FirstForm LLC Privacy Policy
Last updated: 30 July 2026
Draft status: Attorney-review draft, strengthened 2026-07-30 (reinforced the security disclaimer and shared-responsibility language, added an explicit consent/acknowledgment/user-responsibility section, added an express international-transfer consent, and added a limitation-of-liability tie-in to the Terms of Use). This Privacy Policy is not legal advice. It is intentionally broad, conservative, and protective, but a privacy policy protects the company by being accurate and transparent, not by overclaiming: no privacy policy can eliminate all legal risk, and overstating security, compliance, or consent can itself create liability (FTC deception, state consumer-health and privacy laws). The careful hedges here (no HIPAA/encryption/SOC 2 guarantees; "based on inspected code" qualifiers) are deliberate and must be preserved. The business details (contact email admin@firstformllc.com and the FirstForm LLC mailing address) were filled in on 30 July 2026. A licensed-counsel review is still recommended, and every stated practice should continue to match actual production behavior.
1. Who We Are
FirstForm LLC ("FirstForm," "we," "us," or "our") provides Pep Journey, a peptide-first health, wellness, nutrition, training, recovery, biomarker, lab, and personal tracking application, together with related websites, support channels, subscriptions, content, and services that link to this Privacy Policy (collectively, the "App" or "Services").
Contact:
- Company: FirstForm LLC
- Support: admin@firstformllc.com
- Privacy: admin@firstformllc.com
- Legal notices: admin@firstformllc.com
- Mailing address: 30 N Gould St STE N, Sheridan, WY 82801
2. Scope of This Policy
This Privacy Policy explains how we may collect, use, store, disclose, retain, and protect information when you use the Services. It applies to:
- The Pep Journey iOS app.
- In-app tracking, logging, nutrition, peptide, protocol, inventory, lab, biomarker, progress photo, AI, and support features.
- Subscription and purchase flows.
- Optional Apple Health / Apple Watch data import.
- Optional AI coach, meal photo, and lab extraction features.
- Optional food search and barcode lookup.
- Optional Ideas board, feedback, support, and user-generated content features.
- Any FirstForm website or landing page that links to this Policy.
This Policy does not replace the privacy policies of third parties such as Apple, Apple Health, Anthropic or any AI provider, USDA FoodData Central (the food database provider the App currently uses), Neon, email providers, hosting providers, or other vendors.
3. Important Health, Wellness, and Legal Notice
The App may process information that is health-related, wellness-related, nutrition-related, body-image-related, lab-related, peptide-related, or otherwise sensitive.
The App is not a medical device and is not a healthcare provider. The App does not provide medical advice, diagnosis, treatment, prescribing, emergency care, or professional healthcare services. You should consult a qualified licensed clinician before making decisions about your health, medications, supplements, compounds, peptides, injections, nutrition, training, symptoms, labs, or biomarkers.
We do not claim HIPAA compliance unless we separately state that in a signed agreement or official publication. Based on the current inspected implementation, the App does not appear to operate as a HIPAA covered entity or business associate workflow. Other privacy and consumer health data laws may still apply.
4. Local-First Design and Current Backend Posture
Based on the current codebase inspected for this draft, the App is primarily local-first. Many user records are stored on your device. Several sensitive local stores appear to be encrypted at rest using an on-device keychain-held key.
Important limitations:
- Some settings and profile fields appear to be stored in device defaults, not necessarily in the encrypted health-data stores.
- Export files are plain, human-readable JSON after creation unless you separately protect them.
- Optional features may send information to third parties or FirstForm-controlled infrastructure.
- If FirstForm later adds cloud accounts, sync, analytics, marketing, server-side subscriptions, or other backend systems, this Policy must be updated before launch or use.
5. Information We May Collect or Process
The categories below describe information that may be collected, stored, processed, transmitted, displayed, or otherwise handled depending on which features you use.
5.1 Identifiers and Account Information
We may process:
- Name.
- Email address.
- Phone number.
- Date of birth.
- Local device account ID.
- App install identifiers or internal record IDs.
- Subscription entitlement status.
- Support contact information.
Current implementation note: A true production cloud login, signup, password reset, and cloud sync system was not confirmed in the inspected code. The current app appears to use a device-scoped local account.
5.2 Profile, Preferences, and Personalization Information
We may process:
- Goals.
- Experience level.
- Age.
- Sex.
- Height.
- Weight.
- Activity level.
- Unit preferences.
