Legal

LiveFirst Privacy Policy

How Symcore Design LLC collects, uses, discloses, retains, and protects personal information when you use LiveFirst — and which parts of your Screen Time, Health, and location data never leave your iPhone.

Effective August 8, 2026 Last updated August 8, 2026 No ads, no data brokers, no sale of your data

SECTION 01Scope and who we are

This Privacy Policy explains how Symcore Design LLC, a North Carolina limited liability company (“Symcore,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you use the LiveFirst iOS application and related support services (collectively, “LiveFirst” or the “Service”). LiveFirst is presently offered only in the United States. LiveFirst is a digital-wellness and productivity application, not a healthcare provider or medical service.

Symcore Design LLC is responsible for the personal information described here.

Legal & privacy requests
admin@symcoredesign.com
Support questions
support@symcoredesign.com
Mailing address
901 Fontaine Ct, Waxhaw, NC, 28173, United States

SECTION 02Privacy at a glance

LiveFirst is designed so that especially sensitive device data can remain on your iPhone:

  • Raw Screen Time usage, the Apple-issued token representing your Screen Time selection, and shield or blocked-app counts stay on the device and are not uploaded to Symcore.
  • HealthKit step counts and walking/running distance stay on the device and are not uploaded to Symcore.
  • Live location updates, movement history, and geofence events stay on the device. A place and coordinate that you deliberately attach to a task are stored with that task.
  • Calendar and Reminders are read on the device. Only metadata for the event or reminder you deliberately attach to a task is stored with that task.
  • Notifications are scheduled locally. LiveFirst does not operate a remote push-notification service.

LiveFirst does not contain an advertising SDK or behavioral analytics SDK. We do not sell personal information, share personal information for cross-context behavioral advertising, or use it to track you across other companies’ apps or websites.

Consumer Health Data Privacy Notice

If you use LiveFirst’s Health or location features, our separate Consumer Health Data Privacy Notice explains those practices in full detail — including your rights under Washington’s My Health My Data Act and Nevada’s consumer health data law.

Read the Consumer Health Data Privacy Notice

SECTION 03Information we collect or process

3.1 Account and authentication information

We process your email address, display name, unique Supabase account identifier, account-creation and confirmation status, session records, last-sign-in time, and password and account-security activity. If you use Sign in with Apple, we process the authentication credential and provider identifier Apple supplies. Apple may provide a private relay email address and generally provides a name only on the first authorization.

If you use email and password, the password is transmitted over an encrypted connection to Supabase Auth. LiveFirst does not place a readable copy in its application database. Supabase Auth stores a one-way password hash.

Email-password accounts can change their password from Profile. LiveFirst sends the current password to Supabase Auth to verify the account, then sends the new password over an encrypted connection. Both are used transiently for the request and are not copied into LiveFirst’s application database. Supabase Auth replaces the stored salted password hash. This in-profile password change does not require an emailed reset link.

3.2 Profile and onboarding information

We process your name, optional profile picture, device time zone, self-selected daily allowance, Bronze, Silver, and Gold reward values, onboarding Screen Time guess, any fallback estimate shown during onboarding, Screen Time permission or connection status, onboarding-completion status, and related account settings. The device time zone is used to apply daily limits and resets at local midnight, with UTC as a fallback.

If Apple Screen Time is unavailable or declined and you use the fallback setup, we may store the general app or category choices you select from LiveFirst’s catalog, your own estimated minutes, and whether you marked a choice as limited. LiveFirst does not obtain those fallback choices from the selected apps.

3.3 Parental-control information

If parental controls are enabled, we store a one-way bcrypt hash of the six-digit parental passcode, not the readable passcode; whether adding, editing, deleting, or completing tasks requires the passcode; the number of unsuccessful verification attempts; and timestamps for temporary unlocking and any lockout. Five unsuccessful attempts prevent further verification for 15 minutes. The app also relocks when it moves to the background.

The passcode protects selected actions inside LiveFirst on the signed-in device. It does not create a separate parent account, transmit the passcode to a parent, provide remote monitoring, or prevent someone with control of the device from changing iOS settings, withdrawing permissions, or removing the app.

