Legacy — Privacy Policy
Effective date: 6 June 2026
Legacy is a private voice journal. You speak; we transcribe what you said, organise it, and help you reflect on it. Because a journal is one of the most personal things a person can own, this policy is written to be read — not skimmed past. It explains exactly what we collect, what we do with it, who touches it along the way, and how to make it all disappear.
Legacy is operated by a UK-based developer. If anything here is unclear, email ryan75195@gmail.com and you will get an answer from the person who built the app.
What we collect
We collect only what the app needs to work:
- Voice recordings. The audio you record in the app. Recordings are uploaded to our servers so they can be transcribed.
- Transcripts. The text version of your recordings, produced by AI transcription.
- Derived content. Titles, summaries, key topics, insights, sentiment analysis, chat conversations with the AI assistant, and Deep Research reports — all generated from your own journal entries.
- Account information. Your email address and a unique account identifier, provided when you sign in (with Google, Apple, or email and password). We do not see or store your password — sign-in is handled by Auth0, our authentication provider.
- Purchase state. Whether you have an active subscription and which tier. We never see your card details — payment is handled entirely by Apple, and subscription status is managed by RevenueCat.
- Usage and crash data. Basic events about how the app is used (for example, that a recording was completed) and crash reports, so we can fix bugs and improve the app.
How your journal is processed
When you record an entry, here is exactly what happens:
- The audio is uploaded over an encrypted connection to our backend, hosted on Microsoft Azure in the United Kingdom.
- The audio is sent to the Groq API (Whisper) for transcription, and the transcript is sent to the OpenAI API (GPT) to generate the summary, title, topics, insights, and sentiment. Under both providers' API terms, data sent to their APIs is not used to train their models. The app asks for your permission before your first recording is processed.
- Mathematical representations of your entries (embeddings) are stored in Pinecone, our vector database. This is what lets the AI assistant search your journal semantically — so you can ask "when did I last write about the allotment?" and get a real answer.
- The finished transcript, summary, and insights are encrypted (see below) and stored in our Azure database, where they appear in your personal feed.
When you chat with the AI assistant or run a Deep Research report, your question and the relevant journal excerpts are processed by the OpenAI API under the same no-training terms, and the results are encrypted and stored in your account.
Our service providers
We use a small number of specialist providers, each for one job:
| Provider | What they do |
|---|---|
| Microsoft Azure (UK region) | Hosting, storage, and encryption key management |
| Groq API | Audio transcription (no training on your data) |
| OpenAI API | AI text generation — summaries, insights, chat (no training on your data) |
| Pinecone | Semantic search index (embeddings) |
| Auth0 | Sign-in and account security |
| RevenueCat | Subscription status management |
| Sentry | Crash reporting |
Each provider processes data only on our instructions and only to provide their service to us.
How your journal is protected
This is the part we are proudest of, so it gets its own section.
Every piece of your journal content — transcripts, titles, summaries, insights, chat history, and reports — is encrypted at rest with keys that belong to you alone.
In technical terms: each journal item is encrypted with a strong AES-256 data key, and that data key is itself encrypted ("wrapped") by an RSA-2048 key that is unique to your account and held in Azure Key Vault, a hardened key-management service. This is called envelope encryption, and it means:
- Your entries are not stored in readable form anywhere in our database.
- Your content can only be decrypted using your key — no other user's key can unlock it.
- When you delete your account, we destroy your key, which makes every encrypted copy of your data permanently unreadable, everywhere, instantly.
All data in transit is protected with TLS (HTTPS).
What we never do
- We never sell your data. Not to anyone, not in any form.
- We never use your journal to train AI models. Not our own, and — per OpenAI's API terms — not OpenAI's either.
- We never share your data with advertisers or data brokers. There are no advertising SDKs in the app, no tracking across other apps or websites, and no targeted advertising of any kind.
- We never read your journal. Routine operations work on encrypted data. Access to decrypted content happens only inside the automated pipeline that serves the app's features to you.
How long we keep your data
We keep your journal content and account data for as long as you have an account — that's the point of a journal. Crash and usage data is kept only as long as needed to diagnose problems and understand how the app is used, and is then deleted or aggregated.
When you delete your account, everything goes. See below.
Deleting your account
You can delete your account at any time, inside the app: Settings → Delete Account. No emails, no waiting period, no "are you sure" runaround beyond a single confirmation.
Deletion is immediate and total. We purge:
- All voice recordings and transcripts
- All summaries, insights, chat history, and reports
- Your semantic search index in Pinecone
- Your account record and authentication identity
- Your personal encryption key — destroying the key renders any residual encrypted data permanently unrecoverable
This cannot be undone. We can't restore a deleted journal even if you ask us to, because we no longer hold the key that could read it.
Subscriptions and billing
Legacy offers auto-renewing monthly subscriptions (Plus and Premium), purchased through Apple's App Store. Apple processes the payment; we never see your payment details. We use RevenueCat to know whether your subscription is active so the app can unlock the right features. You can manage or cancel your subscription at any time in your App Store account settings.
Children
Legacy is not intended for children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone under 16; if we learn that we have, we will delete it.
Your rights (UK and EU GDPR)
We process your data on two lawful bases: contract (we need your recordings, transcripts, and account details to provide the journaling service you signed up for) and consent (for optional processing, which you can withdraw at any time). Usage and crash data is processed under our legitimate interest in keeping the app working and improving it, in a way that respects the privacy of your journal content.
Under UK and EU data protection law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (the in-app Delete Account button is the fastest way)
- Export your data in a portable format
- Restrict or object to certain processing
- Withdraw consent at any time, where processing is based on consent
- Complain to the Information Commissioner's Office (ICO) in the UK, or your local supervisory authority in the EU
To exercise any of these rights, email ryan75195@gmail.com. We will respond within one month.
Changes to this policy
If we change this policy, we will update the effective date at the top and, for significant changes, tell you in the app before the change takes effect. We will never quietly weaken the protections described here.
Contact
Email: ryan75195@gmail.com
Developer: UK-based independent developer
Your journal is yours. We just keep it safe.