- Reminder settings.
- Quiet hours.
- Theme or display settings.
- Weekly workout goals.
- Onboarding answers.
5.3 Peptide, Compound, Protocol, Dose, and Inventory Information
We may process:
- Compound names, aliases, categories, favorites, and catalog interactions.
- Protocol names, goals, start dates, duration, routes, frequency, and schedule.
- Dose logs, dose amount, dose status, timing, route, injection site, protocol links, vial links, and notes.
- Reconstitution calculator inputs and outputs.
- Vial strength, water amount, concentration, total doses, doses remaining, expiration or start dates, and low-inventory status.
- Protocol adherence, streaks, due doses, and history.
This information may be sensitive because it may reveal health, wellness, research, peptide, medication, compound, or regulated-substance-related behavior.
5.4 Side Effects, Symptoms, and Notes
We may process:
- Symptoms.
- Side effects.
- Severity.
- Associated compound.
- Dates and times.
- Notes.
- Optional side effect photos.
Side effect and symptom information may be sensitive health information.
5.5 Nutrition, Food, Water, and Weight Information
We may process:
- Food entries.
- Meal type.
- Serving size.
- Calories.
- Protein, carbohydrates, fat, fiber, sugar, sodium, and other nutrition values.
- Water intake.
- Weight entries.
- Nutrition goals.
- Custom foods.
- Favorite foods.
- Recent foods.
- Food search queries.
- Barcode values.
- Meal photos and meal notes.
Food database results and photo-based estimates may be inaccurate.
5.6 Workout, Training, Body, and Progress Information
We may process:
- Workout sessions.
- Exercise names.
- Sets, reps, weights, duration, notes, and source.
- Imported Apple Health workouts.
- Training frequency.
- Body/physique progress photos.
- Pose labels.
- Progress photo notes.
- Weight associated with progress photos.
Progress photos and body-tracking information can be sensitive.
5.7 Apple Health / Apple Watch Information
If you authorize Apple Health access, the App may read certain categories from Apple Health, including:
- Body mass / weight.
- Steps.
- Sleep analysis.
- Heart rate variability.
- Resting heart rate.
- Active energy burned.
- Exercise minutes.
- Workouts and workout source information.
Based on the inspected code, the App requests read-only access and does not request permission to write data to Apple Health.
Apple Health data stays on your device. It is not sent to the AI provider or the FirstForm AI proxy. The AI coach is built to exclude Apple Health and wearable readings (such as sleep, heart rate variability, resting heart rate, steps, and active energy), and body weight that was imported from Apple Health, from the context sent to the AI provider.
5.8 Lab, Rythm, and Biomarker Information
We may process:
- Lab panel names.
- Collection dates.
- Biomarker names.
- Biomarker values.
- Units.
- Reference ranges.
- Status labels.
- Categories.
- Manual biomarker entries.
- Imported lab PDFs, photos, screenshots, or page images.
- Lab source labels such as Rythm, other labs, Apple Health, Apple Watch, or manual.
Lab files may contain names, dates of birth, lab account numbers, provider names, test dates, and other highly sensitive information. Review files before uploading them.
5.9 Photos, Images, Files, and Uploads
We may process:
- Meal photos.
- Progress photos.
- Side effect photos.
- Lab report PDFs and images.
- Any other file or image you choose to upload, import, attach, or share through the App.
Based on the inspected code, progress photos appear to be stored locally and encrypted. Meal photos and lab images are sent to AI services or a FirstForm-controlled AI proxy when you use those optional features. Side effect photos are stored with your side effect records and may be included, as embedded image data, in the plain JSON export file if you export your data.
5.10 AI Prompts, AI Context, and AI Outputs
When you use AI features, we may process and transmit:
- Your AI messages.
- Assistant responses.
- Structured prompts and model instructions.
- Meal images and notes.
- Lab report images or extracted page images.
- Relevant App context, which may include protocols, doses, inventory, nutrition, user-entered weight, biomarkers, labs, side effects, and goals.
Apple Health and wearable readings, and body weight imported from Apple Health, are excluded from AI context and are not sent to the AI provider. AI features are optional. Do not submit information you do not want processed by an AI provider or proxy.
5.11 Purchases and Subscription Information
We may process:
- StoreKit product identifiers.
- Subscription entitlement state.
- Purchase and restore status.
- Subscription active/inactive state.
- App Store transaction information made available to the App.
Apple processes payment details. We do not receive your full payment card number from Apple.
