LegacySave
Support Privacy Terms

00 Legal · Version 1.0

Privacy Policy

How LegacySave handles the passports, Emirates IDs and family records you upload. No dark patterns. If something here reads wrong to you, write to us and we will fix the wording or the practice.

Effective 22 Jul 2026 Last updated 22 Jul 2026 Controller LegacySave, Dubai
On this page
  1. Short version
  2. Who runs LegacySave
  3. What we collect
  4. How we use it
  5. How we protect it
  6. Where your data lives
  7. How long we keep it
  8. Sharing and family access
  9. Your rights
  10. Children
  11. Changes
  12. Contact

01 Short version

The short version.

You upload a document. The file is encrypted with AES-256-GCM before it lands on our storage. A small set of extracted fields (document number, expiry date, issuing authority, country of issue) lives in our database so the app can email you 90, 30 and 7 days before your Emirates ID lapses at ICP Sharjah, or before your Indian passport crosses the six-month validity threshold that gets people turned away at Dubai immigration.

We do not sell your data. We do not run ads. Your passport photograph is never sent to OpenAI, Google Vision, Anthropic, AWS Textract or any other cloud AI provider. OCR runs on two servers we operate ourselves in Hostinger data centres.

You can delete your account inside the app. It wipes files and fields within seconds. Backups roll off within 30 days.

That is the short version. The rest of this page is the long version.

02 Who runs LegacySave

Who runs LegacySave.

LegacySave is built and operated by Macklin Dias in Dubai. Correspondence should go to privacy@legacysave.space.

For users in the UAE, LegacySave is the data controller for the purposes of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. For users in India, we act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023. For users in the European Economic Area or the United Kingdom, treat us as the controller of your personal data under GDPR.

03 What we collect

What we collect.

We only collect what you give us. We do not buy data about you. We do not track your location. We do not scrape social profiles.

Account details

Email address. Display name. If you enter them, phone number and date of birth. The device model and iOS version you signed in from, plus the timestamp of that sign-in. This is what powers the "active devices" screen and lets you approve a new phone before it can read your vault.

Family membership

Which family your account belongs to and your role in it (owner, admin, member or view-only). If you are the parent tracking two passports, three Emirates IDs and an elderly mother's residence visa for your household, that graph is stored here.

The documents you upload

Passports, including the bio page and the address page for Indian passports. Emirates IDs. UAE driving licences. Birth certificates. Marriage certificates. Education certificates. Ejari and other tenancy documents. Wills. Anything else you drop into your vault. The file itself is encrypted before it touches our storage.

OCR-extracted fields

When you upload a passport, the Machine Readable Zone is parsed for the document number, printed name, expiry date, and country. When you upload an Emirates ID, a regex reads the 15-digit number. A small local llama3.2 model then reads the "issuing authority" place name and nothing else from the image. Every field is editable before you save. Nothing is inferred behind your back.

Diagnostic data

Crash reports and error logs, stripped of any content from your documents. We do not run Firebase Analytics, Mixpanel, Amplitude, Sentry with user context, or any third-party SDK that follows you around the internet.

04 How we use it

How we use it.

Every use below is tied to a feature. Turn off the feature and the use stops.

Rendering your vault

The documents and their extracted fields are displayed to you and to the family members you have invited. That is the app.

Expiry reminders

We compare the expiry date on file to today. If it lands on the 90, 30 or 7 day threshold, an email goes out to whichever family member you named as responsible for that document. If you did not name one, it goes to you.

Reminders are a courtesy. We track and remind. Governments renew. If your inbox rejects the mail or you miss it in the noise, the AED 20 per day Emirates ID fine still applies (capped at AED 1,000). Please do not treat these as guaranteed.

Family sharing

A document in a family vault is visible to that family's invited members and to no one outside it. Removing a member cuts their app off from your documents on the next request they make.

Security and abuse prevention

Rate limits. Brute-force protection on login. Encryption-key rotation when key material is suspected to be exposed. Audit logs on privileged access. The usual hygiene, done in the open.

05 How we protect it

How we protect it.

We name the technology so you can verify each claim, not because the labels sell anything.

Files are encrypted with AES-256-GCM before they touch disk. The ciphertext is stored on Cloudflare R2, an S3-compatible object store, in an EU-West region. The encryption keys live on our API server and never leave it. A Cloudflare operator reading the raw object bytes would see ciphertext.

OCR runs on two virtual servers we rent from Hostinger. Stage one is PaddleOCR, an open-source model we run under systemd on a 4GB VPS. Stage two is llama3.2:3b via Ollama on a separate 8GB VPS, used only to extract the issuing authority (a place name). Your document image is not sent to any third-party cloud AI. Not once.

Sessions are short-lived JWTs. A sign-in from a new device requires approval from a device already on the account. The app locks with Face ID and re-prompts if it has been in the background for more than 60 seconds. Every connection between the app, the API and the database uses TLS.