3.4 Tasks, journals, and content

We process task titles, notes, dates, reward tiers, earned minutes, completion status and time, reminder settings, repeat rules, series information, skips, custom settings, journal titles and entries, task history, and allowance-ledger activity. Completed Count or timer tasks sync their completion; in-progress tallies and timer state are generally local. Any information you type in a task, note, or journal is also stored when you save it.

3.5 Optional task integrations

When you deliberately configure an integration, we may store:

  • Location: place label, precise latitude and longitude, radius, arrival/dwell/departure rule, and dwell duration.
  • Health: whether the task uses steps or walking/running distance, the target, and task-completion status. Raw HealthKit readings are not uploaded.
  • Calendar: selected event identifier, title, start and end time, and calendar title.
  • Reminders: selected reminder identifier and title, list identifier or title, and the completion target used for the task.
  • Journal or Count: the goal configuration associated with the task.

3.6 Profile picture

If you select a profile picture, LiveFirst uploads only the selected image. The app crops or compresses it without retaining EXIF metadata. It is stored under your account identifier in a private Supabase Storage bucket and displayed through a short-lived signed link. LiveFirst does not request camera or microphone access.

3.7 Subscription and purchase information

If you view, buy, restore, or use LiveFirst Pro, Apple and RevenueCat process the product identifier, subscription period, purchase and renewal dates, expiration, grace-period, billing-issue and cancellation status, introductory offer or trial status, whether the subscription will renew, store, receipt and transaction or event identifiers, and your LiveFirst account identifier as the RevenueCat app user identifier. RevenueCat may also process device type, operating system, locale or currency, last-seen time, Apple receipt information, and similar technical information needed to operate subscriptions.

LiveFirst uses the unique identifier for your signed-in Supabase account as the RevenueCat app user identifier. Purchases and restores are available only after LiveFirst confirms that association. The app refreshes RevenueCat subscription information at launch and when it returns to the foreground, compares it with the subscription-status copy stored in Supabase, and may update that copy to reflect a purchase, renewal, cancellation, or expiration. A per-account Pro status may also be cached locally and is cleared when accounts change.

Apple processes payment through your Apple ID. Symcore does not receive your full payment-card number, bank-account information, Apple ID password, or Apple billing address.

3.8 Technical, security, and update information

Our hosting and authentication infrastructure automatically processes limited technical records needed to deliver and secure LiveFirst. These can include IP address, user agent, device or operating-system information, timestamps, request route and status, authentication action and provider, and error or security information.

When LiveFirst checks whether the Service is available and the installed version is supported, our infrastructure may process the app version or runtime and standard request information. The response can provide an operational notice, require a minimum version, or temporarily place the app in maintenance or unavailable mode. LiveFirst may cache the latest valid response on the device so a temporary network failure does not unnecessarily interrupt access.

LiveFirst uses EAS Update. Expo may process the device operating system, a randomized token used to determine whether an update was downloaded, IP address, update channel and runtime information, and standard network or performance information needed to deliver and protect the update service.

3.9 Support and legal communications

If you contact us, we process the name, contact details, message, attachments, and information you provide so we can investigate and respond.

SECTION 04Information that remains on your device

The following is not uploaded to Symcore’s account database:

  • The Apple FamilyActivitySelection token for apps or categories you choose to shield, and the identities represented by that token.
  • Actual Screen Time usage, device-activity reports, shield events, and blocked counts. LiveFirst may keep local per-account, per-day summaries for up to approximately 400 days to operate and display device history.
  • HealthKit step counts and walking/running distance.
  • Current and background location updates, movement history, and the queue of geofence events. Only the selected task place and resulting task completion can sync.
  • Calendar events and Reminders other than the selected item’s metadata stored with a task.
  • Local notification schedules and preferences.
  • In-progress timers and Count tallies, unsaved journal drafts, widgets, Screen Time enforcement state, per-account cached Pro status, consent flags, and device-setup state.

Some local information is shared only among LiveFirst and its own iOS extensions through Apple’s App Group storage so shields and widgets can work while the main app is closed. This is device storage, not disclosure to another company.

An authentication session is stored in the iOS Keychain with device-only accessibility. iOS Keychain items may survive deleting and reinstalling an app. The session remains subject to expiration or revocation and can be cleared by signing out or deleting the LiveFirst account.

