Pep JourneyHome

FirstForm LLC Privacy Policy

Last updated: 30 July 2026

Draft status: Attorney-review draft, strengthened 2026-07-30 (reinforced the security disclaimer and shared-responsibility language, added an explicit consent/acknowledgment/user-responsibility section, added an express international-transfer consent, and added a limitation-of-liability tie-in to the Terms of Use). This Privacy Policy is not legal advice. It is intentionally broad, conservative, and protective, but a privacy policy protects the company by being accurate and transparent, not by overclaiming: no privacy policy can eliminate all legal risk, and overstating security, compliance, or consent can itself create liability (FTC deception, state consumer-health and privacy laws). The careful hedges here (no HIPAA/encryption/SOC 2 guarantees; "based on inspected code" qualifiers) are deliberate and must be preserved. The business details (contact email admin@firstformllc.com and the FirstForm LLC mailing address) were filled in on 30 July 2026. A licensed-counsel review is still recommended, and every stated practice should continue to match actual production behavior.

1. Who We Are

FirstForm LLC ("FirstForm," "we," "us," or "our") provides Pep Journey, a peptide-first health, wellness, nutrition, training, recovery, biomarker, lab, and personal tracking application, together with related websites, support channels, subscriptions, content, and services that link to this Privacy Policy (collectively, the "App" or "Services").

Contact:

2. Scope of This Policy

This Privacy Policy explains how we may collect, use, store, disclose, retain, and protect information when you use the Services. It applies to:

This Policy does not replace the privacy policies of third parties such as Apple, Apple Health, Anthropic or any AI provider, USDA FoodData Central (the food database provider the App currently uses), Neon, email providers, hosting providers, or other vendors.

3. Important Health, Wellness, and Legal Notice

The App may process information that is health-related, wellness-related, nutrition-related, body-image-related, lab-related, peptide-related, or otherwise sensitive.

The App is not a medical device and is not a healthcare provider. The App does not provide medical advice, diagnosis, treatment, prescribing, emergency care, or professional healthcare services. You should consult a qualified licensed clinician before making decisions about your health, medications, supplements, compounds, peptides, injections, nutrition, training, symptoms, labs, or biomarkers.

We do not claim HIPAA compliance unless we separately state that in a signed agreement or official publication. Based on the current inspected implementation, the App does not appear to operate as a HIPAA covered entity or business associate workflow. Other privacy and consumer health data laws may still apply.

4. Local-First Design and Current Backend Posture

Based on the current codebase inspected for this draft, the App is primarily local-first. Many user records are stored on your device. Several sensitive local stores appear to be encrypted at rest using an on-device keychain-held key.

Important limitations:

5. Information We May Collect or Process

The categories below describe information that may be collected, stored, processed, transmitted, displayed, or otherwise handled depending on which features you use.

5.1 Identifiers and Account Information

We may process:

Current implementation note: A true production cloud login, signup, password reset, and cloud sync system was not confirmed in the inspected code. The current app appears to use a device-scoped local account.

5.2 Profile, Preferences, and Personalization Information

We may process:

5.3 Peptide, Compound, Protocol, Dose, and Inventory Information

We may process:

This information may be sensitive because it may reveal health, wellness, research, peptide, medication, compound, or regulated-substance-related behavior.

5.4 Side Effects, Symptoms, and Notes

We may process:

Side effect and symptom information may be sensitive health information.

5.5 Nutrition, Food, Water, and Weight Information

We may process:

Food database results and photo-based estimates may be inaccurate.

5.6 Workout, Training, Body, and Progress Information

We may process:

Progress photos and body-tracking information can be sensitive.

5.7 Apple Health / Apple Watch Information

If you authorize Apple Health access, the App may read certain categories from Apple Health, including:

Based on the inspected code, the App requests read-only access and does not request permission to write data to Apple Health.

Apple Health data stays on your device. It is not sent to the AI provider or the FirstForm AI proxy. The AI coach is built to exclude Apple Health and wearable readings (such as sleep, heart rate variability, resting heart rate, steps, and active energy), and body weight that was imported from Apple Health, from the context sent to the AI provider.

5.8 Lab, Rythm, and Biomarker Information

We may process:

Lab files may contain names, dates of birth, lab account numbers, provider names, test dates, and other highly sensitive information. Review files before uploading them.

5.9 Photos, Images, Files, and Uploads

We may process:

Based on the inspected code, progress photos appear to be stored locally and encrypted. Meal photos and lab images are sent to AI services or a FirstForm-controlled AI proxy when you use those optional features. Side effect photos are stored with your side effect records and may be included, as embedded image data, in the plain JSON export file if you export your data.

