Privacy Policy
Effective date: 21 June 2026
Last updated: 21 June 2026
LegacySave is a secure family document vault that helps you store identity and legal documents (such as passports, Emirates IDs, driving licences and certificates), automatically read key details from them, track their expiry dates, send you renewal reminders, and share documents with members of your family.
This Privacy Policy explains what personal data we collect, why we collect it, the legal basis on which we process it, who we share it with, where it is stored (including outside the United Arab Emirates), how we keep it secure, how long we keep it, and the rights you have over your data. Please read it carefully. Because LegacySave stores sensitive identity documents, this policy and the choices you make in the app matter — please take a moment to understand them.
We collect only the personal data we actually need to provide LegacySave's core functionality — securely storing your documents, automatically reading their key fields, tracking expiry dates and sending you reminders. We do not collect data that is not relevant to those purposes. The sensitive identity documents we hold are collected because they are the very thing the vault exists to store and protect, and because reading their fields is what powers expiry tracking and reminders; we limit our processing of them to that purpose (see Data minimisation below).
This policy is intended to be governed by the laws of the United Arab Emirates, in particular Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"). LegacySave is operated by an independent developer based in Dubai and is not established in a financial free zone such as the DIFC or ADGM; accordingly the federal PDPL governs and the competent courts of Dubai, United Arab Emirates have jurisdiction.
1. Who we are (the Data Controller)
The party responsible for your personal data (the "Data Controller", referred to in this policy as "we", "us", "our" or "LegacySave") is:
- Legal entity / trade licence name: Macklin Dias
- Trade licence number: Not applicable — operated by an individual freelance developer
- Legal status: Independent (freelance) software developer, Dubai, United Arab Emirates
- Registered address: Dubai, United Arab Emirates
- Contact email: macklin.dias@gmail.com
We are the controller who decides why and how your personal data is processed when you use LegacySave.
If you have any question about this policy or about how we handle your data, you can contact us at macklin.dias@gmail.com. Our privacy and data-protection contact details, including our Data Protection Officer, are in the "Contact us" section at the end of this policy.
2. What personal data we collect
We collect the following categories of personal data.
Account data
- Your full name
- Your email address
- Your password (stored only as a secure cryptographic hash — we never store your password in plain text)
- Your role within the app (for example, account owner or family member)
Subscription and purchase data
LegacySave offers a free tier and a paid ("Pro") tier. Paid subscriptions are sold and managed through the Apple App Store using Apple's in-app purchase system. We do not receive or store your full payment-card details. We do receive and process limited subscription data needed to give you the features you have paid for, such as your subscription status (active, expired or cancelled), your subscription tier, and the associated Apple-provided transaction or receipt identifier. Your payment itself is processed by Apple under Apple's own privacy policy.
Family member data (data about people you add)
When you add or invite a family member to your account, we collect and process information about that person:
- Their name
- Their relationship to you
- Their date of birth (which, for a child, is the date of birth of a minor)
- Their email address
- An optional profile photo
Where you invite a family member, we process the email address you supply for that person and send an invitation email to them through our email provider (see Who we share data with and Family sharing below). This means a person you invite receives a message from us even if they are not yet a LegacySave user.
Please read the Family sharing section, which explains the lawful basis on which we process the data of family members (including minors) and your responsibilities when you provide it.
Documents you upload (sensitive personal data)
The core of LegacySave is the documents you choose to store. These are sensitive, high-risk personal data. They may include:
- Images and PDF files of passports (including the photo page and the machine-readable zone / MRZ)
- Images of Emirates IDs
- Images of driving licences
- Images of certificates and other identity or legal documents you choose to upload
These documents contain government-issued identifiers, machine-readable zone (MRZ) data and facial photographs of the document holder. A passport or ID photograph is a facial image and is therefore closely related to biometric data, which is a heightened-risk category. To be clear, LegacySave does not generate, derive or store any biometric template, faceprint or facial-recognition data from these images — we store them only as ordinary picture files inside your vault. The only true biometric used anywhere in LegacySave is your device's Face ID, which is handled entirely on your device and never reaches us (see What we do not collect). We treat all uploaded documents with the heightened protection described in the Sensitive data and Security sections below.
Information automatically extracted from your documents (OCR + LLM data)
When you upload a document, our system automatically reads ("OCR") certain fields from it so the app can organise it and track expiry. This extracted data may include:
- Document number
- Full name as printed on the document
- Date of birth
- Issue date and expiry date
- Issuing authority
- Country of issue
How this automated reading works — including our use of a self-hosted language model — is described in the Automated processing section.
