
In the same pass the download also gained which wearable you linked and when, along with the identifier that provider knows you by. Previously a linked device that had not yet sent any readings left no trace in your download at all.
Nothing about what we collect, keep, delete or share has changed. Quiet Mode is not new; describing it is.
No advance notice was owed for this change: First Light has no users yet, so there is nobody whose agreement predates it. Once the Service has users, material changes carry thirty days' notice as described in Section 13.
How this version is classified under the change-notice commitment. Most of what changed here is a correction as newly defined: it alters what we say, not what we do. The exceptions are three, and all three narrow what we do rather than widen it — Quiet Mode now requires your consent before it can happen at all, its record is now deleted rather than kept, and an internal score was removed. Nothing here expands what we collect, how we use it, who receives it, or how long we keep it, so no renewed consent is required. And no advance notice was owed in any case: First Light has no users, so there is nobody whose agreement predates this version.
Version 1.4 — effective September 7, 2026
We replaced the company that used to sit between your wearable and us.
Until now, health data from a connected device reached us through Terra, a separate health-data aggregation company. Terra received your readings, normalized them, and passed them on. We have replaced Terra with Open Wearables — health-data software that we run ourselves. The practical effect is that one fewer company receives your health data: what used to be an outside service is now software under our own control, and no aggregation provider sits in front of us any more.
The software runs on servers provided by Railway, which is now listed as a service provider in the same way our other hosting and database providers are. Railway stores the data for us; it is not a health-data company and does nothing with it.
Nothing about what we collect, how long we keep it, or what we do with it has changed. The list of who receives your health data (Sections 5.1 and 14.5) is shorter as a result, not longer.
No advance notice was owed for this change: First Light has no users yet, so there is nobody whose agreement predates it. Once the Service has users, material changes carry thirty days' notice as described in Section 13.
Version 1.3 — effective September 5, 2026
An audit compared every statement in this Policy against the software as it runs. Thirteen statements across our published policies were found to describe something the software does not do, or to leave out something it does. This version corrects the ones in this Policy. Nothing here changes what we collect; it changes what we say about it, to match.
- An attribution cookie we had not listed. Sections 2.5 and 11 said we set strictly necessary cookies only, and listed them. That was not the whole list: since August 2026 our marketing site has set a first-party cookie,
fl_attr, that remembers which of our ads brought a visitor, so that if they later sign up we can tell which ads work. It holds only the campaign labels from the link they clicked, no identifier for the person or device, lasts 30 days, is readable only by our own servers, and is never sent to anyone — including the ad platform. Section 11 now lists it and says all of that; Section 2.5 and Section 11.2 no longer claim that every cookie is strictly necessary. - What the apps keep on your device. Section 11's "complete list" named one item of device storage and there are more: the check-in you are still writing (web), your sign-in session and the new-tab page's small caches (extension), and offline check-ins waiting to be sent (mobile). All are listed now, with what each is for. None of it leaves your device except to reach us.
- Sentry runs in your browser. Section 5.1 said that neither of the two providers that measure the Service runs in your browser. That is true of PostHog and was never true of Sentry, whose job is to catch a crash in the page you are looking at. Corrected: Sentry runs in the web app and the extension, its reports leave your browser directly under the same stripped-down rules, and each report instructs Sentry not to record the internet address it arrived from.
- A song lookup we had not mentioned. When the weekly report recommends a song, our server asks Apple's public iTunes Search service for the album artwork, sending the song's title and artist and nothing about you. Section 5.1 now says so.
- Date of birth. Section 2.1 said we collect your date of birth "to verify 18+", and the California table in Section 15.1 said the same. We do not verify age with it, and it is optional: it lets First Light notice your birthday and tells the AI your age when it writes to you. Both places now say that.
- Firebase removed. Section 5.1 named Firebase Cloud Messaging as receiving push tokens. Nothing in the software sends anything to Firebase; web push goes through your browser's own push service and mobile reminders are set locally on your phone. A processor that receives nothing has been removed from the list.
- Turning off "Keep my voice recordings." Section 6 said kept audio is retained until you turn the setting back off, which reads as though turning it off removes the recordings. It does not. Turning the setting off stops us keeping new recordings; the ones kept while it was on stay until you delete the check-ins they belong to, or your account. Sections 6 and 8 now say so. Section 20 also referred to a "transcript only" setting that does not exist; it now names the real one.
- Inferences from sensitive information. Section 15.3 said we do not use Sensitive Personal Information for inferences about characteristics, while Section 2.3 has always said we infer emotional state from what you write and say. The two now agree: those inferences are made to provide the Service you requested, and for nothing else.
On the 30 days' notice promised in Section 13. No notice was given for these changes, and none was owed, for the same reason recorded under Versions 1.1 and 1.2: First Light still has no users. The only accounts in existence belong to the operator, testing the Service before launch, so there is no one to notify and no previously collected data to which a change could be applied. We are recording that here rather than leaving it to be inferred. The Section 13 commitment stands unchanged and applies in full from the first real user onward.
Version 1.2 — effective September 2, 2026
- We import history when you connect a wearable, and now we say so. Section 2.2 previously listed which metrics a connected device contributes and was silent on how far back. That was accurate while First Light only ever received readings a device made after you linked it. It stopped being accurate when we began requesting up to three years of readings that already exist in the device's account at the moment you connect. The metrics collected have not changed; the reach of the collection has. Section 2.2 now states the three-year request, that the device provider — not us — decides how much of it we actually receive, and that on-device sources (Apple Health, Google Health Connect) contribute no history at all.
- What disconnecting does, and does not do. Section 2.2 now says plainly that disconnecting a wearable stops new readings but does not delete readings we already hold, and points to the deletion right in Section 8. This was already true and already governed by that section; it was not stated where somebody deciding whether to disconnect would read it.
On the 30 days' notice promised in Section 13. No notice was given for this change, and none was owed, for the same reason recorded under Version 1.1: First Light still has no users. The only accounts in existence belong to the operator, testing the Service before launch, so there is no one to notify and no previously collected data to which this change could be applied — nobody has connected a wearable to a First Light account except the operator. We are recording that here rather than leaving it to be inferred. The Section 13 commitment stands unchanged and applies in full from the first real user onward.
Version 1.1 — effective August 28, 2026
Consolidates every change made since Version 1.0 took effect on August 1, 2026:
- Deletion timing. Corrected a promise of up to 30 days to export your data before deletion; deletion is immediate, and the export is available beforehand rather than during a wait.
- IP-based location. The policy said we did not derive location from your IP address, and we had begun doing so. Corrected to describe what actually happens.
- No ad tracking, and so no cookie banner. Stated plainly that we run no advertising or behavioral-tracking technology on any surface, which is why you are never asked to dismiss a cookie notice.
- Two processors we had not named. Added Sentry (error reporting) and PostHog (product analytics) to our disclosures.
On the 30 days' notice promised in Section 13. Section 13 commits us to 30 days' advance notice before a material change takes effect, and to renewed consent before a change that materially expands our use of Consumer Health Data is applied to previously collected data. No such notice was given for the changes above, and none was owed: First Light had no users during this period. The only accounts in existence belonged to the operator, testing the Service before launch, so there was no one to notify. We are recording that here rather than leaving it to be inferred.
The Section 13 commitment stands unchanged and applies in full to every version from this one onward.
Version 1.0 — effective August 1, 2026. Initial published policy.
Version 1.4 — effective September 7, 2026. © Legacy Build Inc.