5.10 AI Prompts, AI Context, and AI Outputs

When you use AI features, we may process and transmit:

Apple Health and wearable readings, and body weight imported from Apple Health, are excluded from AI context and are not sent to the AI provider. AI features are optional. Do not submit information you do not want processed by an AI provider or proxy.

5.11 Purchases and Subscription Information

We may process:

Apple processes payment details. We do not receive your full payment card number from Apple.

5.12 Support, Feedback, Ideas, and User-Generated Content

We may process:

Do not submit sensitive health, medical, financial, legal, or confidential information in shared feedback areas.

5.13 Device, Technical, and Network Information

Based on the inspected code, no dedicated third-party analytics, crash-reporting, advertising, remarketing, or tracking SDK was found. However, we or third parties may process technical information needed to operate features, such as:

6. Consumer Health Data Privacy Notice

Certain laws may define "consumer health data" broadly. For purposes of this section, consumer health data may include information that identifies or can reasonably be linked to you and relates to your past, present, or future physical or mental health, body functions, wellness, nutrition, fitness, symptoms, labs, biomarkers, medications, peptides, compounds, protocols, side effects, or similar information.

6.1 Categories of Consumer Health Data Collected

Depending on your use of the App, we may collect or process:

6.2 Sources of Consumer Health Data

Sources may include:

6.3 Purposes for Consumer Health Data

We use consumer health data to:

6.4 Categories of Consumer Health Data Shared

Depending on feature use, consumer health data may be shared as follows:

6.5 Third Parties and Affiliates

Current confirmed or strongly indicated third-party categories include:

Specific production vendors require confirmation before publication.

6.6 Consumer Health Data Rights

Depending on your location and applicable law, you may have rights to access, delete, withdraw consent, restrict, correct, appeal, or otherwise control consumer health data. Because the App is local-first, FirstForm may not be able to access data stored only on your device unless you export or send it to us.

To exercise rights, contact admin@firstformllc.com.

7. How We Use Information

We may use information to:

We do not use health data found in the inspected app code for third-party advertising.

8. Legal Bases Where Required

Where laws such as GDPR or UK GDPR apply, our legal bases may include:

Legal bases and jurisdiction-specific requirements must be confirmed by counsel.

9. How We Disclose Information

We may disclose information:

9.1 To Provide Features You Request

Examples:

9.2 To Service Providers

Service providers may help with:

9.3 For Legal, Safety, and Enforcement Reasons

We may disclose information if we believe disclosure is necessary to:

9.4 Business Transfers

Information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction.

10. No Sale or Cross-Context Behavioral Advertising Based on Inspected Code

Based on the inspected code, we did not find ad SDKs, remarketing SDKs, App Tracking Transparency use, or third-party analytics SDKs. We do not currently sell personal information or share personal information for cross-context behavioral advertising based on the inspected code.

If FirstForm later uses advertising, remarketing, analytics, pixels, affiliates, referrals, or cross-context behavioral advertising, this Policy must be updated and required opt-outs must be provided before such use.

11. Cookies and Online Tracking

The inspected native app code did not show cookies, browser tracking, or a cookie preference center. If FirstForm operates a website, landing page, checkout flow, analytics tool, ad pixel, affiliate program, or marketing stack outside this codebase, FirstForm must update this Policy and publish any required cookie notice or preference center.

12. Storage, Security, and Encryption

Based on the inspected implementation, several local stores are encrypted at rest using device-based encryption and keychain-held keys. These appear to include core app state, nutrition, workouts, notes, progress photos, and session data.

Do not understand this as a guarantee that all information is encrypted in all locations. Limitations include:

We use reasonable safeguards designed to protect information, but we cannot guarantee absolute security. No system, storage, or transmission is ever completely secure, and you provide information and use the Services with that understanding and at your own risk. Security is a shared responsibility: you are responsible for protecting your device, passcode, biometrics, credentials, backups, and any information you export, share, screenshot, or transmit outside the App. To the fullest extent permitted by law, FirstForm is not liable for unauthorized access, loss, or disclosure that it could not reasonably prevent, or that results from your device, your actions, or third-party services, except to the extent applicable law requires otherwise.

13. Data Retention

Retention depends on where the information is stored:

FirstForm should adopt a written retention schedule before publication.

14. Your Choices and Controls

Depending on the feature, you may be able to:

Because the App is local-first, FirstForm may not be able to see or retrieve data stored only on your device.