Security, device and usage data
- Trusted device identifiers
- Authentication session tokens (JWT) used to keep you signed in
- Audit logs of key actions taken in your account (for security and accountability)
- Expiry-reminder schedules linked to your documents
What we do not collect
- Face ID / biometric app-lock is handled entirely by your device's operating system (iOS). The app uses Face ID or your device passcode only as an on-device lock. We never receive, see or store your fingerprint, face scan or any other biometric data.
3. Why we process your data (purposes)
We process each category of data only for specified, clear and legitimate purposes, as required by the PDPL (Article 7). Specifically:
- Account data — to create and manage your account, authenticate you, communicate with you about your account, and provide customer support.
- Subscription and purchase data — to determine your tier (free or Pro), unlock and provide the paid features you have subscribed to, recognise renewals and cancellations, prevent abuse of paid features, and keep records of your subscription.
- Family member data — to let you add and invite family members, send invitation emails to people you invite, organise documents by person, and (where you choose) share documents with them.
- Documents you upload — to store your documents securely in your private vault so you and your family account can access them when needed.
- OCR- and LLM-extracted data — to automatically read key fields from your documents so the app can label them, track issue and expiry dates, and power search and reminders.
- Expiry dates and reminder schedules — to track when your documents expire and send you timely renewal reminders.
- Security, device and usage data — to keep your account secure, detect and prevent unauthorised access and misuse, maintain audit logs, and operate the service reliably.
- Email address — to send transactional emails such as email verification, password reset, expiry reminders and family invitations.
We do not use your documents or extracted data to train any public or third-party AI model, and we do not sell your personal data.
4. Data minimisation and justification
In line with the PDPL's purpose-limitation and minimisation principles (PDPL Articles 5 and 7) and Apple's privacy requirements, we collect only the personal data that is relevant to, and necessary for, the functionality you use:
- We collect sensitive identity documents because securely storing them is the core purpose of the app — a document vault cannot work without the documents.
- We perform automated field extraction on those documents because that extracted data is what enables document labelling, expiry tracking and renewal reminders, which are the service's central features.
- We collect family-member details and subscription data only to the extent needed to provide family sharing and the tier you have chosen.
We do not collect data that is unrelated to these functions, and we do not require you to provide more than is needed.
5. Our legal basis for processing
Under the PDPL (Article 4), we must have a lawful basis for each purpose. We rely on the following:
- Your consent (PDPL Articles 4, 5 and 6) — especially for storing and processing your sensitive identity documents, and for the automated OCR and language-model extraction of fields from them. Because these are sensitive personal data, we rely on your explicit, freely given, specific and informed consent.
- Performance of our agreement with you — to provide the LegacySave service you have signed up for, manage your account, and provide and administer your subscription.
- Compliance with legal obligations — where we must process data to meet applicable UAE legal requirements.
- Our legitimate interests — for limited purposes such as securing the service, preventing fraud and misuse, sending invitations you ask us to send, and maintaining audit logs, provided these do not override your rights.
For the personal data of family members you add or invite — including a minor's date of birth, and another adult's email address or photo — those individuals have not themselves given us their consent. We process that data on the basis of (a) your instruction and authority as the account holder to add them to your family account and, where relevant, to invite them, and (b) our and your legitimate interest in operating a shared family vault, in each case strictly limited to what is needed for the family-sharing feature. You confirm, when you provide it, that you are authorised to provide any other person's information and that, for any minor, you are their parent or legal guardian. The individual can ask us to stop processing or to delete their data by contacting us at macklin.dias@gmail.com.
We keep records that allow us to demonstrate that you gave consent where consent is the basis we rely on (PDPL Article 6).
6. How you give and withdraw consent
Giving consent. We ask for your consent in clear, simple and unambiguous language inside the app — at sign-up and, for sensitive documents, when you upload them. Where the law requires it (for example, your sensitive documents and the transfer of your data outside the UAE), we ask for separate, specific consent rather than bundling it into general acceptance of our terms.
Withdrawing consent. You can withdraw your consent at any time. You can:
- Stop uploading documents at any time;
- Delete individual documents from within the app;
- Adjust your sharing and reminder settings;
- Request deletion of your entire account (see Your rights and Retention and deletion); or
- Email us at macklin.dias@gmail.com to withdraw a specific consent.