No system is beyond attack. We publish the choices above so you can check them against the industry baseline, and we plan on the assumption that we will one day have to defend them.

06 Where your data lives

Where your data lives.

Four vendors. That is the full list. There is no fifth party reading your documents.

  • Cloudflare R2
    Encrypted document files. EU-West region. Objects stored as ciphertext, keys held only on our API server.
  • Supabase Postgres
    Account records, family membership, document metadata, OCR-extracted fields. EU region, TLS-only, session pooler.
  • Resend
    Transactional email only. Delivers the 90/30/7 day reminders and any sign-in codes to your inbox. Only your email address and the message body are shared.
  • Hostinger
    Two VPS instances that run PaddleOCR and llama3.2. Document images are held in memory during extraction, then discarded.
  • Cross-border transfers: because most of our sub-processors are in the EU, personal data of UAE and India residents is transferred to the European Economic Area for storage and processing. We rely on the appropriate transfer mechanism in each direction (adequate protection under the UAE PDPL executive regulations for exports from the UAE, standard contractual clauses for transfers into the EEA where relevant).

    07 How long we keep it

    How long we keep it.

    Until you delete it, or until you leave the family. Whichever comes first.

    If you delete your account, your profile is removed and every file plus every OCR field associated with your account is wiped from the database and from R2 within a few seconds. Rolling backups purge on a 30-day cycle. Diagnostic logs older than 90 days are dropped as a matter of course.

    If you leave a family, or the owner removes you, your access to that family's documents ends on the next request your app makes. Documents someone else uploaded to that family remain the family's, not yours to take with you. Documents you personally uploaded stay in the family vault unless you request otherwise before you leave, in which case we will remove them for you.

    If LegacySave ever goes out of business, our commitment is to give 30 days' notice by email and to publish a bulk-export tool before we shut anything down. You would leave with your files, not without them.

    08 Sharing and family access

    Sharing and family access.

    Documents in a family vault are visible to the family members that vault's owner has invited, and to no one else. LegacySave staff do not open your documents to browse them.

    We may access encrypted object metadata in a narrow set of cases. A support ticket you explicitly asked us to look at. A lawful legal request served on us under UAE law. An active security incident where an account is at risk. Those accesses are logged and are auditable at your request.

    Removing a family member revokes their app's access to your documents on the next request. If they downloaded a file to their own phone before removal, that copy is outside our reach. Any sharing system has this property. We say it in plain terms so you can make an informed choice about who you invite to the vault.

    We do not hand your documents to any government by default. We respond to lawful, properly-served orders from UAE authorities where legally required to do so. We do not respond to informal requests.

    09 Your rights

    Your rights.

    Under Federal Decree-Law No. 45 of 2021 (UAE PDPL), you have the right to access, correct, erase and port your personal data, to withdraw consent, and to object to certain processing.

    Under India's Digital Personal Data Protection Act, 2023, you have the right to access, correction, erasure, grievance redressal, and to nominate someone to act on your behalf in the event of your death or incapacity.

    Under GDPR, if you are in the EEA or the UK, you have equivalent rights plus the right to lodge a complaint with your national supervisory authority.

    Most of these you can exercise directly inside the app. View and edit documents on the detail screen. Delete your account from Settings then Delete Account. Export any single document via the iOS share sheet. For anything that needs a human, write to privacy@legacysave.space. We reply within 48 hours for straightforward support and within 30 days for formal data-subject requests under PDPL, DPDP, GDPR or an equivalent framework.

    10 Children

    Children.

    LegacySave is built for a parent or guardian to run a family vault that includes documents belonging to their children. A minor's Indian passport (5 years validity for under-15s). Their UAE resident visa. A school leaving certificate.

    Children below the age of consent in their country of residence do not open their own accounts. A guardian holds the account and takes responsibility for the documents added to it. If we learn that a child has created an independent account, we close it and delete the associated data.

    11 Changes

    Changes to this policy.

    We update this page when the product changes in a way that affects your data, when the law changes, or when we notice a passage that could be misread. Material changes go out by email to your account address and reset the "last updated" date at the top of this page. If you disagree with the new version, you can delete your account inside the app before the change takes effect.

    12 Contact

    Contact.

    Data protection questions, access requests, deletion requests, or a security concern you want us to look at. Write to us.

    Data Protection Officer · LegacySave

    Privacy: privacy@legacysave.space

    Support: support@legacysave.space

    Response time: 48 hours for support. Up to 30 days for formal data-subject requests.

    If we cannot resolve a complaint to your satisfaction, you can escalate to the UAE Data Office, or, if you are in India, to the Data Protection Board of India, or, if you are in the EEA, to your local supervisory authority.

    See also the Terms and Support pages.

    LegacySave
    Home Support Privacy Terms

    © 2026 LegacySave · Built in Dubai

    support@legacysave.space