Privacy Policy

Effective 21 June 2026. Word-for-word the policy shown inside the LegacySave app.

Effective date: 21 June 2026

Last updated: 21 June 2026

LegacySave is a secure family document vault that helps you store identity and legal documents (such as passports, Emirates IDs, driving licences and certificates), automatically read key details from them, track their expiry dates, send you renewal reminders, and share documents with members of your family.

This Privacy Policy explains what personal data we collect, why we collect it, the legal basis on which we process it, who we share it with, where it is stored (including outside the United Arab Emirates), how we keep it secure, how long we keep it, and the rights you have over your data. Please read it carefully. Because LegacySave stores sensitive identity documents, this policy and the choices you make in the app matter — please take a moment to understand them.

We collect only the personal data we actually need to provide LegacySave's core functionality — securely storing your documents, automatically reading their key fields, tracking expiry dates and sending you reminders. We do not collect data that is not relevant to those purposes. The sensitive identity documents we hold are collected because they are the very thing the vault exists to store and protect, and because reading their fields is what powers expiry tracking and reminders; we limit our processing of them to that purpose (see Data minimisation below).

This policy is intended to be governed by the laws of the United Arab Emirates, in particular Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"). LegacySave is operated by an independent developer based in Dubai and is not established in a financial free zone such as the DIFC or ADGM; accordingly the federal PDPL governs and the competent courts of Dubai, United Arab Emirates have jurisdiction.


1. Who we are (the Data Controller)

The party responsible for your personal data (the "Data Controller", referred to in this policy as "we", "us", "our" or "LegacySave") is:

We are the controller who decides why and how your personal data is processed when you use LegacySave.

If you have any question about this policy or about how we handle your data, you can contact us at macklin.dias@gmail.com. Our privacy and data-protection contact details, including our Data Protection Officer, are in the "Contact us" section at the end of this policy.


2. What personal data we collect

We collect the following categories of personal data.

Account data

Subscription and purchase data

LegacySave offers a free tier and a paid ("Pro") tier. Paid subscriptions are sold and managed through the Apple App Store using Apple's in-app purchase system. We do not receive or store your full payment-card details. We do receive and process limited subscription data needed to give you the features you have paid for, such as your subscription status (active, expired or cancelled), your subscription tier, and the associated Apple-provided transaction or receipt identifier. Your payment itself is processed by Apple under Apple's own privacy policy.

Family member data (data about people you add)

When you add or invite a family member to your account, we collect and process information about that person:

Where you invite a family member, we process the email address you supply for that person and send an invitation email to them through our email provider (see Who we share data with and Family sharing below). This means a person you invite receives a message from us even if they are not yet a LegacySave user.

Please read the Family sharing section, which explains the lawful basis on which we process the data of family members (including minors) and your responsibilities when you provide it.

Documents you upload (sensitive personal data)

The core of LegacySave is the documents you choose to store. These are sensitive, high-risk personal data. They may include:

These documents contain government-issued identifiers, machine-readable zone (MRZ) data and facial photographs of the document holder. A passport or ID photograph is a facial image and is therefore closely related to biometric data, which is a heightened-risk category. To be clear, LegacySave does not generate, derive or store any biometric template, faceprint or facial-recognition data from these images — we store them only as ordinary picture files inside your vault. The only true biometric used anywhere in LegacySave is your device's Face ID, which is handled entirely on your device and never reaches us (see What we do not collect). We treat all uploaded documents with the heightened protection described in the Sensitive data and Security sections below.

Information automatically extracted from your documents (OCR + LLM data)

When you upload a document, our system automatically reads ("OCR") certain fields from it so the app can organise it and track expiry. This extracted data may include:

How this automated reading works — including our use of a self-hosted language model — is described in the Automated processing section.

Security, device and usage data

What we do not collect


3. Why we process your data (purposes)

We process each category of data only for specified, clear and legitimate purposes, as required by the PDPL (Article 7). Specifically:

We do not use your documents or extracted data to train any public or third-party AI model, and we do not sell your personal data.


4. Data minimisation and justification

In line with the PDPL's purpose-limitation and minimisation principles (PDPL Articles 5 and 7) and Apple's privacy requirements, we collect only the personal data that is relevant to, and necessary for, the functionality you use:

We do not collect data that is unrelated to these functions, and we do not require you to provide more than is needed.


