Legal

Privacy Policy

Last updated: May 26, 2026

This Privacy Notice for LegacySafe ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share your personal information when you use our Services, including when you visit legacysafe-web-cyan.vercel.app, use our mobile application (Legacy Safe), or engage with us in other related ways. Questions or concerns? Contact us at [email protected].

Summary of Key Points
What personal information do we process?Information you provide when registering, using, or interacting with our Services.
Do we process sensitive personal information?Yes — financial data, health data, and vault contents — only with your consent or as required by law.
Do we collect information from third parties?No. We do not collect any information from third parties.
How do we process your information?To provide, improve, and administer our Services, for security and fraud prevention, and to comply with law.
With whom do we share personal information?Only in specific situations with specific third parties. We do not sell your data.
How do we keep your information safe?Through AES-256 encryption, organizational controls, and technical security measures.
What are your rights?Depending on your location, you may have rights to access, correct, delete, or port your data.
Section 01

What Information Do We Collect?

Personal information you disclose to us

We collect personal information that you voluntarily provide when you register, express interest in our products, participate in activities, or contact us. This includes:

  • Names
  • Phone numbers
  • Email addresses
  • Mailing and billing addresses
  • Job titles
  • Usernames
  • Contact preferences
  • Contact or authentication data
  • Debit/credit card numbers (processed by Stripe and Razorpay)

Sensitive information

When necessary and with your consent, we may process: health data, genetic data, financial data, biometric data, data about sexual orientation, racial or ethnic origin, political opinions, religious beliefs, credit worthiness, trade union membership, student data, and government identifiers.

Vault-specific data

As a digital estate vault, we also store the following data on your behalf — encrypted and accessible only to you and your designated nominees post-death:

  • Bank account information
  • Social media accounts
  • Capsule videos
  • Death notifications and instructions for nominees and legal delegates

Payment data

Payment data is handled by Stripe and Razorpay. We do not store your card details.

Application data

If you use our mobile app, we may collect geolocation information to provide location-based services. You can manage permissions in your device settings.


Section 02

How Do We Process Your Information?

We process your personal information to provide, improve, and administer our Services — and only when we have a valid legal reason to do so. Purposes include:

  • Facilitate account creation and authentication
  • Deliver and facilitate services to the user
  • Respond to user inquiries and offer support
  • Send administrative information (policy updates, product changes)
  • Fulfill and manage orders and payments
  • Enable user-to-user communications
  • Request feedback and improve our Services
  • Protect our Services from fraud and abuse
  • Save or protect an individual's vital interest
  • Share vault contents with nominees post-death, as designated by the user

Section 03

What Legal Bases Do We Rely On?

If you are in the EU or UK

The GDPR and UK GDPR require us to explain the valid legal bases we rely on:

  • Consent — you have given us explicit permission for a specific purpose
  • Performance of a contract — necessary to fulfil our contractual obligations to you
  • Legitimate interests — to diagnose problems, prevent fraud, and improve user experience
  • Legal obligations — compliance with law enforcement or regulatory requirements
  • Vital interests — to protect your or a third party's vital interests

If you are in Canada

We process your information with your express or implied consent. You may withdraw consent at any time. In exceptional cases permitted by law, we may process without consent (e.g., fraud prevention, legal obligations, protecting next of kin).


Section 04

When and With Whom Do We Share Your Information?

We may share personal information in the following situations:

  • Business transfers — in connection with a merger, sale, financing, or acquisition of all or part of our business
  • Designated nominees — vault contents are shared with your nominated beneficiaries and legal delegates upon verified death event

We have not sold or shared personal information to third parties for commercial purposes in the preceding 12 months, and we will not do so in the future.


Section 05

Do We Use Cookies and Tracking Technologies?

We may use cookies and similar tracking technologies (web beacons, pixels) to gather information when you interact with our Services — to maintain security, prevent crashes, fix bugs, save preferences, and support basic site functions.

We also permit third-party providers to use tracking technologies for analytics and advertising. For full details and to manage your preferences, see our Cookie Policy.


Section 06

Do We Offer AI-Based Products?

Yes. We offer AI-powered features including AI document generation and extraction. These are powered by third-party AI Service Providers including Anthropic and OpenAI.

Your input, output, and personal information may be shared with these providers solely to enable AI features. All processing adheres to our Privacy Notice and our agreements with those providers. You must not use AI features in any way that violates the terms of any AI Service Provider.

To opt out of AI features, update your preferences in your account settings.


Section 07

How Do We Handle Your Social Logins?

Our Services offer the option to register or log in using third-party social media accounts (e.g., Google, Facebook). If you do so, we receive certain profile information — typically your name, email address, and profile picture.

We use this information only as described in this Privacy Notice. We are not responsible for how your social media provider uses your data — please review their privacy policy separately.


Section 08

Is Your Information Transferred Internationally?

Our servers are located in India. If you access our Services from outside India, your information may be transferred to, stored by, and processed in India and other countries where our third-party providers operate.

If you are a resident of the EEA, UK, or Switzerland, we protect your personal information using the European Commission's Standard Contractual Clauses and, where applicable, Binding Corporate Rules (BCRs). Our Standard Contractual Clauses and BCRs can be provided upon request.


