Legacy — Privacy Policy

Effective date: 6 June 2026

Legacy is a private voice journal. You speak; we transcribe what you said, organise it, and help you reflect on it. Because a journal is one of the most personal things a person can own, this policy is written to be read — not skimmed past. It explains exactly what we collect, what we do with it, who touches it along the way, and how to make it all disappear.

Legacy is operated by a UK-based developer. If anything here is unclear, email ryan75195@gmail.com and you will get an answer from the person who built the app.

What we collect

We collect only what the app needs to work:

What about location? The app reads your device's location once, on the device itself, solely to calculate local sunrise and sunset times for automatic dark mode. Your location is never transmitted to our servers, never stored, and never shared. It does not leave your phone.

How your journal is processed

When you record an entry, here is exactly what happens:

  1. The audio is uploaded over an encrypted connection to our backend, hosted on Microsoft Azure in the United Kingdom.
  2. The audio is sent to the Groq API (Whisper) for transcription, and the transcript is sent to the OpenAI API (GPT) to generate the summary, title, topics, insights, and sentiment. Under both providers' API terms, data sent to their APIs is not used to train their models. The app asks for your permission before your first recording is processed.
  3. Mathematical representations of your entries (embeddings) are stored in Pinecone, our vector database. This is what lets the AI assistant search your journal semantically — so you can ask "when did I last write about the allotment?" and get a real answer.
  4. The finished transcript, summary, and insights are encrypted (see below) and stored in our Azure database, where they appear in your personal feed.

When you chat with the AI assistant or run a Deep Research report, your question and the relevant journal excerpts are processed by the OpenAI API under the same no-training terms, and the results are encrypted and stored in your account.

Our service providers

We use a small number of specialist providers, each for one job:

Provider What they do
Microsoft Azure (UK region) Hosting, storage, and encryption key management
Groq API Audio transcription (no training on your data)
OpenAI API AI text generation — summaries, insights, chat (no training on your data)
Pinecone Semantic search index (embeddings)
Auth0 Sign-in and account security
RevenueCat Subscription status management
Sentry Crash reporting

Each provider processes data only on our instructions and only to provide their service to us.

How your journal is protected

This is the part we are proudest of, so it gets its own section.

Every piece of your journal content — transcripts, titles, summaries, insights, chat history, and reports — is encrypted at rest with keys that belong to you alone.

In technical terms: each journal item is encrypted with a strong AES-256 data key, and that data key is itself encrypted ("wrapped") by an RSA-2048 key that is unique to your account and held in Azure Key Vault, a hardened key-management service. This is called envelope encryption, and it means:

All data in transit is protected with TLS (HTTPS).

What we never do

How long we keep your data

We keep your journal content and account data for as long as you have an account — that's the point of a journal. Crash and usage data is kept only as long as needed to diagnose problems and understand how the app is used, and is then deleted or aggregated.

When you delete your account, everything goes. See below.

Deleting your account

You can delete your account at any time, inside the app: Settings → Delete Account. No emails, no waiting period, no "are you sure" runaround beyond a single confirmation.

Deletion is immediate and total. We purge:

This cannot be undone. We can't restore a deleted journal even if you ask us to, because we no longer hold the key that could read it.

Subscriptions and billing

Legacy offers auto-renewing monthly subscriptions (Plus and Premium), purchased through Apple's App Store. Apple processes the payment; we never see your payment details. We use RevenueCat to know whether your subscription is active so the app can unlock the right features. You can manage or cancel your subscription at any time in your App Store account settings.

Children

Legacy is not intended for children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone under 16; if we learn that we have, we will delete it.

Your rights (UK and EU GDPR)

We process your data on two lawful bases: contract (we need your recordings, transcripts, and account details to provide the journaling service you signed up for) and consent (for optional processing, which you can withdraw at any time). Usage and crash data is processed under our legitimate interest in keeping the app working and improving it, in a way that respects the privacy of your journal content.

Under UK and EU data protection law, you have the right to:

To exercise any of these rights, email ryan75195@gmail.com. We will respond within one month.

Changes to this policy

If we change this policy, we will update the effective date at the top and, for significant changes, tell you in the app before the change takes effect. We will never quietly weaken the protections described here.

Contact

Email: ryan75195@gmail.com
Developer: UK-based independent developer

Your journal is yours. We just keep it safe.