Withdrawing consent is as easy as giving it. Withdrawing consent does not affect the lawfulness of any processing we carried out before you withdrew it, and we will stop the relevant processing going forward. Please note that some features (such as storing documents or OCR/LLM extraction) cannot work without the relevant consent, so withdrawing it may limit or end your ability to use those features.
7. Sensitive personal data — special handling
The documents you upload (passports, Emirates IDs, driving licences and certificates) and the fields read from them are sensitive, high-risk personal data, because they contain government identifiers and facial photographs of the document holder.
We handle this data with particular care:
- We process it only on the basis of your explicit consent (PDPL Articles 5 and 6).
- We apply heightened technical and organisational safeguards (PDPL Article 20), including the encryption and access controls described in the Security section.
- We do not use it for any purpose other than providing the service.
Who can see your documents. LegacySave is organised around a family account, and access to documents is scoped to your family account. This means that any member of your family account can view and access the documents stored in that family's vault, not only documents specifically marked as shared with them. The per-document "share" setting inside the app is an additional organisational control that helps you tag or surface documents to particular members; it is not the security boundary that limits who can read a document. The boundary is your family account. Please keep this in mind when deciding what to store, and when adding members to your family account. We are working towards finer-grained, share-level access controls; until those ship, treat anything you upload as visible to everyone in your family account.
8. Where your data is stored and international transfers
Your data is stored on servers located outside the United Arab Emirates. When you use LegacySave, your personal data — including your sensitive identity documents and the contents of emails we send on your behalf — is transferred to, stored and processed in other countries.
The destinations include:
- Japan — our managed database is hosted in Tokyo, Japan.
- The United States and/or Europe — our application servers and self-hosted OCR/LLM servers run on third-party hosting providers located in these regions.
- The United States and/or Europe — our transactional email provider (Resend), which processes the email addresses and email contents involved in verification, password-reset, reminder and family-invitation messages, operates outside the UAE in these regions.
- Global infrastructure — our encrypted file-storage provider operates globally and may store or route the encrypted files through data centres in various countries. The files are encrypted with AES-256-GCM before storage, which is a key safeguard for routing sensitive ID files through global infrastructure.
These countries may have data-protection standards that differ from those of the UAE.
Our legal basis for the transfer. Because the UAE has not published a definitive list of countries it recognises as providing an adequate level of protection, we treat these transfers as transfers to countries without a formal adequacy decision. We therefore rely on:
- Your explicit, informed consent to the international transfer (PDPL Article 23), which we ask for separately at sign-up/upload and keep a record of; and, as an additional safeguard,
- Contractual safeguards that we require and are putting in place (such as data processing agreements and standard contractual clauses) with our overseas providers, intended to require them to protect your data to a standard equivalent to the PDPL (PDPL Article 22).
We disclose these transfers to you, as required by PDPL Article 13, so you understand where your data goes and on what basis. If you do not consent to your data being transferred outside the UAE, you will not be able to use LegacySave, because the service depends on this infrastructure.
9. How we keep your data secure
We apply technical and organisational measures designed to protect your data (PDPL Article 20), including:
- Encryption at rest: your document files are encrypted using AES-256-GCM before they are stored.
- Encryption in transit: all data sent between the app and our servers is protected with TLS / HTTPS.
- Access controls: access is enforced at the family-account level — our systems gate every document request on the requester belonging to the owning family account (see Sensitive data for what this means in practice).
- Self-hosted OCR and LLM: the automated reading of your documents runs on our own self-hosted servers, not on a public third-party AI service.
- Audit logging: key actions are logged so we can detect and investigate misuse.
- Password protection: passwords are stored only as secure cryptographic hashes.
No system can be guaranteed to be completely secure. While we work hard to protect your data, we encourage you to keep your account credentials confidential and to use your device's Face ID / passcode app-lock.
10. How long we keep your data, and deletion
Retention period. We keep your personal data only for as long as we need it for the purposes set out in this policy:
- We retain your account and document data for as long as your account remains active. We treat an account as inactive if you have not signed in or used the app for 12 months.
- Where an account has been inactive for that period, we will send a notice to your registered email address and, if the account remains inactive for a further 30 days after that notice, we will delete the account and its associated documents. This sets a maximum retention tied to the criteria above, consistent with PDPL Article 13.
- We may retain limited information for a short period beyond deletion where we are required to do so by law, or to resolve disputes, prevent fraud or enforce our terms; such data is deleted once it is no longer needed.
