Legacy is built on a simple premise: what you share here is yours. We designed Legacy to hold your inner life with care — not to monetize it, not to profile you, and not to sell access to you to advertisers. This policy explains what we collect, why, and what we will never do.
We've written it to be accurate rather than reassuring. Where something is imperfect, it says so.
1. Who We Are
Legacy is operated by Legacy AI LLC, a Pennsylvania limited liability company. Our contact address is:
Legacy AI LLC
502 W 7th St, STE 100, Erie, PA 16502, USA
shawn@legacy-ai.app
Legacy is currently offered only to users in the United States, and you must be 18 or older to use it.
2. What We Collect
We collect only what's necessary to operate the app:
- Account information — your name and email address when you create an account, and a record of the date you accepted these terms and which version you accepted.
- Age confirmation — we ask your date of birth at signup to confirm you are 18 or older. We store only the yes-or-no answer. Your birthdate is used to compute it and then discarded — we have no reason to keep it, so we don't.
- Journal entries — the text, photos, video, audio, and documents you create. Journal content is encrypted on your device before being stored.
- Social content — posts, comments, and interactions you share with your circles. When you choose to share something, you are choosing to make it visible to others — social content is stored in a form that allows it to be displayed to the people you share it with.
- Direct messages — messages between you and other people are encrypted end-to-end. Conversations with AI Allies and Legacy AI are handled differently; see Section 5.
- Incognito / alias content — content created under an alias. Aliases use their own separate encryption keys, and the record connecting an alias to your real account is held in an isolated collection that no user can read. Alias handles and bios visible to others are stored in displayable form.
- Survey responses — if you complete the personality, values, attachment, or legacy surveys, we store your answers and the resulting profile. These are processed by our AI provider to generate your results, and they inform your AI profile.
- AI profile data — themes, values, and patterns Legacy's AI infers from content you share with it over time. Stored encrypted.
- Voice recordings — when you record a voice entry, the audio is stored and encrypted. If you request a transcript, the audio must be readable by Google Speech-to-Text, which reads it directly from storage — so it is briefly stored without our encryption during the transcription window, then encrypted once transcription completes. Audio you attach without transcribing is encrypted immediately. Transcripts are processed by Anthropic for cleanup and formatting.
- Live speech — some features let you speak instead of type. These use your device's built-in speech recognition, which may send audio off your device for processing: to Apple on iOS, or to Google on Android, each under their own privacy terms.
- Shared-in content — when you share something into Legacy from another app, it passes through a shared container on your device before Legacy takes it in. It sits there briefly without our encryption until the app collects and clears it. See Section 5.
- Feedback reports — if you submit feedback through the app, we collect your display name, email, your description, your current screen, device model, OS version, app version, recent error logs, and a screenshot of the app at the time of submission. Screenshots may contain visible app content. Feedback is stored unencrypted.
- Crash and error reports — we use Firebase Crashlytics in released builds to collect crashes and non-fatal errors, tagged with your user ID, including device state at the time. These are sent to Google.
- Usage data — counters for AI interactions and feature usage, to enforce plan limits and manage costs. Never used for advertising.
- Device and session information — device type, OS version, timezone, and push notification token, for compatibility, debugging, and notification delivery.
- Invite codes — every account is issued an invite code. If you redeem someone else's, we store the code and the relationship between the two accounts.
- Moderation reports — if you report content, we store the report. Reports are retained after account deletion as moderation history.
We do not collect your phone number, your contacts, or your location.
One honest caveat on that last point: we store your timezone so that reminders arrive at the right hour. A timezone is not your location, but it does indicate roughly what part of the world you are in. We would rather say so than let you discover it.
3. What We Don't Collect
We do not collect advertising identifiers. We do not build advertising profiles. We do not sell your data. We do not share your data with data brokers. We do not track your location. We do not read your journal entries to target you with ads — ever.
4. How We Use Your Data
Your data is used for exactly one purpose: to operate Legacy for you.
- Journal entries and messages are stored so you can access them.
- AI profile and survey data personalize your Legacy AI experience.
- Usage counters enforce plan limits and help us manage infrastructure costs.
- Account information identifies you, allows account-related email, and lets us meet legal obligations.
- Crash reports help us find and fix bugs without requiring you to report them.
- Content you post to shared or community spaces is automatically screened for prohibited material before it publishes, so that reports are not the only thing standing between users and abuse. Your private journal is never screened, and end-to-end encrypted messages cannot be — we have no way to read them.
We do not use your content to train AI models. Content you share with our AI features is sent to Anthropic's API for processing. Under Anthropic's commercial API terms, that content is not used to train their models. It is retained under Anthropic's standard commercial retention terms, and content flagged by their automated safety systems may be retained longer. See Anthropic's Privacy Center for current periods.
5. Encryption — and Its Limits
Your private content is encrypted before it reaches our servers. What you choose to share is different: social posts, comments, and alias handles and bios are stored in a form that allows them to be displayed to others, because that is what sharing means. The distinction is yours to make.
- Journal entries, AI profile data, surveys, and goals are encrypted with AES-256-GCM using a Device Encryption Key generated on your device. That key is held in your device's hardware-backed secure storage — the iOS Keychain or the Android Keystore — and never leaves your device unencrypted.
- Direct messages between people are encrypted end-to-end using X25519 key agreement. Only the intended recipients can decrypt them. We cannot.
- Incognito messages use separate per-alias keypairs, so alias conversations are not decryptable with your main account's keys.
- Recovery phrase — you receive a 12-word BIP39 recovery phrase at setup. It is the only way to recover your encrypted content if you lose access to your device. We cannot recover it or your data without it.