5. Our legal basis for processing

Under the PDPL (Article 4), we must have a lawful basis for each purpose. We rely on the following:

For the personal data of family members you add or invite — including a minor's date of birth, and another adult's email address or photo — those individuals have not themselves given us their consent. We process that data on the basis of (a) your instruction and authority as the account holder to add them to your family account and, where relevant, to invite them, and (b) our and your legitimate interest in operating a shared family vault, in each case strictly limited to what is needed for the family-sharing feature. You confirm, when you provide it, that you are authorised to provide any other person's information and that, for any minor, you are their parent or legal guardian. The individual can ask us to stop processing or to delete their data by contacting us at macklin.dias@gmail.com.

We keep records that allow us to demonstrate that you gave consent where consent is the basis we rely on (PDPL Article 6).


6. How you give and withdraw consent

Giving consent. We ask for your consent in clear, simple and unambiguous language inside the app — at sign-up and, for sensitive documents, when you upload them. Where the law requires it (for example, your sensitive documents and the transfer of your data outside the UAE), we ask for separate, specific consent rather than bundling it into general acceptance of our terms.

Withdrawing consent. You can withdraw your consent at any time. You can:

Withdrawing consent is as easy as giving it. Withdrawing consent does not affect the lawfulness of any processing we carried out before you withdrew it, and we will stop the relevant processing going forward. Please note that some features (such as storing documents or OCR/LLM extraction) cannot work without the relevant consent, so withdrawing it may limit or end your ability to use those features.


7. Sensitive personal data — special handling

The documents you upload (passports, Emirates IDs, driving licences and certificates) and the fields read from them are sensitive, high-risk personal data, because they contain government identifiers and facial photographs of the document holder.

We handle this data with particular care:

Who can see your documents. LegacySave is organised around a family account, and access to documents is scoped to your family account. This means that any member of your family account can view and access the documents stored in that family's vault, not only documents specifically marked as shared with them. The per-document "share" setting inside the app is an additional organisational control that helps you tag or surface documents to particular members; it is not the security boundary that limits who can read a document. The boundary is your family account. Please keep this in mind when deciding what to store, and when adding members to your family account. We are working towards finer-grained, share-level access controls; until those ship, treat anything you upload as visible to everyone in your family account.


8. Where your data is stored and international transfers

Your data is stored on servers located outside the United Arab Emirates. When you use LegacySave, your personal data — including your sensitive identity documents and the contents of emails we send on your behalf — is transferred to, stored and processed in other countries.

The destinations include:

These countries may have data-protection standards that differ from those of the UAE.

Our legal basis for the transfer. Because the UAE has not published a definitive list of countries it recognises as providing an adequate level of protection, we treat these transfers as transfers to countries without a formal adequacy decision. We therefore rely on:

We disclose these transfers to you, as required by PDPL Article 13, so you understand where your data goes and on what basis. If you do not consent to your data being transferred outside the UAE, you will not be able to use LegacySave, because the service depends on this infrastructure.


9. How we keep your data secure

We apply technical and organisational measures designed to protect your data (PDPL Article 20), including:

No system can be guaranteed to be completely secure. While we work hard to protect your data, we encourage you to keep your account credentials confidential and to use your device's Face ID / passcode app-lock.


10. How long we keep your data, and deletion

Retention period. We keep your personal data only for as long as we need it for the purposes set out in this policy:

Deleting individual documents. You can delete individual documents at any time from within the app. When you do, the document's records are removed from our database, and we then delete the encrypted file from storage. File deletion is performed on a best-effort basis: if a storage deletion does not succeed immediately, the failure is detected and logged, and the file is removed in a follow-up clean-up. We therefore delete your file, but cannot guarantee that removal is instantaneous in every case.

Deleting your account. You can delete your account and all associated personal data at any time from within the app: open the Profile tab and choose Delete Account. You can also request deletion by emailing us at macklin.dias@gmail.com from your registered address. When your account is deleted, your document records are removed from our database and the encrypted files are deleted from storage on the same best-effort basis described above.


