How Symcore Design LLC collects, uses, shares, retains, and protects consumer health data in LiveFirst — the disclosures required by Washington’s My Health My Data Act, Nevada’s consumer health data law, and similar United States requirements.
This Consumer Health Data Privacy Notice (“Notice”) explains how Symcore Design LLC (“Symcore,” “we,” “us,” or “our”) collects, uses, processes, shares, retains, and protects consumer health data in connection with the LiveFirst iOS application and related support services (collectively, “LiveFirst” or the “Service”).
This Notice supplements the LiveFirst Privacy Policy. It is intended to provide the consumer health data disclosures required by Washington’s My Health My Data Act, Nevada’s consumer health data law, and similar United States requirements. If this Notice provides greater protection for consumer health data than the general Privacy Policy, this Notice controls for that consumer health data.
LiveFirst is a digital-wellness and productivity application. It is not a healthcare provider, medical device, medical-record system, health insurer, therapy service, emergency service, or substitute for professional medical advice. LiveFirst is not designed to create a HIPAA-covered medical record.
Symcore Design LLC is responsible for the consumer health data practices described in this Notice.
For this Notice, “consumer health data” means personal information that is linked or reasonably linkable to a consumer and identifies or permits an inference about the consumer’s past, present, or future physical or mental health. Depending on applicable law, this can include fitness measurements, health-related tasks or journal text, attempts to obtain health services, precise location information that reveals health context, and identifiers that associate such information with an account.
Information can be consumer health data even when it is not a diagnosis, medical record, or information collected by a doctor.
The categories below depend on the features you choose. You are not required to connect Apple Health or Location to use LiveFirst’s basic task features.
If you choose a Health completion method and grant Apple Health permission, LiveFirst can read:
These measurements are read and compared with your selected goal on your iPhone. LiveFirst does not upload the raw step count, raw walking or running distance, or a history of those raw readings to Symcore or Supabase. LiveFirst does not write information to Apple Health.
When you create or save a Health task, LiveFirst can store and sync:
The stored goal and completion can reveal information about exercise or physical activity even though the underlying raw HealthKit measurement remains on your device.
If parental controls are enabled, a parent may require a passcode before a person manually completes, edits, or deletes the task. Health, Calendar, Reminders, Location, and timer integrations can still complete an eligible task automatically when their configured condition is met. The parental passcode hash, verification-attempt count, and unlock or lockout timestamps do not contain raw HealthKit readings.
LiveFirst provides general task, note, and journal fields. We do not require you to enter medical information. If you voluntarily type information about health, exercise, symptoms, mental health, treatment, medication, a health condition, reproductive or sexual health, healthcare appointments, or similar subjects, that information is stored as the task, note, or journal content you submitted.
LiveFirst does not automatically obtain diagnoses, prescriptions, medical record numbers, health-insurance identifiers, genetic data, biometric identifiers, or HealthKit clinical records. A reference to one of those topics could nevertheless be stored if you voluntarily type it into a task, note, or journal.
If you deliberately attach a place to a task, LiveFirst can store:
A selected place may be consumer health data when, for example, it reveals a visit to a healthcare location or otherwise permits a health inference.
Live location updates, movement history, and geofence events are processed by the iPhone and are not uploaded to Symcore. Only the place and coordinates you deliberately save with the task are synced. The place picker shows whether Location Services are disabled, not requested, denied, limited to While Using, or sufficient for background completion. You may still save a place without Always access, but the task may require LiveFirst to remain open. LiveFirst does not create geofences for advertising, data brokerage, or to identify or track people seeking health care. A location trigger is created only when you choose a place for your own task-completion feature.
Consumer health data stored with a task may be associated with your LiveFirst user ID, email address, task ID, timestamps, and ordinary request information needed to authenticate, secure, synchronize, and support the account. Supabase’s ordinary service and security logs can include a user identifier, IP address, user agent or device information, timestamp, and requested operation. LiveFirst does not use this technical information to infer health conditions or build advertising profiles.
LiveFirst obtains consumer health data from the following categories of sources:
LiveFirst does not obtain consumer health data from data brokers, advertising networks, social-media profiles, employers, insurers, pharmacies, healthcare providers, or public-record databases.
LiveFirst processes consumer health data only for the following purposes:
The processing works as follows:
LiveFirst does not use consumer health data for targeted advertising, cross-context behavioral advertising, sale, data brokerage, unrelated profiling, credit or insurance decisions, employment decisions, or training artificial-intelligence models.
The in-app parental passcode does not create a separate parent account or remotely disclose consumer health data to a parent. A person who is permitted to use the signed-in device may be able to view readable task and journal content already displayed by the app; the passcode controls selected changes, not account access or a separate sharing channel.
The categories of third parties with which LiveFirst shares or through which it processes consumer health data are:
Symcore has no affiliates that receive LiveFirst consumer health data.
