Security
LegacySave stores the most sensitive documents a family owns. This page explains what protects them. It is written to be checked against, not to impress.
Encryption at rest
Document files are encrypted before they are written to storage. So are the extracted fields that matter: document numbers, names, notes, the text our scanner reads off a page, and two-factor secrets. Someone with access to the raw storage sees ciphertext.
Your documents stay off third-party AI
The scanning that reads names, numbers and dates from your documents runs on servers we own and administer. Your documents are never sent to a third-party AI service, and nothing you store is used to train anything.
What we do not claim
LegacySave is not a zero-knowledge system. Tracking expiry dates and filling fields for you means our servers can decrypt what you store. We believe in telling you that directly rather than implying otherwise. What we commit to: encryption at rest, no third-party AI, no selling or sharing of data, and access that is limited and logged.
Access to your account
- Device approval. Signing in on a new phone is not enough by itself. Each new device must be approved before it can read family documents.
- Face ID lock. The app can require Face ID every time it opens, with auto-lock when you switch away.
- Two-factor sign-in. Optional authenticator-app codes on top of your password.
- Brute-force protection. Repeated failed sign-in attempts lock the account temporarily, and every sensitive action is written to an audit log your family owner can review.
Sharing inside the family
Sharing is per document, not per vault. A family member sees a document only when it is shared with them, and removing a member removes their access.
Reporting a vulnerability
If you believe you have found a security issue in LegacySave, write to support@legacysave.space with the subject line "Security report". A person reads every one of these. Please give us reasonable time to fix an issue before disclosing it publicly.
For how your personal data is handled more broadly, read the Privacy Policy.