Deleting individual documents. You can delete individual documents at any time from within the app. When you do, the document's records are removed from our database, and we then delete the encrypted file from storage. File deletion is performed on a best-effort basis: if a storage deletion does not succeed immediately, the failure is detected and logged, and the file is removed in a follow-up clean-up. We therefore delete your file, but cannot guarantee that removal is instantaneous in every case.
Deleting your account. You can delete your account and all associated personal data at any time from within the app: open the Profile tab and choose Delete Account. You can also request deletion by emailing us at macklin.dias@gmail.com from your registered address. When your account is deleted, your document records are removed from our database and the encrypted files are deleted from storage on the same best-effort basis described above.
11. Your rights under UAE data-protection law
Under the PDPL, you have the following rights over your personal data. You can exercise any of them by using the relevant controls in the app or by emailing us at macklin.dias@gmail.com. We will respond within 30 days of receiving your request (and where the request is complex or we receive a number of requests, we may extend this period to the extent permitted by law and will tell you if we do). We may need to verify your identity before acting.
- Right to information and access (PDPL Article 13) — to be told, and to obtain, what personal data we hold about you, why we process it, who receives it, whether it is transferred outside the UAE, and the safeguards applied.
- Right to data portability (PDPL Article 14) — to receive your personal data in a structured, commonly used, machine-readable format. The app does not yet provide a one-tap, automated account-data export. Until it does, you can exercise this right by emailing us at macklin.dias@gmail.com, and we will compile and provide your data in such a format and, where technically feasible, help transfer it to another controller. (Note: you can already download your individual document files within the app; the portability right above covers your wider account data.)
- Right to correction (PDPL Article 15) — to have inaccurate or incomplete data corrected. This is especially relevant if our automated extraction reads a field incorrectly — you can edit the extracted details in the app.
- Right to erasure ("right to be forgotten") (PDPL Article 15) — to have your personal data deleted. You can delete individual documents in-app, and you can delete your entire account as described in Retention and deletion.
- Right to restrict processing (PDPL Article 16) — to limit how we process your data in certain circumstances.
- Right to stop / object to processing (PDPL Article 17) — to object to our processing on legitimate grounds and ask us to stop.
- Right regarding automated processing (PDPL Article 18) — to object to decisions based solely on automated processing. Our field extraction is automated; you can correct its results, and you can object to automated processing as described in the next section.
- Right to withdraw consent (PDPL Articles 19 and 6) — to withdraw your consent at any time through an easy mechanism, without affecting processing already carried out lawfully.
- Right to lodge a complaint — to complain to us and, if your concern is not resolved, to the UAE Data Office (see Complaints below).
12. Automated processing (OCR and self-hosted LLM)
When you upload a document, it is automatically processed by a two-stage pipeline to read key fields (such as document number, names, dates, issuing authority and country):
- An optical-character-recognition (OCR) engine reads the text and, where present, the passport machine-readable zone (MRZ) from the image; and
- Where the MRZ alone is not sufficient, a self-hosted large language model (LLM) interprets the extracted text to fill in remaining structured fields.
Both stages run on our own self-hosted servers. Your documents and their text are not sent to any public or third-party AI service (such as a commercial AI API) for this processing — it stays on our infrastructure. We use this processing only to label your documents and to power expiry tracking, reminders and search; it does not make any decision that produces legal or similarly significant effects about you.
Automated reading can sometimes make mistakes. If a field is read incorrectly, you can correct it in the app. You also have the right to object to automated processing under PDPL Article 18 — contact us at macklin.dias@gmail.com.
13. Who we share data with (processors and sub-processors)
We do not sell your personal data. We share it only with service providers ("processors") who help us run LegacySave, and only as needed to provide the service. We require, and are putting in place, data processing agreements with these processors obliging them to protect your data to a standard equivalent to the PDPL and to act only on our instructions.
Our processors include:
- Supabase — our managed PostgreSQL database provider (hosted in Tokyo, Japan).
- Cloudflare R2 — our encrypted document and file object-storage provider (global infrastructure; files are encrypted before storage).
- Resend — our transactional email provider (for verification, password-reset, reminder and family-invitation emails), which processes recipient email addresses and email contents and operates outside the UAE.
- Hosting providers (Namecheap, Hostinger) — third-party virtual-server providers that host our application servers and our self-hosted OCR/LLM servers, located outside the UAE (for example, in the United States and/or Europe).