RevenueCat processes subscription and purchase information, but LiveFirst does not send it raw HealthKit readings, Health-task details, selected location-task coordinates, or journal content. Expo provides application build and update infrastructure, but LiveFirst does not send it those consumer health data categories through the reviewed app features.
No advertising network, data broker, or unrelated analytics provider receives consumer health data from LiveFirst.
LiveFirst does not sell consumer health data. LiveFirst does not exchange consumer health data for money or other valuable consideration, and it does not share consumer health data for targeted advertising.
If LiveFirst ever proposes a sale of consumer health data, we will not conduct the sale without the separate, written authorization required by applicable law. No such authorization is requested because no sale occurs.
LiveFirst does not permit an advertising, analytics, or data-broker third party to collect consumer health data over time and across unrelated websites, applications, or online services when you use LiveFirst. LiveFirst contains no advertising SDK or behavioral analytics SDK.
Subject to applicable law, you may have the right to:
LiveFirst does not sell consumer health data, so there is no sale from which to opt out.
You may use any of the following methods:
Revoking an iOS permission stops new access but does not delete a task, goal, place, note, journal, or completion that was already saved. Delete the saved item or submit a verified deletion request if you also want stored information removed.
You do not need to create a new account to submit a request. We may ask for the account email and additional information reasonably necessary to authenticate you and protect the account from an unauthorized request. An authorized agent may submit a request where applicable law permits, subject to proof of authority and verification of the consumer.
We generally provide qualifying request responses without charge. Applicable law may allow a reasonable fee or refusal for requests that are manifestly unfounded, excessive, or repetitive.
We will respond within the period required by applicable law. Washington requests are handled without undue delay and generally within 45 days of receipt, with one additional 45-day extension when reasonably necessary and with timely notice. Nevada requests are handled without undue delay and generally within 45 days after authentication, with one additional 45-day extension when reasonably necessary and with timely notice.
For a verified deletion request, we delete qualifying consumer health data from active records and notify relevant processors, contractors, affiliates, and other third parties as required. Nevada requires qualifying active-record deletion and notices generally within 30 days after authentication. If data is stored in an archived or backup system, deletion may be delayed only as allowed by applicable law, including up to six months after authentication for a qualifying Washington request and up to two years for qualifying Nevada backup data when necessary to restore the archived or backup system.
Deletion can be limited where applicable law permits or requires retention, including for security, fraud prevention, legal compliance, protection of rights, or establishment, exercise, or defense of legal claims. Information retained for one of those purposes is not used for ordinary product purposes.
If we refuse to act on all or part of your request, you may appeal by replying to the decision or emailing admin@symcoredesign.com with the subject “Consumer Health Data Appeal.” Include the original request and explain why you believe the decision should be reconsidered.
We will provide a written appeal decision within the period required by law, generally within 45 days. If an appeal is denied, we will provide the applicable Attorney General complaint mechanism. You may also contact:
LiveFirst asks before requesting Apple Health access and uses Apple’s system permission process. A Health goal, location trigger, task, note, or journal is stored because you deliberately select, enter, and save it for a feature you requested.
You may withdraw Health or Location permission in iOS Settings and may stop using an integration at any time. Where applicable law requires consent for a new category, purpose, or unnecessary disclosure of consumer health data, we will request the required consent before that processing begins. Consent to collect consumer health data is not treated as authorization to sell it.
Raw HealthKit steps and walking or running distance are not stored in LiveFirst’s server database. Live location updates, movement history, and geofence events are also not stored in that database.
Stored Health goals, task settings, selected places, completions, notes, and related account identifiers are generally retained while the account and relevant content remain active. A journal entry is stored as a separate record and may remain after its original task is removed; it remains until account deletion or removal following a verified request.
Authentication, security, support, request, and legal records are retained only as reasonably necessary for their operational, security, contractual, and legal purposes under the applicable provider schedule. Account deletion and consumer health data deletion are subject to Section 12 and the LiveFirst Privacy Policy.
LiveFirst uses safeguards designed to protect stored consumer health data, including encrypted network connections, provider encryption at rest where applicable, account-scoped database row-level security, limited credentials, and access restricted to purposes reasonably necessary to operate, secure, or support the Service. No security measure can guarantee absolute security.
Contact admin@symcoredesign.com promptly if you believe consumer health data associated with LiveFirst has been accessed or disclosed without authorization.
LiveFirst is not directed to children under 13, and children under 13 may not create or use a LiveFirst account. Users aged 13 through 17 may use LiveFirst only with permission and supervision from a parent or legal guardian. Contact admin@symcoredesign.com if you believe a child provided consumer health data so we can investigate and take action required by law.
We may update this Notice when LiveFirst, our providers, or applicable law changes. We will post the updated Notice, revise the “Last updated” date, and provide additional notice or request consent when required.
LiveFirst will not collect, use, or share an additional category of consumer health data, add an undisclosed recipient, or use consumer health data for an additional purpose without first providing the disclosure and obtaining the affirmative consent required by applicable law.