SECTION 05Sources

Information comes from you; your device when you grant permission or use a feature; Apple services including Sign in with Apple, Screen Time, HealthKit, Location Services, MapKit/geocoding, Calendar, Reminders, Photos, StoreKit, and the App Store; RevenueCat; and our infrastructure providers’ operational and security systems.

SECTION 06How we use information

We use information to create and secure accounts; sync profile, settings, tasks, journals, history, parental-control state, time zone, and entitlement status; verify a parental passcode and enforce selected task restrictions; provide task completion, Screen Time shielding, reminders, widgets, local-midnight allowance calculations and other requested features; display a profile picture; validate and restore LiveFirst Pro; reconcile subscription status across RevenueCat and Supabase; deliver updates; enforce supported versions and communicate Service status; diagnose failures and prevent abuse; respond to support, privacy, and legal requests; comply with law; and maintain Service reliability.

We do not use HealthKit readings, precise-location task settings, private task or journal content, or Screen Time data for advertising, data brokerage, or training an artificial-intelligence model.

SECTION 07Disclosures

7.1 Service providers

  • Supabase, Inc. provides the database, authentication, private file storage, APIs, and server functions. The LiveFirst project is hosted in Supabase’s U.S. West (Oregon) region. Supabase processes synced account and content data and technical logs on our behalf. See supabase.com/privacy.
  • RevenueCat, Inc. provides purchase validation and subscription entitlements. It receives the LiveFirst account identifier, purchase history, Apple receipt information, and related technical data. See revenuecat.com/privacy.
  • 650 Industries, Inc. (Expo) provides EAS Update and processes the limited update information described above. LiveFirst does not use Expo’s push service. See expo.dev/privacy.
  • Apple Inc. provides iOS, the App Store, Sign in with Apple, Screen Time, HealthKit, Location Services, MapKit/geocoding, Calendar, Reminders, Photos, notifications, and Keychain. Apple processes information under its own terms and privacy policy. See apple.com/legal/privacy.

These providers may use subprocessors under their contracts. Providers acting for us are permitted to process information for the services they supply and must protect it appropriately.

7.2 Legal, safety, and business events

We may disclose information when reasonably necessary to comply with law or valid legal process; respond to an emergency involving serious physical danger; investigate fraud, abuse, or a security incident; enforce agreements; or protect rights, property, and safety. Information may also be reviewed or transferred as part of a merger, financing, reorganization, bankruptcy, sale of assets, or acquisition, subject to appropriate protections and legally required notice.

7.3 At your direction

We may disclose information at your direction or with your consent. Choices you make in Apple services may separately cause Apple to process information under Apple’s terms.

We do not disclose personal information to data brokers, advertising networks, or third parties for their independent direct marketing.

SECTION 08Sensitive Apple frameworks

8.1 Screen Time

With permission, LiveFirst uses Apple’s Family Controls, Device Activity, and Managed Settings frameworks to shield apps or categories you choose. The opaque selection token, measured usage, and enforcement state remain on the device. Changing the selection can be protected by the parental passcode, but the selection itself is never uploaded. You can withdraw access in iOS Settings; shielding and device-activity features will then stop.

8.2 HealthKit

If you select a Health completion method and grant access, LiveFirst reads only today’s steps and walking/running distance needed to evaluate the goal. It asks for no HealthKit write access. Readings are compared locally and not uploaded. The task’s metric, target, and completion can sync. You can withdraw Health access in iOS Settings. Symcore will not use HealthKit data for advertising, marketing, data mining, or sale.

8.3 Location

For a location task, LiveFirst stores the selected place, coordinate, radius, and rule. iOS performs region monitoring and can wake the app for a boundary event when Always location access is available; without that grant, the task may require LiveFirst to remain open. The place picker identifies the current permission state and links to Settings, but does not prevent you from saving a place. LiveFirst does not request continuous background location updates. Movement and boundary-event details remain local, while completion can sync. Apple may process searches, current location, and coordinates to provide MapKit, geocoding, and system location services. You can revoke permission in iOS Settings or remove the integration.