5.12 Support, Feedback, Ideas, and User-Generated Content
We may process:
- Support messages.
- Feature requests.
- Problem reports.
- App version and iOS version included in diagnostics text.
- Ideas board titles and descriptions.
- Votes.
- Anonymous device identifier used to deduplicate votes.
- Any personal information you choose to include in support or feedback.
Do not submit sensitive health, medical, financial, legal, or confidential information in shared feedback areas.
5.13 Device, Technical, and Network Information
Based on the inspected code, no dedicated third-party analytics, crash-reporting, advertising, remarketing, or tracking SDK was found. However, we or third parties may process technical information needed to operate features, such as:
- IP address.
- User agent or device/app request metadata.
- App version.
- iOS version.
- Request timestamps.
- API response codes.
- Server logs if a proxy or backend is deployed.
- Diagnostic information you include in a support request.
6. Consumer Health Data Privacy Notice
Certain laws may define "consumer health data" broadly. For purposes of this section, consumer health data may include information that identifies or can reasonably be linked to you and relates to your past, present, or future physical or mental health, body functions, wellness, nutrition, fitness, symptoms, labs, biomarkers, medications, peptides, compounds, protocols, side effects, or similar information.
6.1 Categories of Consumer Health Data Collected
Depending on your use of the App, we may collect or process:
- Peptide, compound, protocol, dose, route, injection site, vial, and inventory records.
- Side effects, symptoms, severity, and health notes.
- Nutrition, food, water, weight, and meal photo information.
- Workout, training, recovery, activity, and progress information.
- Progress photos and body-tracking information.
- Apple Health metrics.
- Lab reports, lab images, biomarkers, and reference ranges.
- AI prompts and outputs that include health or wellness context.
- Profile information such as age, sex, height, weight, goals, and activity level.
6.2 Sources of Consumer Health Data
Sources may include:
- You.
- Your device.
- Apple Health, if authorized.
- Lab files or photos you upload.
- Food database responses.
- AI-generated outputs based on your inputs.
- Imported files you choose to import.
6.3 Purposes for Consumer Health Data
We use consumer health data to:
- Provide tracking, logging, calculations, reminders, summaries, and App functionality.
- Display history, trends, goals, adherence, nutrition totals, workouts, labs, and insights.
- Import Apple Health data you authorize.
- Estimate food or extract lab data when you request AI analysis.
- Generate AI coach responses when you choose to use AI.
- Provide support and troubleshoot issues.
- Process exports, imports, and local deletion.
- Maintain, secure, and improve the Services.
- Comply with law and enforce our Terms.
6.4 Categories of Consumer Health Data Shared
Depending on feature use, consumer health data may be shared as follows:
- Food search queries and scanned barcodes (UPC/GTIN) with the active food database providers: Open Food Facts for barcode scans (with USDA FoodData Central as a fallback), and USDA FoodData Central for text search.
- AI prompts, meal images, lab images, and relevant App context with AI service providers or a FirstForm AI proxy. This App context excludes Apple Health and wearable readings and Apple Health-imported weight; it may include user-entered data such as protocols, doses, nutrition, user-entered weight, biomarkers, and side effects.
- Apple Health data with the App locally after you authorize Apple Health access. Apple Health readings stay on your device and are not transmitted to the AI provider or proxy.
- Ideas and feedback with the Ideas board database if submitted.
- Support messages with email/support providers when you send them.
- Export files with recipients you choose through the iOS share sheet.
- Purchase/subscription status with Apple through StoreKit.
6.5 Third Parties and Affiliates
Current confirmed or strongly indicated third-party categories include:
- Apple and Apple Health.
- Apple App Store / StoreKit.
- AI provider or AI proxy provider.
- Open Food Facts (active food database provider for barcode scans).
- USDA FoodData Central (active food database provider for text search, and barcode fallback).
- Neon or database provider for Ideas board.
- Email/support providers.
- Hosting/infrastructure providers if deployed.
Specific production vendors require confirmation before publication.
6.6 Consumer Health Data Rights
Depending on your location and applicable law, you may have rights to access, delete, withdraw consent, restrict, correct, appeal, or otherwise control consumer health data. Because the App is local-first, FirstForm may not be able to access data stored only on your device unless you export or send it to us.
To exercise rights, contact admin@firstformllc.com.
7. How We Use Information
We may use information to:
- Provide and operate the Services.
- Personalize the App.
