The Horizon

Effective 2026-05-01

Privacy Policy

Effective May 1, 2026.

Effective May 1, 2026. This Privacy Policy explains how The Horizon handles the information you enter into the app.

The short version: we do not collect your data to sell it, share it, advertise against it, or train AI on it. The data you enter is encrypted. Your login and your in-app preferences live in your phone's protected storage area, where other apps cannot read them.

The rest of this document explains what is stored, where, and the controls you have over it.

Your data is yours

We do not collect your data for any purpose other than running the app for you. Specifically:

  • No advertising. We do not load advertising SDKs, do not load advertising scripts, and do not share your data with ad networks or data brokers.
  • No analytics on your health data. We do not run Google Analytics, Mixpanel, Hotjar, or any equivalent third-party analytics SDK on screens that touch your health information.
  • No AI training. Nothing you enter is sent to a third-party large-language-model provider for inference or training. The clinical engine that drives Trends, Patterns, Today's State, Hormone tracker, and similar surfaces is rule-based and runs against your own data — there is no AI / LLM feature in this release.
  • No selling, ever. We do not sell, rent, license, or transfer your data to third parties for their own use.

How we keep it that way:

  • Encrypted in transit — every request between your phone and the server is encrypted over TLS 1.2 or higher.
  • Encrypted at rest — the database encrypts every row at rest with AES-256. Backups inherit the same encryption.
  • On-device security — your authentication token and your on-device preferences (theme choice, last-used email) are stored encrypted inside the Android Keystore via expo-secure-store. They do not sit on disk in clear text.
  • Per-user isolation — row-level security policies on every per-user table scope reads, writes, and deletes to your authenticated user identifier. No other The Horizon user can read your data, and no client request — including from the official The Horizon app — can ask for someone else's data on your behalf.
  • Logs stripped — production builds strip every diagnostic console statement from the bundle so health values cannot leak into device logs or future crash-report integrations.
  • Input validation — every text field is filtered through an allowlist validator before it leaves the device and again on the server, so malformed or hostile input never reaches the database.

Who we are

The Horizon is a hormone-intelligence platform delivered as a native mobile app with two portals — HRT for women, TRT for men. It is built and operated by The Formularie LLC ("The Formularie", "we", "us"). The Horizon is the product name. When this policy refers to "The Horizon", it means the mobile app and back-end service; when it refers to "we" or "The Formularie", it means the company that operates the service. We are NOT a healthcare provider, NOT a clinic, and do NOT employ prescribers. We do NOT provide telehealth, do NOT prescribe medications, and do NOT generate diagnoses. Insights surfaced in the app are informational only.

What The Horizon collects

The Horizon collects only what you enter or generate by using the app:

  • Account information — your email address, first and last name, age, body weight, gender (selected portal), goal, and the consent records you sign.
  • Symptom and well-being data — your daily check-ins (energy, sleep quality, mood, libido, brain fog, recovery, plus hot flashes for HRT or mental clarity for TRT) and any free-text notes you add.
  • Medication and protocol data — the medications, peptides, and supplements you log; their doses, routes, schedules, and any reconstitution math; the dose-logs you record (time, amount, injection site if applicable, and notes); and the protocol stacks you build to group them.
  • Cycle data (HRT) — period markers, ovulation markers, spotting events, menopause stage, and the cycle-length / luteal-phase preferences you set.
  • Lab results — the biomarker values and units you enter, the panels they belong to, and the alerts the local interpretation engine generates from them.
  • Body and performance metrics — body composition, VO₂ max, fasting glucose, HbA1c, and similar metrics if you enter them; training-load, strength, movement, sleep-hours, and HRV entries if you record them; and the diet entries (protein, meal quality, eating window) if you log them.
  • Journal entries — your free-text journal body and tags.
  • Audit metadata — a per-user log of when your own protected information was read inside the app, recorded server-side so you can hold us accountable to it.

The Horizon does NOT collect location data, contacts, photos, advertising identifiers, microphone or camera audio/video, or any third-party analytics events that carry health information.

What The Horizon does NOT collect

The Horizon does not collect location data, contacts, photos, advertising identifiers, microphone or camera audio/video, or any device-fingerprint signals beyond what Android requires to deliver the app. See the "Your data is yours" section above for the broader stance on analytics, advertising, AI training, and third-party sharing.

How we use your information

We use your information solely to deliver the product you signed up for:

  • To render your tracking screens — calendars, check-ins, dose logs, lab history.
  • To compute the personalized reads — your Today's State on Home, your Hormone tracker tile, the Lab insights on Labs, the Performance / Fitness scores, the Patterns page correlations, the cycle predictions on HRT, and the diet read on Calendar.
  • To send you in-app reminders for medications and missed-dose follow-ups when those features are enabled.
  • To process your account-deletion request when you choose to invoke it.

We do NOT use your information to train third-party models, sell to advertisers, profile you for marketing, or share with prescribers or insurers without your explicit, separate consent.

How we store and protect your information

Operational detail beyond the "Your data is yours" summary:

  • Audit trail — reads against your protected information are recorded server-side in an immutable log keyed to your user identifier, so a misuse of access can be surfaced.
  • Engineering access — access to production systems is gated, logged, and reviewed; engineers cannot read your individual entries unless you ask us to assist with a specific request.
  • Breach notification — no system is perfectly secure. If The Formularie ever experiences a security incident that affects your information, we will notify you as required by applicable law.

Who has access to your information

  • You — through the app, end to end.
  • The Formularie's engineering team — only to the minimum extent needed to operate the service. Access to production systems is gated, logged, and reviewed.
  • Our cloud-infrastructure providers — for hosting, database, authentication, and email delivery. These providers process your data on The Formularie's behalf under contractual safeguards.

We do NOT share your information with advertisers, data brokers, employers, insurers, or any other third party unless you give explicit, separate consent — or unless required by law (a valid legal process compels disclosure).

Data retention

We retain your data for as long as your account is active. You can delete your account at any time from Settings; the deletion is processed by a server-side function that removes your auth record and every per-user row from every The Horizon table. Some operational logs (e.g. abuse-prevention rate-limit records) may be retained for a short period after deletion as required by law or to protect against fraud, but they do not contain your health information.

Your rights

You can:

  • Access — see every piece of data The Horizon holds about you, in the app, at any time.
  • Correct — edit your profile, check-ins, lab results, medications, and any other data you've entered, in the app, at any time.
  • Delete — destroy your account and all per-user data from Settings → Delete Account. This is permanent.
  • Export — request a machine-readable copy of your data. An in-app export is on the roadmap; until it ships, contact us and we will produce one for you.
  • Withdraw consent — by deleting your account.
  • Object or restrict — by ceasing use and deleting your account.

Residents of jurisdictions that grant additional rights (GDPR, CCPA / CPRA, Washington My Health My Data Act, California CMIA, etc.) have those rights as granted by law and may exercise them at any time.

Age requirement

The Horizon is intended for adults 18 and older. We do not knowingly collect information from anyone under 18. If we learn that we have collected information from someone under 18, we will delete it.

International users

The Horizon's servers run in cloud regions in the United States. If you access the app from outside the United States, your information is transferred to and processed in the United States. By using The Horizon you consent to that transfer.

Changes to this policy

We may update this policy as the product evolves. The current version date is shown at the top of this page. Material changes will be surfaced in-app and, where required by law, you will be asked to re-consent before continuing to use the affected feature. Old consent records are retained against the policy version they were signed under.

Contact

Questions, requests, or concerns about your data go to [email protected]. Privacy-specific requests are answered within the timeframes required by applicable law.

← Back to overview