Where content is necessarily readable
Being honest about this matters more than sounding airtight:
- AI conversations are not end-to-end encrypted. They are encrypted at rest with your device key, but an AI cannot respond to something it cannot read — so the content of a message you send to Legacy AI or an Ally is transmitted in readable form to our AI provider. This is inherent to the feature, not a shortcoming of it.
- Voice transcription requires your audio to be readable by Google Speech-to-Text during the transcription window, as described in Section 2.
- Transcripts are briefly held on our servers in readable form between transcription and the point where your device encrypts and stores them.
- Content shared into Legacy from other apps sits briefly in a shared container on your device before the app collects and clears it.
- The link between an alias and your real account is protected by access controls, not by encryption. No user can read it. We can.
Your journal entries, AI profile, and messages to other people are not stored in readable form on our servers. Firebase holds only an encrypted copy of your encryption key and cannot decrypt your content. If you lose your recovery phrase and your device, your encrypted content is unrecoverable — by you and by us.
6. Third-Party Services
Legacy uses a small number of third-party services. Each receives only what its function requires:
- Firebase (Google) — database, authentication, push notifications, file storage, and crash reporting. Your encrypted content is stored here. Firebase holds only encrypted copies of your keys and cannot decrypt your personal content. Crash reports include your user ID and device state. Firebase Privacy Policy.
- Anthropic — powers Legacy AI, AI Allies, survey interpretation, and transcript cleanup. Content you share with these features is sent to Anthropic's API. It is not used to train their models. Anthropic Privacy Policy.
- Google Speech-to-Text — transcribes voice entries. Google's service reads the audio directly from storage; it never passes through Legacy's servers. Data logging is disabled for our project, so Google does not retain your audio to improve its services. Google Cloud Privacy Notice.
- Apple and Google device speech recognition — where you use live speech input, audio may be processed by your device's speech recognition service: Apple's on iOS, Google's on Android, each under their own terms. See Apple's privacy policy and Google's privacy policy.
We do not use advertising SDKs or data brokers, and we do not integrate with social networks for tracking.
7. Account Deletion
You can delete your account at any time from within the app — open the menu, then either Profile or Settings → Account. You can also request deletion by writing to shawn@legacy-ai.app.
- When you request deletion, your profile and feed posts are hidden immediately and your sessions are ended.
- If you signed in with Apple, we revoke Legacy's access to your Apple ID at the moment you request deletion. If that step fails for a technical reason, deletion still proceeds — you can also revoke access yourself in your Apple ID settings.
- A 30-day grace period begins. Signing back in during that window restores your account.
- After 30 days, your journal entries, messages, AI profile, surveys, goals, media, and account are permanently deleted. This cannot be undone.
What is not deleted
Some material survives deletion, because it belongs to conversations other people are part of or to records we are obliged to keep:
- Direct messages you sent to other people are anonymized to "Legacy Echo" rather than deleted, so their side of the conversation stays intact. The thread becomes read-only.
- Content you posted under an alias — forum posts, comments, chatroom messages — is anonymized to "Legacy Ghost" and retained.
- Your public encryption key is preserved so other people's encrypted messages to you remain readable to them.
- Moderation reports you submitted, or that were filed about you, are retained as moderation history.
- Deletion requests generate an operational email to our support address.
Routine automated backups are encrypted and retained on a fixed schedule: database exports for 7 days, authentication records for 30 days, and pre-restore snapshots for up to 90 days. After that they are permanently deleted.
8. Age
Legacy is for adults. You must be 18 or older to create an account. We do not knowingly collect personal information from anyone under 18, and we will close any account we learn belongs to a minor.
If you believe a minor has created an account, contact us at shawn@legacy-ai.app.
9. Your Rights
- Access — you can request a copy of the personal data we hold about you. Because your private content is encrypted with a key only you hold, what we can produce from our servers is encrypted; readable content can only come from your device. Contact us and we will help you assemble what is available.
- Correction — you can update your account information in the app.
- Deletion — you can delete your account at any time, subject to the retained material described in Section 7.
- Portability — you can export your goals and calendar entries from within the app today. A full export is not yet built; if you want your data before it is, write to us and we will do what we can by hand.
- Objection — you can object to particular processing by contacting us.
If you are in California, you have rights under the CCPA/CPRA. To exercise any right, contact shawn@legacy-ai.app. We will respond within 30 days.
We do not sell or share personal information as those terms are defined under the CCPA, and we have not done so in the preceding 12 months.
10. Security
Security is structural, not aspirational. Alongside the encryption described in Section 5, we use Firebase Security Rules to restrict data access, HTTPS for all transmission, and ongoing review. We conducted a formal security audit in July 2026 covering the encryption implementation, and a full pre-launch audit in August 2026 covering the codebase, access rules, and data handling.
No system is immune to breach. If a security incident affects your data, we will notify you as required by law.
11. Legal Requests and Emergencies
We may disclose information when the law requires it, or when we believe in good faith that disclosure is necessary to prevent an imminent risk of serious harm.
What that means in practice:
- We require valid legal process. We do not hand over user information on informal request, and we push back on demands that are overbroad or improperly issued.
- We will tell you. If we receive a request for your information, we will notify you — unless a court order forbids it, or we believe notice would put someone at risk.
- Most of what we hold, we cannot read. A demand for your journal entries or your private messages produces ciphertext we have no key for. We cannot decrypt it for anyone, including a court.
- The connection between your alias and your account is something we can see. It is kept in an isolated collection no user can read, and we never disclose it voluntarily. But it is data we hold, and valid legal process can compel it. If alias anonymity is critical to your safety, understand that boundary before relying on it.
12. Changes to This Policy
We may update this policy. When changes are material we will notify you in the app or by email. The effective date above reflects the most recent update. Continued use after changes take effect constitutes acceptance.