15. Privacy Rights

Depending on your location, you may have rights to:

To submit a request, contact admin@firstformllc.com.

We may need to verify your identity. We may deny or limit requests where permitted by law, including where data is local-only and not available to FirstForm, where retention is legally required, where deletion would impair security or legal rights, or where the request cannot be verified.

16. California and Other State Privacy Notices

If the California Consumer Privacy Act or similar state laws apply, California and other eligible residents may have rights to know, access, delete, correct, opt out of sale/share, limit use of sensitive personal information, and avoid discrimination for exercising privacy rights.

Sensitive personal information may include health information, biometric-like information, account credentials, precise geolocation, genetic information, contents of certain communications, and other categories defined by law.

Based on the inspected code:

If FirstForm's actual production practices differ, this section must be updated before launch.

17. Washington and Other Consumer Health Privacy Notices

Washington's My Health My Data Act and similar laws may impose specific requirements for consumer health data. If those laws apply, FirstForm may need a separate consumer health data privacy policy link, affirmative consent for certain collection/sharing, deletion rights, data security practices, processor contracts, and restrictions on sale or geofencing.

This App handles categories that may qualify as consumer health data. Counsel must confirm applicability and required implementation before public launch.

18. GDPR, UK GDPR, and International Rights

If GDPR, UK GDPR, or similar laws apply, you may have rights including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights related to solely automated decision-making.

The App does not appear to make legally significant decisions using solely automated processing based on inspected code. AI outputs are informational and should not be treated as medical decisions.

If FirstForm offers the App to users in the EU, UK, or other international markets, FirstForm must confirm controller/processor roles, lawful bases, transfer mechanisms, representative requirements, DPO requirements, retention, and vendor contracts.

19. Children and Minors

The Services are intended only for adults 18 and older. The Services are not directed to children, and we do not knowingly collect personal information from anyone under 18. This includes children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA). If you are under 18, do not use the Services or provide any information. If you believe a person under 18 has used the Services or provided information, contact us and we will take reasonable steps to delete it.

20. Communications

The inspected app code did not show a marketing email or SMS stack. If FirstForm later sends marketing email, SMS, push marketing, referrals, or affiliate communications, FirstForm must obtain any required consent and provide opt-out mechanisms.

Local notifications for reminders are controlled through the App and iOS settings.

21. Data Incidents and Breach Notification

If we discover a security incident involving personal information or consumer health information, we will investigate and provide notices if and as required by applicable law.

FirstForm must confirm its FTC Health Breach Notification Rule, state breach law, HIPAA, and consumer health privacy breach posture before publication.

22. International Transfers

FirstForm is based in the United States. Where permitted by law, by using the Services you consent to the processing and transfer of your information in the United States and in other countries where FirstForm or its service providers operate, which may have data-protection laws different from those of your country. If international transfer laws apply, FirstForm will use the transfer mechanisms required by law.

23. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we may provide notice through the App, website, email, App Store release notes, or other means required by law. Continued use of the Services after an updated Policy becomes effective means you acknowledge the updated Policy.

24. Your Consent, Acknowledgment, and Responsibility

By using the Services, you acknowledge that you have read and understood this Policy and consent to the collection, use, storage, disclosure, and processing of information as described here, including:

Your consent is voluntary. You may withdraw it for a given feature by not using that feature, by revoking a device permission, or by stopping use of the Services and deleting your data. Because some processing is necessary to provide the Services, withdrawing consent may limit or end your ability to use them.

You are responsible for:

Because the Services are local-first, information stored only on your device is under your control, and FirstForm cannot access, correct, or delete it unless you export or send it to us.

25. Limitation of Liability

To the fullest extent permitted by law, the disclaimers and limitations in the Terms of Use, including the disclaimer of warranties and the limitation of liability, apply to this Policy and to any claim relating to the privacy, security, storage, transmission, disclosure, loss, retention, or handling of information. FirstForm uses reasonable safeguards but does not guarantee that information will always be secure, private, accurate, available, or free from unauthorized access, and you use the Services and provide information with that understanding and at your own risk. Nothing in this Policy limits any right or remedy that applicable law does not allow to be limited.

26. Contact Us

FirstForm LLC

Mailing address: 30 N Gould St STE N, Sheridan, WY 82801

Privacy: admin@firstformllc.com

Legal: admin@firstformllc.com

Support: admin@firstformllc.com

Attorney Review Flags

FirstForm LLC · 30 N Gould St STE N, Sheridan, WY 82801 · admin@firstformllc.com · Privacy · Terms · Disclaimer · Support