Who we are
Legacy Wallet is a non-custodial crypto wallet with a built-in dead man's switch and an encrypted Legacy Vault. This policy covers the Legacy Wallet app, the optional Legacy Account and subscription, and this website, thelegacywallet.app.
The company responsible for your data (the "controller") will be named here, with its registered number and address, before Legacy Wallet launches. Until then, write to info@thelegacywallet.app with any privacy question or request.
The short version
- Your recovery phrase and private keys never leave your phone. We never receive them, so we cannot move your funds or recover your wallet.
- Your Legacy Vault is encrypted on your phone before it is uploaded. We store it but cannot read it.
- Some things we can read, because the service needs them: your Legacy Account email, the wallet addresses you attach to it, your subscription status, any alert contact you give us, and the labels (not the contents) of your vault items. The full list is below.
- Your inheritance settings live on the Solana blockchain, which is public and permanent.
- We don't sell data, show ads, or use analytics or tracking tools in the app or on this website.
What we can and cannot see
On your phone only
- Your recovery phrase and private keys. They are held in your phone's secure keychain behind Face ID, fingerprint or passcode. Device backups don't carry them in a usable form.
- The keys that unlock your vault. Your phone derives them from your wallet when needed and keeps them in memory for a few minutes at most.
- App data such as your account names, in-app browser tabs, bookmarks and history, connected apps, and the owners you watch as an heir. This stays on your phone, not on our servers. Like other app data, it can be included in your phone's own iCloud or Google backup, which you control.
Stored with us, encrypted so we cannot read it
- The contents of your vault items: notes, recovery phrases for other wallets, final messages, files, and the real names of those files. Each item is encrypted on your phone (XChaCha20-Poly1305) before it is uploaded.
- How the key is protected. Each item's key is split into shares. One is sealed so only you can open it, one is sealed so only your heir can open it, and our server holds one. Our share cannot decrypt anything on its own. Combined with your heir's share it can, which is why our server releases its share only after the on-chain program shows a claim on your wallet as finalised.
Stored with us and readable by us
The table in the next section lists everything we hold that is not encrypted this way.
What we collect, why, and our legal basis
| What | Details | Why | Legal basis |
|---|---|---|---|
| Legacy Account (optional, needed only for the paid plan) | Email address; password, stored only in hashed form by our sign-in provider; sign-in sessions | To sign you in and tie your subscription to you | Contract |
| Wallets attached to your account | Wallet addresses, a device label, and when each was attached or detached (detached wallets stay on record) | To know whose vault your subscription covers | Contract |
| Subscription records | Account ID, plan, store (Apple or Google), the store's transaction reference, status, renewal and expiry dates, and the purchase events our billing provider sends us, which can include your country, the price and the currency. We never see your card details. | To provide paid features, handle renewals, refunds and billing problems, and keep financial records | Contract; legal obligation |
| Alert contact (optional) | An email address and/or phone number, linked to your wallet address. Stored readable so warnings can be sent. | To warn you before your switch fires | Contract |
| Notification token | Your phone's push token, linked to your wallet address, and its platform | To deliver warnings and alerts, such as when your heir opens your vault. You can switch notifications off in your phone's settings. | Contract |
| Vault item labels | The title you give each item, its type and category, your heir's wallet address, release settings, file size, and when the item was created, changed or last checked | To list your items and release each one to the right heir | Contract |
| Vault activity log | Which wallet did what to which item, and when (for example: saved, released, opened), with technical details such as item type and size | To keep the vault secure and accountable, and to tell you when it is opened | Legitimate interests |
| Heir details | An heir's wallet address, the public key their app registers to receive sealed shares, and one-time codes used when they request a release | To release vault items to the heir the owner chose | Legitimate interests |
| Requests to our servers | Your IP address, and the wallet addresses and transactions a request involves | To run the service and protect it from abuse | Legitimate interests |
| Support requests | Email address, your name if you give it, your message, the help article you came from, and our replies | To answer you | Legitimate interests |
| Waitlist | Email address | To tell you when Legacy Wallet launches | Consent |
Vault titles are not encrypted
Don't put anything sensitive in a vault item's title. If you add a file and leave the title blank, the file's name becomes the title, and we can read it.
