LegacySave
Legal

Privacy Policy

How LegacySave collects, encrypts, stores and deletes your family's documents. Written for humans, not lawyers.

Effective: 22 Jul 2026 Last updated: 22 Jul 2026 Version 1.0

Summary in plain English

LegacySave is a document vault privacy policy you can actually read. Before the detail below, here is the short version.

What we store and why

We store the documents you choose to upload (passports, Emirates IDs, driving licences, birth and marriage certificates, education certificates), the fields our OCR reads from them (document number, expiry, issuing authority), and the details you need for an account (name, email, family membership). We use this to render the documents inside the app, to send you renewal reminders before expiry, and to share documents with the family members you invite.

What we never do with your documents

  • We do not sell your data. We do not run ads.
  • We do not send your document images to any third-party AI provider. OCR runs on servers we operate ourselves.
  • We do not read the contents of your documents for any purpose other than the OCR extraction described in this policy.
  • We do not share your documents with anyone outside the family members you invite in the app.

Information we collect

Everything below is information you or your family have chosen to give us. We do not buy data about you and we do not collect location data.

Account information (email, name, family membership)

When you create an account we collect your email address, your display name, and, if you enter them, your date of birth and phone number. If you join or create a family we store which family you belong to and your role in it (for example: guardian, member).

Documents you upload (passports, Emirates IDs, certificates)

We store the document files you upload: passports (bio page and, for Indian passports, the address page), Emirates IDs, UAE driving licences, birth and marriage certificates, education certificates, visas, and any other file you add to your vault. Files are encrypted before they touch disk.

OCR-extracted fields (document number, expiry, issuing authority)

When you upload a document our OCR extracts a small set of structured fields so the app can track expiry and show you readable metadata: document number, full name as printed, date of birth, issue date, expiry date, country, and issuing authority. For passports these are read from the Machine Readable Zone. For Emirates IDs the 15-digit number is read by regex. You can edit any field manually.

Device and diagnostic information

We collect the minimum needed to keep the app working: the device model and OS version you signed in from (used to show you your active devices and to approve new ones), the timestamp of each sign-in, and error logs when something crashes. We do not use third-party analytics SDKs and we do not track you across other apps or websites.

How we use your information

Every use of your data below is tied to a feature you asked for. If you turn off a feature, the corresponding use stops.

To render your documents and reminders inside the app

Your documents, the fields our OCR read, and the reminders you set are shown to you and to the family members you invited. This is the core purpose of the app.

To send expiry email reminders (90, 30, 7 days)

Ninety, thirty and seven days before a document expires we send a reminder email to the responsible family member. We track and we remind. Governments renew. LegacySave does not renew documents for you and cannot guarantee that a reminder email will reach your inbox, so please treat these reminders as helpful, not authoritative.

To share documents with the family members you invite

When you invite a parent, spouse or child to your family, they can see the documents in that family's vault. You control the invitation, and removing a member revokes their access immediately.

How we protect your information

This is the encrypted document storage privacy section. We name the technology so you can verify it, not because the labels are marketing.

AES-256-GCM encryption at rest in Cloudflare R2

Every file you upload is encrypted with AES-256-GCM before it is written to storage. The ciphertext lives in Cloudflare R2. The keys are held on our API server and never leave it. If a Cloudflare operator somehow read the raw object bytes, they would see ciphertext.

Self-hosted OCR — no third-party AI provider ever sees your documents

OCR runs on servers we control. We use PaddleOCR for text extraction and a small local llama3.2 model for a single field (the issuing authority place name). Your passport image is never sent to OpenAI, Google, Anthropic, AWS Textract or any other third-party cloud AI provider.

JWT sessions with device approval and Face ID app lock

Sign-in from a new device requires approval from a device already on the account. The app can be locked with Face ID or your device passcode and auto-locks after sixty seconds in the background. Sessions are short-lived JWTs and can be revoked from the Devices screen at any time.

Data storage locations

Where your data physically lives, and who runs the box.

File storage: Cloudflare R2

Encrypted document files are stored in Cloudflare R2, an S3-compatible object store. Only our API server holds the keys required to decrypt them.

Database: Supabase (managed Postgres)

Account records, family membership, document metadata and the fields our OCR extracted are stored in a managed Postgres database on Supabase. All connections use TLS.

Email: Resend (transactional only)

Renewal reminders, sign-in codes and account emails are sent through Resend. Only your email address and the message content are shared with Resend to deliver the message. We do not use email marketing tools.

Sharing and family access

Family is the unit. This section explains exactly who can see what.

Documents are only visible to invited family members

A document you upload is visible to the family members you have invited to that family and to no one else. LegacySave staff do not read your documents. We can, in a narrow set of cases (a support request you explicitly ask us to look at, a lawful legal request, an active security incident), access metadata to help you or to protect the service, and we log those accesses.

Removing a member revokes their access immediately

If you remove a member from your family, their app sessions lose access to your family's documents on the next request. Any documents they downloaded to their own device before removal are outside our control — that is a property of any sharing system, and we mention it so you can make an informed choice about who to invite.

Your rights (a UAE PDPL compliant app, and beyond)

LegacySave is built to be a UAE PDPL compliant app and to respect equivalent rights for users in India. Here is how to exercise those rights.

Access, export and correction

You can view and edit your documents and profile inside the app at any time. To request a full export of your data in a machine-readable format, or to correct information we hold about you, email the address in the Contact section below. We respond within thirty days.

In-app account deletion (Apple Guideline 5.1.1(v))

You can delete your account from inside the app: Settings, then Delete Account. Deleting your account removes your profile, revokes your sessions, and wipes your documents and OCR-extracted fields from our database and from Cloudflare R2. Backups are purged on the standard rolling schedule (up to thirty days). Emails already delivered to your inbox and any files a family member downloaded to their own device are outside our control.

UAE PDPL rights (Federal Decree-Law 45/2021)

If you are in the UAE, Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data gives you the right to access, correct, erase and port your personal data, to withdraw consent, and to object to certain processing. You can exercise each of these rights by writing to the Data Protection Officer address below.

Data-subject rights under Indian DPDP Act 2023 for users in India

If you are in India, the Digital Personal Data Protection Act, 2023 gives you the right to access, correction, erasure, grievance redressal, and to nominate another person to exercise your rights in the event of your death or incapacity. Write to the Data Protection Officer address below and identify yourself as a data principal under the DPDP Act so we can route your request correctly.

Children

Guardian-managed family accounts and minor documents

LegacySave is designed for a parent or guardian to manage a family vault that includes documents belonging to their children — an Indian passport for a minor, a UAE resident visa, a school certificate. Children under the age required for consent in their country of residence do not create their own accounts; a guardian holds the account and is responsible for the documents added to it. If a child is added as a family member, the guardian who invited them controls their access. If you believe a child has created an independent account, please contact us and we will close it.

Changes to this policy

We update this policy when the product changes in a way that affects your data, when the law changes, or when we notice an ambiguity. Material changes are announced by email to your account address and are reflected on this page with a new effective date. Continuing to use the app after a change means you accept the updated policy; if you do not, you can delete your account.

Contact the Data Protection Officer

Questions, access requests, deletion requests, or a security concern you want us to look at — write to us.

Data Protection Officer, LegacySave
Email: privacy@legacysave.space
Support: support@legacysave.space
Response time: within 48 hours for support, within 30 days for formal data-rights requests.

For our terms of use, see the Terms page. For help using the app, see Support.