11. Your rights under UAE data-protection law

Under the PDPL, you have the following rights over your personal data. You can exercise any of them by using the relevant controls in the app or by emailing us at macklin.dias@gmail.com. We will respond within 30 days of receiving your request (and where the request is complex or we receive a number of requests, we may extend this period to the extent permitted by law and will tell you if we do). We may need to verify your identity before acting.


12. Automated processing (OCR and self-hosted LLM)

When you upload a document, it is automatically processed by a two-stage pipeline to read key fields (such as document number, names, dates, issuing authority and country):

  1. An optical-character-recognition (OCR) engine reads the text and, where present, the passport machine-readable zone (MRZ) from the image; and
  2. Where the MRZ alone is not sufficient, a self-hosted large language model (LLM) interprets the extracted text to fill in remaining structured fields.

Both stages run on our own self-hosted servers. Your documents and their text are not sent to any public or third-party AI service (such as a commercial AI API) for this processing — it stays on our infrastructure. We use this processing only to label your documents and to power expiry tracking, reminders and search; it does not make any decision that produces legal or similarly significant effects about you.

Automated reading can sometimes make mistakes. If a field is read incorrectly, you can correct it in the app. You also have the right to object to automated processing under PDPL Article 18 — contact us at macklin.dias@gmail.com.


13. Who we share data with (processors and sub-processors)

We do not sell your personal data. We share it only with service providers ("processors") who help us run LegacySave, and only as needed to provide the service. We require, and are putting in place, data processing agreements with these processors obliging them to protect your data to a standard equivalent to the PDPL and to act only on our instructions.

Our processors include:

Because our OCR and LLM processing is self-hosted, your documents are read on our own servers running on the above hosting providers, rather than being sent to an external AI service.

We may also disclose data where required by law, court order, or a valid request from a competent authority, or to protect our rights, your safety, or the safety of others.


14. Family sharing and inviting others

LegacySave lets you build a family account, add or invite family members, and share documents with them.

Please share responsibly: only add or invite people, and only share documents, where you have the authority to do so. You can manage and revoke sharing, and remove members, from within the app.


15. Data breaches

We maintain a breach-response plan and apply security measures designed to prevent unauthorised access to your data (PDPL Article 20). In the event of a personal data breach, we will, without undue delay after becoming aware of it and within the timeframes required by applicable UAE law, notify the UAE Data Office and, where the breach is likely to result in a high risk to your rights, notify you, in accordance with the PDPL (Article 9). Our notification to you will describe, to the extent we can, the nature of the breach, the categories of data affected, the likely consequences, the measures we have taken or propose to take, and how you can contact us for more information.


16. Children and eligibility

LegacySave is not directed at children and is intended for users aged 18 or over. We do not knowingly create accounts for, or collect personal data directly from, anyone under 18.

You may choose to store documents that relate to a minor in your family (for example, a child's passport), and to add a minor as a family member with limited details such as their date of birth. If you do, you, as the adult account holder, are responsible for those documents and details and for ensuring you are authorised to store and process them on the minor's behalf (see Family sharing and Our legal basis for processing).

If you believe a minor has created their own account, please contact us at macklin.dias@gmail.com so we can take appropriate action.


17. Complaints and the supervisory authority

If you have a concern about how we handle your personal data, please contact us first at macklin.dias@gmail.com — we want to put things right.

You also have the right to lodge a complaint with the UAE Data Office, the federal supervisory authority established under Federal Decree-Law No. 44 of 2021, which operates the complaints and grievance system under the PDPL.


18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in the app, our service providers, or the law. This policy carries both an Effective date and a Last updated date at the top; when we publish a materially revised version, we will set a new Effective date.

We keep prior versions and a record of material changes so you can see what changed and when.


19. Governing law

This Privacy Policy and any matter relating to it are intended to be governed by the laws of the United Arab Emirates, including the PDPL (Federal Decree-Law No. 45 of 2021). LegacySave is operated by an independent developer based in Dubai and is not established in a financial free zone such as the DIFC or ADGM; accordingly the federal PDPL governs and the competent courts of Dubai, United Arab Emirates have jurisdiction.


20. Contact us

For any privacy question, request, or to exercise your rights:

Given that LegacySave carries out large-scale processing of sensitive identity documents combined with systematic automated (OCR + LLM) processing, we treat the appointment of a Data Protection Officer as required and have appointed the DPO named above, whom you may contact directly for any matter relating to your personal data or this policy.