- Display logs, protocols, nutrition, workouts, labs, progress, health metrics, reminders, and summaries.
- Process calculations and trends.
- Import Apple Health data with permission.
- Search food databases and return nutrition results.
- Analyze meal photos and lab reports when requested.
- Generate AI responses.
- Process subscriptions and entitlements.
- Respond to support requests.
- Operate the Ideas board and feedback features.
- Export, import, or delete local data at your request.
- Maintain security and prevent abuse.
- Debug, maintain, and improve the Services.
- Enforce our Terms.
- Comply with legal obligations.
We do not use health data found in the inspected app code for third-party advertising.
8. Legal Bases Where Required
Where laws such as GDPR or UK GDPR apply, our legal bases may include:
- Contract: to provide the Services you request.
- Consent: for optional Apple Health access, camera/photo access, notifications, AI analysis, lab uploads, and certain communications.
- Legitimate interests: to operate, maintain, secure, improve, and support the Services.
- Legal obligation: to comply with law, tax, accounting, App Store, fraud, dispute, and regulatory obligations.
- Vital interests: only in limited circumstances where legally permitted and necessary to protect safety.
Legal bases and jurisdiction-specific requirements must be confirmed by counsel.
9. How We Disclose Information
We may disclose information:
9.1 To Provide Features You Request
Examples:
- Sending food queries or barcodes to food database providers.
- Sending AI prompts, meal photos, lab images, and related context to an AI provider or proxy.
- Sending subscription purchase/restore requests through Apple.
- Sending support emails through your email provider.
- Posting ideas and votes to the Ideas board.
- Sharing export files through the iOS share sheet when you choose.
9.2 To Service Providers
Service providers may help with:
- AI processing.
- App Store distribution and billing.
- Food data lookup.
- Database hosting.
- Email/support.
- Hosting and infrastructure.
- Security and debugging.
- Legal, accounting, and compliance.
9.3 For Legal, Safety, and Enforcement Reasons
We may disclose information if we believe disclosure is necessary to:
- Comply with law or legal process.
- Enforce our Terms.
- Protect FirstForm, users, or others.
- Investigate fraud, abuse, security incidents, or unlawful conduct.
- Respond to disputes, chargebacks, App Store issues, or legal claims.
- Protect rights, privacy, safety, or property.
9.4 Business Transfers
Information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction.
10. No Sale or Cross-Context Behavioral Advertising Based on Inspected Code
Based on the inspected code, we did not find ad SDKs, remarketing SDKs, App Tracking Transparency use, or third-party analytics SDKs. We do not currently sell personal information or share personal information for cross-context behavioral advertising based on the inspected code.
If FirstForm later uses advertising, remarketing, analytics, pixels, affiliates, referrals, or cross-context behavioral advertising, this Policy must be updated and required opt-outs must be provided before such use.
11. Cookies and Online Tracking
The inspected native app code did not show cookies, browser tracking, or a cookie preference center. If FirstForm operates a website, landing page, checkout flow, analytics tool, ad pixel, affiliate program, or marketing stack outside this codebase, FirstForm must update this Policy and publish any required cookie notice or preference center.
12. Storage, Security, and Encryption
Based on the inspected implementation, several local stores are encrypted at rest using device-based encryption and keychain-held keys. These appear to include core app state, nutrition, workouts, notes, progress photos, and session data.
Do not understand this as a guarantee that all information is encrypted in all locations. Limitations include:
- Some profile/settings values may be stored in device defaults.
- Export files are plain JSON after creation.
- Support emails are processed by email systems.
- AI, food database, Apple, Neon, and other third-party services process data under their own systems.
- Device backups, screenshots, shared files, compromised devices, or user actions may expose data.
- No security method is perfect.
We use reasonable safeguards designed to protect information, but we cannot guarantee absolute security. No system, storage, or transmission is ever completely secure, and you provide information and use the Services with that understanding and at your own risk. Security is a shared responsibility: you are responsible for protecting your device, passcode, biometrics, credentials, backups, and any information you export, share, screenshot, or transmit outside the App. To the fullest extent permitted by law, FirstForm is not liable for unauthorized access, loss, or disclosure that it could not reasonably prevent, or that results from your device, your actions, or third-party services, except to the extent applicable law requires otherwise.
13. Data Retention
Retention depends on where the information is stored:
- Local App data is generally retained on your device until you delete it, delete the App, or use delete-all-data.