8.4 Calendar and Reminders

LiveFirst reads these locally after permission so you can select an item and the device can check its status. Only the selected item’s metadata and task rule sync. LiveFirst does not create, edit, or delete Calendar events or Reminders.

SECTION 09Sales, tracking, and privacy signals

LiveFirst does not sell personal information, share it for cross-context behavioral advertising, serve third-party ads, or conduct qualifying profiling with legal or similarly significant effects. We do not knowingly allow third parties to collect LiveFirst activity over time and across unaffiliated services for advertising.

There is therefore no sale, targeted-advertising, or profiling opt-out needed for the app. Browser Do Not Track and Global Privacy Control signals do not change app behavior. If these practices change, we will update this Policy and honor legally recognized signals before beginning the new practice.

SECTION 10Retention and account deletion

Account, profile, onboarding, settings, parental-control state, tasks, history, selected integration metadata, and our subscription-status copy are generally kept while the account is active. Disabling parental controls deletes the parental-control record, including its passcode hash and attempt or lockout state. A removed task is deleted from the active task table. A saved journal entry is a separate record and can remain after its original task is removed; it remains until account deletion unless removed after a verified request. A profile picture remains until replaced, removed, or the account is deleted.

Local information remains until cleared by a feature, sign-out or account deletion, token expiration or revocation, removal of app storage by iOS, or manual device action. Keychain sessions can survive an app reinstall.

Authentication, security, request, support, legal, and update records are kept only as reasonably needed for their operational, security, contractual, and legal purposes under the applicable provider’s schedule. Apple and RevenueCat may retain transaction, receipt, entitlement, fraud, and required business records under their own obligations. Deleting a LiveFirst account does not erase Apple’s App Store records and does not cancel a production App Store subscription. Contact us to request an eligible RevenueCat end-user deletion.

The Profile screen has a Delete Account function. When it succeeds, it deletes the active LiveFirst database records for the profile, onboarding, limits, parental controls, tasks, task history, journal, legacy fallback information, our subscription copy, and the Supabase authentication user, and clears key local account data. It also attempts to remove private profile-photo objects before database deletion. If that storage operation is unavailable, an unlinked private photo object may remain; contact admin@symcoredesign.com so we can verify and remove it.

Production subscriptions must be canceled through Apple

Before deleting your account, cancel through Settings > [your name] > Subscriptions or the App Store if you do not want a production LiveFirst Pro subscription to renew. TestFlight purchases are no-charge sandbox transactions that renew on an accelerated test schedule and expire automatically; they do not create real billing that must be canceled.

We may retain limited information when required by law, to preserve evidence, resolve disputes, prevent fraud or abuse, enforce agreements, or protect legal rights. We isolate it from ordinary use where feasible.

SECTION 11Security

Safeguards include encrypted network connections, provider encryption at rest where applicable, owner-scoped database row-level security, a parental-control table that is reachable only through restricted server functions and never returns the passcode hash to the app, bcrypt passcode hashing, verification-attempt lockouts, a private avatar bucket, short-lived avatar links, limited server credentials, and iOS Keychain session storage. No system is completely secure. Contact admin@symcoredesign.com promptly if you suspect compromise.

SECTION 12Choices and United States state rights

You can edit supported app information, remove your photo, change permissions in iOS Settings, sign out, manage the Apple subscription, delete the account in Profile, or contact us for access, correction, a copy, or deletion.

Depending on applicable state law, you may have rights to confirm processing; access and receive a portable copy; correct; delete; learn categories, sources, purposes, and recipients; withdraw sensitive-data consent; opt out of sale, targeted advertising, or qualifying profiling; appeal a decision; and receive equal service. LiveFirst does not conduct the three opt-out activities.

Submit a request to admin@symcoredesign.com or (980) 297-4432 and identify the account email and right requested. We may verify your identity. Authorized agents may act when legally permitted, subject to proof and direct verification. We will respond within the legally required period, generally 45 days. To appeal, reply to the decision or use the subject “Privacy Appeal.”

California residents may request Shine the Light information, but Symcore does not disclose personal information for another party’s independent direct marketing. This Policy also describes categories, sources, uses, recipients, retention, changes, and Do Not Track treatment for CalOPPA. The CCPA applies only when statutory thresholds and conditions are met; we do not represent that Symcore currently meets them, but we will honor applicable rights when required.