Section 09

How Long Do We Keep Your Information?

We retain your personal information only for as long as necessary for the purposes outlined in this Notice — generally for as long as you have an active account with us, unless a longer retention period is required by law.

When we have no ongoing legitimate need to process your information, we will delete or anonymize it. If immediate deletion is not possible (e.g., backup archives), we will securely isolate it until deletion is feasible.


Section 10

How Do We Keep Your Information Safe?

We implement appropriate technical and organizational security measures, including AES-256 encryption at rest, secure transmission protocols, and access controls. However, no electronic transmission over the internet is 100% guaranteed secure. We cannot promise that hackers or unauthorized third parties will never defeat our security measures. Transmission of personal information to and from our Services is at your own risk — please only access the Services within a secure environment.


Section 11

Do We Collect Information from Minors?

We do not knowingly collect, solicit data from, or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or are the parent/guardian of a minor consenting to their use. If we learn that data from a user under 18 has been collected, we will deactivate the account and delete the data. Contact us at [email protected] if you believe we have collected data from a minor.


Section 12

What Are Your Privacy Rights?

Depending on your location, applicable data protection laws may give you rights including: access and copy, rectification, erasure, restriction of processing, data portability, and objection to automated decision-making. You may also have the right to object to processing and to withdraw consent at any time.

If you are in the EEA or UK and believe we are unlawfully processing your data, you may complain to your Member State data protection authority or the UK data protection authority. In Switzerland, contact the Federal Data Protection and Information Commissioner.

Account information

You may review or update your account information at any time via your account settings. Upon requesting account termination, we will deactivate and delete your data from active databases, though we may retain some information to prevent fraud or comply with legal requirements.

For privacy rights questions, email [email protected].


Section 13

Controls for Do-Not-Track Features

Most browsers include a Do-Not-Track ("DNT") feature. No uniform technology standard for recognizing DNT signals has been finalized, so we do not currently respond to DNT browser signals. California law requires us to disclose this. If an industry standard is adopted in the future, we will update this Notice accordingly.

We do recognize and honor Global Privacy Control (GPC) signals. If your browser or extension supports GPC, we will treat it as a valid opt-out from the sale or sharing of your personal information for targeted advertising under applicable state privacy laws. Learn more at globalprivacycontrol.org.


Section 14

Do United States Residents Have Specific Privacy Rights?

If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of its sale or use for targeted advertising.

Categories of personal information we collect

CategoryExamplesCollected
A. IdentifiersName, alias, postal address, phone number, IP address, email, account nameYES
B. California Customer RecordsName, contact information, education, employment, financial informationNO
C. Protected classification characteristicsGender, age, date of birth, race and ethnicity, national origin, marital statusYES
D. Commercial informationTransaction information, purchase history, financial details, payment informationYES
E. Biometric informationFingerprints and voiceprintsYES
F. Internet or network activityBrowsing history, search history, interaction dataNO
G. Geolocation dataDevice locationNO
H. Audio, electronic, sensory informationImages and audio/video recordingsNO
I. Professional or employment informationBusiness contact details, job title, work historyYES
J. Education informationStudent records and directory informationYES
K. Inferences from personal informationProfile or summary about individual preferencesYES
L. Sensitive personal informationAccount login, biometric data, financial account access, health data, genetic data, government IDs, and moreYES

We only collect sensitive personal information as defined by applicable law or with your consent. We retain each category for as long as the user has an active account with us.

Your rights

  • Right to know whether we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies in your personal data
  • Right to request deletion of your personal data
  • Right to obtain a copy of personal data you previously shared with us
  • Right to non-discrimination for exercising your rights
  • Right to opt out of targeted advertising, sale of personal data, or profiling

How to exercise your rights

Submit a request at legacysafe-web-cyan.vercel.app/contact or contact us using the details in Section 16. We will honor your opt-out preferences if you use the Global Privacy Control.

You may designate an authorized agent to make a request on your behalf. We may deny requests from agents who cannot prove valid authorization. To appeal a declined request, email [email protected].


Section 15

Do We Make Updates to This Notice?

Yes. We may update this Privacy Notice from time to time to stay compliant with relevant laws. The updated version will be indicated by an updated "Last updated" date at the top. If we make material changes, we may notify you by prominently posting a notice or sending a direct notification. We encourage you to review this Notice frequently.


Section 16

How Can You Contact Us About This Notice?

If you have questions or comments, contact us at:

LegacySafe
First Floor, Pt#55, Samatha Nagar
Opp JNTU, KPHB
Hyderabad, Telangana 500085
India

Email: [email protected]
Website: legacysafe-web-cyan.vercel.app

Section 17

How Can You Review, Update, or Delete Your Data?

You have the right to request access to the personal information we collect, details about how we have processed it, corrections of inaccuracies, or deletion of your personal information. You may also have the right to withdraw your consent to processing.

To submit a data request, visit legacysafe-web-cyan.vercel.app/contact or contact us at [email protected]. We will consider and act upon any request in accordance with applicable data protection laws.