- Progress photos are retained locally until deleted or wiped.
- Export files are controlled by you after export.
- Support emails may be retained according to FirstForm's support practices.
- AI provider or proxy records may be retained according to vendor and server settings.
- Food database providers may retain request data under their own policies.
- Ideas board submissions and votes may remain until removed under FirstForm's moderation/deletion process.
- Apple purchase records are retained by Apple.
- Legal, tax, accounting, fraud, and dispute records may be retained as required or permitted by law.
FirstForm should adopt a written retention schedule before publication.
14. Your Choices and Controls
Depending on the feature, you may be able to:
- Choose not to enter certain information.
- Deny or revoke Apple Health permissions.
- Deny or revoke camera/photo permissions.
- Disable notifications through the App or iOS.
- Delete local records.
- Use delete-all-data.
- Export a copy of local data.
- Import a supported export file.
- Manage subscriptions through Apple.
- Contact support or privacy contacts for requests.
Because the App is local-first, FirstForm may not be able to see or retrieve data stored only on your device.
15. Privacy Rights
Depending on your location, you may have rights to:
- Know or access information collected about you.
- Receive a copy of information.
- Delete information.
- Correct inaccurate information.
- Withdraw consent.
- Restrict or object to processing.
- Opt out of sale or sharing for cross-context behavioral advertising.
- Limit certain uses of sensitive personal information.
- Appeal a privacy request decision.
- Request data portability.
To submit a request, contact admin@firstformllc.com.
We may need to verify your identity. We may deny or limit requests where permitted by law, including where data is local-only and not available to FirstForm, where retention is legally required, where deletion would impair security or legal rights, or where the request cannot be verified.
16. California and Other State Privacy Notices
If the California Consumer Privacy Act or similar state laws apply, California and other eligible residents may have rights to know, access, delete, correct, opt out of sale/share, limit use of sensitive personal information, and avoid discrimination for exercising privacy rights.
Sensitive personal information may include health information, biometric-like information, account credentials, precise geolocation, genetic information, contents of certain communications, and other categories defined by law.
Based on the inspected code:
- No sale of personal information was found.
- No sharing for cross-context behavioral advertising was found.
- No ad SDK was found.
- No precise location framework was found.
If FirstForm's actual production practices differ, this section must be updated before launch.
17. Washington and Other Consumer Health Privacy Notices
Washington's My Health My Data Act and similar laws may impose specific requirements for consumer health data. If those laws apply, FirstForm may need a separate consumer health data privacy policy link, affirmative consent for certain collection/sharing, deletion rights, data security practices, processor contracts, and restrictions on sale or geofencing.
This App handles categories that may qualify as consumer health data. Counsel must confirm applicability and required implementation before public launch.
18. GDPR, UK GDPR, and International Rights
If GDPR, UK GDPR, or similar laws apply, you may have rights including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights related to solely automated decision-making.
The App does not appear to make legally significant decisions using solely automated processing based on inspected code. AI outputs are informational and should not be treated as medical decisions.
If FirstForm offers the App to users in the EU, UK, or other international markets, FirstForm must confirm controller/processor roles, lawful bases, transfer mechanisms, representative requirements, DPO requirements, retention, and vendor contracts.
19. Children and Minors
The Services are intended only for adults 18 and older. The Services are not directed to children, and we do not knowingly collect personal information from anyone under 18. This includes children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA). If you are under 18, do not use the Services or provide any information. If you believe a person under 18 has used the Services or provided information, contact us and we will take reasonable steps to delete it.
20. Communications
The inspected app code did not show a marketing email or SMS stack. If FirstForm later sends marketing email, SMS, push marketing, referrals, or affiliate communications, FirstForm must obtain any required consent and provide opt-out mechanisms.
Local notifications for reminders are controlled through the App and iOS settings.
21. Data Incidents and Breach Notification
If we discover a security incident involving personal information or consumer health information, we will investigate and provide notices if and as required by applicable law.
FirstForm must confirm its FTC Health Breach Notification Rule, state breach law, HIPAA, and consumer health privacy breach posture before publication.
22. International Transfers
FirstForm is based in the United States. Where permitted by law, by using the Services you consent to the processing and transfer of your information in the United States and in other countries where FirstForm or its service providers operate, which may have data-protection laws different from those of your country. If international transfer laws apply, FirstForm will use the transfer mechanisms required by law.
23. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we may provide notice through the App, website, email, App Store release notes, or other means required by law. Continued use of the Services after an updated Policy becomes effective means you acknowledge the updated Policy.
24. Your Consent, Acknowledgment, and Responsibility
By using the Services, you acknowledge that you have read and understood this Policy and consent to the collection, use, storage, disclosure, and processing of information as described here, including:
- Sending your prompts, relevant tracked data, meal photos, and lab images to an AI provider or a FirstForm-controlled AI proxy when you use AI features.
- Sending food search queries and scanned barcodes to the active food database provider (currently USDA FoodData Central).
- Importing Apple Health data locally on your device when you authorize it (Apple Health data is not sent to the AI provider).
- Storing your records on your device and, for optional features, transmitting the information those features require.
- Processing information in the United States and, where applicable, other countries (see International Transfers).
Your consent is voluntary. You may withdraw it for a given feature by not using that feature, by revoking a device permission, or by stopping use of the Services and deleting your data. Because some processing is necessary to provide the Services, withdrawing consent may limit or end your ability to use them.
You are responsible for:
- The accuracy and lawfulness of the information you enter, upload, or share.
- Not entering another person's personal or health information without their permission.
- Securing your device, passcode, biometrics, backups, and any files you export or share.
- Deciding what to include in AI prompts, uploads, exports, and shared or public features such as the Ideas board.
Because the Services are local-first, information stored only on your device is under your control, and FirstForm cannot access, correct, or delete it unless you export or send it to us.
25. Limitation of Liability
To the fullest extent permitted by law, the disclaimers and limitations in the Terms of Use, including the disclaimer of warranties and the limitation of liability, apply to this Policy and to any claim relating to the privacy, security, storage, transmission, disclosure, loss, retention, or handling of information. FirstForm uses reasonable safeguards but does not guarantee that information will always be secure, private, accurate, available, or free from unauthorized access, and you use the Services and provide information with that understanding and at your own risk. Nothing in this Policy limits any right or remedy that applicable law does not allow to be limited.
26. Contact Us
FirstForm LLC
Mailing address: 30 N Gould St STE N, Sheridan, WY 82801
Privacy: admin@firstformllc.com
Legal: admin@firstformllc.com
Support: admin@firstformllc.com
Attorney Review Flags
- Confirm company address, privacy email, legal email, and public product name.
- Confirm HIPAA position and whether HIPAA is expressly disclaimed.
- Confirm FTC Health Breach Notification Rule posture, given that identifiable health-related data (such as lab images, biomarkers, side effects, and user-entered health data) is transmitted to a third-party AI provider when the AI coach and lab/photo features are used. Note: Apple Health and wearable readings are excluded from AI context (see the 5.1.3 note below).
- Confirm Washington My Health My Data Act and similar consumer health privacy law requirements, including whether a separately linked consumer health data privacy policy and affirmative, logged opt-in consent are required before health-related data is collected or shared (for example, before sending health context to the AI provider or food queries to USDA).
- App Store Guideline 5.1.3 (HealthKit to third parties): RESOLVED in code by excluding Apple Health and wearable readings, and Apple Health-imported weight, from AI context. Confirm the exclusion holds for any future feature that adds HealthKit-derived data to AI prompts.
- Confirm the active food database provider(s). Current inspected code uses USDA FoodData Central only; Open Food Facts exists in code but is not active, and USDA queries currently use a shared demo API key.
- Confirm California and other state privacy law applicability.
- Confirm all production vendors and data flows.
- Confirm AI provider/proxy logging, retention, training, deletion, and vendor terms.
- Confirm whether profile/settings fields should be encrypted before publication.
- Confirm App Store privacy labels, HealthKit disclosure, permission strings, and subscription disclosures.
- Confirm whether website cookies, analytics, ads, SMS, referrals, affiliates, or marketing exist outside this repo.
- Review the 2026-07-30 strengthening pass: the added consent/acknowledgment section (§24), the international-transfer consent (§22), the reinforced security disclaimer (§12), and the limitation-of-liability tie-in (§25). Confirm that (a) "consent by use" is sufficient in the target jurisdictions or whether affirmative clickwrap/opt-in consent must be captured and logged (WA MHMD, Nevada, Connecticut, GDPR require affirmative consent for certain consumer-health data collection/sharing); (b) the liability tie-in to the Terms does not purport to waive non-waivable statutory privacy rights or breach-notification duties; and (c) none of the added language contradicts the stated user rights or the honest security/encryption hedges.