SECTION 13U.S. consumer health data privacy notice

This Section is LiveFirst’s Consumer Health Data Privacy Notice for Washington and Nevada residents and similar U.S. requirements.

Read the full notice

The complete Consumer Health Data Privacy Notice — including recipients, response deadlines, backup-deletion timing, and the Attorney General complaint mechanisms — is published as its own document.

LiveFirst Consumer Health Data Privacy Notice

13.1 Categories and sources

Depending on your choices, LiveFirst processes: today’s HealthKit steps and walking/running distance locally; the stored Health task metric, target, title, note and completion; information you type that reveals or permits an inference about health, exercise, symptoms, treatment, medication, healthcare locations, or health status; a location-task place and coordinate to the extent it reveals health status or an attempt to obtain health services; and identifiers needed to associate the stored task with your account.

This information comes from you, HealthKit after permission, and the device’s local determination that a goal was met. LiveFirst does not obtain it from data brokers or advertising networks. The reviewed features do not collect genetic data, biometric identifiers, diagnoses, prescriptions, medical-record numbers, reproductive or sexual-health records, or HealthKit clinical records.

13.2 Uses

We process consumer health data only to provide the feature you request: create and sync a Health- or place-based task, compare a local reading with your goal, mark completion, display history, secure the account, provide support, and comply with law. We do not use it for advertising, sale, data brokerage, unrelated profiling, or AI training. Selecting the integration, setting a goal, granting iOS permission, and saving the task directs the processing necessary for that feature. We will request separate consent for another purpose when required.

13.3 Recipients

Symcore has no affiliates that receive LiveFirst consumer health data. Supabase processes stored tasks, goals, selected places, completions, identifiers, and user content, but not raw HealthKit readings. Apple provides HealthKit, Location Services, MapKit, geocoding, and device processing under its own terms. RevenueCat and Expo do not receive raw HealthKit readings, Health task details, location-task coordinates, or journal content through LiveFirst’s integrations.

We do not sell consumer health data or share it with advertising networks, data brokers, or unrelated third parties. We may disclose it when required by law or for safety and legal rights as described above. We will obtain legally required authorization before a sale or unnecessary sharing; none occurs today.

13.4 Rights

Subject to law, you may confirm collection, sharing, or sale; access the data; obtain a list of recipients; withdraw consent or stop future collection or sharing; delete the data, including with processors; and appeal a refusal.

Revoke Health or Location access in iOS Settings, remove the task integration, delete the account, email admin@symcoredesign.com, or call (980) 297-4432. Revoking permission stops new access but does not delete an already-saved task; delete it or submit a verified request. Account deletion removes stored Health tasks and associated content from the active database.

We respond within applicable deadlines. Nevada deletion requests are processed without undue delay and no later than 30 days after authentication, subject to legal exceptions. If consumer health data ever exists in a backup, we will delete it within applicable limits and, for a Washington request, no later than six months after authentication. Appeal using the subject “Consumer Health Data Appeal.”

SECTION 14Children and teens

LiveFirst is not directed to children under 13, and a child under 13 may not create or use an account. Contact us if you believe we collected a child’s information so we can investigate and delete it as required. Users aged 13 through 17 may use LiveFirst only with a parent or guardian’s permission. LiveFirst’s in-app parental passcode is a product safeguard; it is not age verification, proof of parental consent to data processing, or a separate parent account. We do not sell or target ads using personal information from known minors.

SECTION 15Incident notification

If an incident triggers notification under the FTC Health Breach Notification Rule or another applicable U.S. law, we will investigate and notify affected people, regulators, or others in the manner and time the law requires.

SECTION 16Changes

We may update this Policy when LiveFirst, vendors, or law changes. We will post the update, revise the date, and provide additional notice when a change is material or consent is required. We will not collect a materially new category of consumer health data or use it for a materially new purpose without the notice and consent required by law.

SECTION 17Contact

Company
Symcore Design LLC
Legal & privacy requests
admin@symcoredesign.com
Support questions
support@symcoredesign.com
Mailing address
901 Fontaine Ct, Waxhaw, NC, 28173, United States
Questions about this policy? Email admin@symcoredesign.com. Back to top