- Apple — when you buy or manage a subscription, your payment and the associated transaction are processed by Apple through the App Store under Apple's own privacy policy.
Because our OCR and LLM processing is self-hosted, your documents are read on our own servers running on the above hosting providers, rather than being sent to an external AI service.
We may also disclose data where required by law, court order, or a valid request from a competent authority, or to protect our rights, your safety, or the safety of others.
14. Family sharing and inviting others
LegacySave lets you build a family account, add or invite family members, and share documents with them.
- Family-account visibility. As explained in the Sensitive data section, documents stored in your family account are accessible to the members of that family account. Adding someone to your family account therefore gives them access to the documents in the vault. Add members carefully.
- Inviting someone. When you invite a person, you provide us their email address, and we send an invitation email to that person through our email provider (Resend), which processes that email outside the UAE. That person may receive a message from us even if they have never used LegacySave.
- Data about other people, including minors. When you add a family member, you provide personal data about another individual — which may include a child's date of birth or another adult's email address and photo. You confirm that you are authorised to provide that data and to have us process it for family-sharing purposes. We process it on the lawful bases set out in Our legal basis for processing, limited to operating the family-sharing feature. An individual whose data you have added can contact us at macklin.dias@gmail.com to ask us to stop processing or to delete their data.
Please share responsibly: only add or invite people, and only share documents, where you have the authority to do so. You can manage and revoke sharing, and remove members, from within the app.
15. Data breaches
We maintain a breach-response plan and apply security measures designed to prevent unauthorised access to your data (PDPL Article 20). In the event of a personal data breach, we will, without undue delay after becoming aware of it and within the timeframes required by applicable UAE law, notify the UAE Data Office and, where the breach is likely to result in a high risk to your rights, notify you, in accordance with the PDPL (Article 9). Our notification to you will describe, to the extent we can, the nature of the breach, the categories of data affected, the likely consequences, the measures we have taken or propose to take, and how you can contact us for more information.
16. Children and eligibility
LegacySave is not directed at children and is intended for users aged 18 or over. We do not knowingly create accounts for, or collect personal data directly from, anyone under 18.
You may choose to store documents that relate to a minor in your family (for example, a child's passport), and to add a minor as a family member with limited details such as their date of birth. If you do, you, as the adult account holder, are responsible for those documents and details and for ensuring you are authorised to store and process them on the minor's behalf (see Family sharing and Our legal basis for processing).
If you believe a minor has created their own account, please contact us at macklin.dias@gmail.com so we can take appropriate action.
17. Complaints and the supervisory authority
If you have a concern about how we handle your personal data, please contact us first at macklin.dias@gmail.com — we want to put things right.
You also have the right to lodge a complaint with the UAE Data Office, the federal supervisory authority established under Federal Decree-Law No. 44 of 2021, which operates the complaints and grievance system under the PDPL.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example to reflect changes in the app, our service providers, or the law. This policy carries both an Effective date and a Last updated date at the top; when we publish a materially revised version, we will set a new Effective date.
- For minor or clarifying changes, we will update the dates and, where appropriate, notify you in the app or by email.
- For material changes — in particular any change that affects how we process your sensitive identity documents or any change to the international transfer of your data — we will not rely on your continued use as acceptance. Instead, we will ask you to review the change and provide fresh, specific consent before the new processing or transfer takes effect. If you do not provide it, the affected processing will not proceed (which may limit your ability to use the related features).
We keep prior versions and a record of material changes so you can see what changed and when.
19. Governing law
This Privacy Policy and any matter relating to it are intended to be governed by the laws of the United Arab Emirates, including the PDPL (Federal Decree-Law No. 45 of 2021). LegacySave is operated by an independent developer based in Dubai and is not established in a financial free zone such as the DIFC or ADGM; accordingly the federal PDPL governs and the competent courts of Dubai, United Arab Emirates have jurisdiction.
20. Contact us
For any privacy question, request, or to exercise your rights:
- Data Controller: Macklin Dias
- Trade licence number: Not applicable — operated by an individual freelance developer
- Address: Dubai, United Arab Emirates
- Privacy contact email: macklin.dias@gmail.com
- Data Protection Officer (DPO): Macklin Dias (macklin.dias@gmail.com)
Given that LegacySave carries out large-scale processing of sensitive identity documents combined with systematic automated (OCR + LLM) processing, we treat the appointment of a Data Protection Officer as required and have appointed the DPO named above, whom you may contact directly for any matter relating to your personal data or this policy.