IP addresses. Most of the app's blockchain requests pass through our server, which keeps our providers' access keys private. Our server uses your IP address in memory to limit abuse. It does not write IP addresses to our database. Our hosting providers keep standard request logs for short periods.
On the blockchain: public and permanent
When you set up the switch, the Legacy Wallet program on Solana records your wallet address, your heir's wallet address, your timer settings, the time of each check-in, and the state of any claim. Anything you deposit for your heir is visible too. The app checks in for you automatically when you open it.
Anyone can read this information. Neither we nor anyone else can change or delete it. We never put your name or email address on the blockchain, but anyone who knows your wallet address can see this activity.
What we don't do
- We don't sell or rent personal data.
- We don't show ads or work with advertising networks.
- There are no analytics, crash-reporting or tracking tools in the app, and no analytics scripts on this website. We don't track you across other apps or websites.
- This website sets no cookies for ordinary visitors. The only cookies it uses keep authorised people signed in to password-protected pages.
Who else handles your data
We use these providers to run Legacy Wallet. They handle your data only to provide their service to us.
| Provider | What they handle |
|---|---|
| Supabase | Legacy Account sign-in (email, hashed password, sessions) and support tickets |
| Render | Hosts our API server and its database, which hold everything in the table above that we store, including encrypted vault contents |
| RevenueCat | Manages subscriptions: your account ID and the purchase records from Apple or Google |
| Apple and Google | Take payment for subscriptions as the seller, under their own terms and privacy policies, and deliver notifications to your phone |
| Expo | Passes notifications to Apple and Google: your push token and the notification's text, which can include wallet addresses and times |
| Helius | Access to the Solana network: wallet addresses and transactions, sent by our server, so Helius sees our server rather than your IP address |
| Solana network endpoints | Some read-only lookups go straight from your phone, so the endpoint sees your IP address and the wallet addresses looked up |
| Jupiter and Raydium | Prepare token swaps: your wallet address, the tokens and amounts, and the transaction. Your phone also looks up prices from Jupiter directly. |
| CoinGecko, Birdeye, DexScreener and RugCheck | Prices and token information: your phone sends them token addresses and, like any website, sees your IP address. They don't receive your wallet address. |
| Tensor | The Collectibles marketplace: your wallet address, and any listings, purchases and sales |
| Resend | Sends support emails: your name, email address and message |
| Microsoft | Hosts the mailbox that receives support emails |
| Vercel | Hosts this website and passes waitlist sign-ups on |
| britcardmeme.com | Waitlist sign-ups are currently stored in the waitlist database of this separate project: your email address |
We may also share data if the law requires it, to protect people from harm, or as part of a sale or reorganisation of our business, in which case this policy continues to protect it.
Services you choose to use
Some features connect you to other companies, which use your data under their own privacy policies:
- MoonPay (Add Funds). We pass on your wallet address. MoonPay collects any identity and payment details directly.
- Apps and websites you open in the in-app browser or connect your wallet to. They receive what any website or connected app would. Searches in the browser go to Google by default.
- Other Legacy services. Your Legacy Account can also sign you in to other Legacy services. Each has its own privacy notice.
Where your data is processed
Our sign-in and support database is in the United Kingdom (London), and the service that sends our support emails is in Ireland. Our API server and its database, which hold most of the data described above, run in the United States, and several of our providers, including RevenueCat, Expo and Helius, are based there.
When personal data leaves the UK or the European Economic Area, we rely on safeguards recognised by UK and EU law, such as the European Commission's standard contractual clauses and the UK's International Data Transfer Addendum.
How long we keep it
| Data | How long |
|---|---|
| Legacy Account and attached wallets | Until you delete your account |
| Subscription records | Until you delete your account. Apple and Google keep their own records of your purchases. |
| Alert contact and notification token | Until you ask us to delete them |
| Vault items and files | Until you delete them in the app |
| Vault activity log | Until you ask us to delete it, unless we need it to protect you, your heir or a claim |
| One-time release codes | 24 hours |
| Support requests and waitlist sign-ups | Until you ask us to delete them |
| Blockchain records | Permanently — nobody can delete them |
Your rights
Under UK and EU data protection law you can ask us to:
- give you a copy of your personal data;
- correct it;
- delete it;
- limit how we use it, or object to uses based on our legitimate interests;
- give it to you, or to another service, in a portable format;
- stop using it where you gave consent (such as the waitlist).
You can delete your Legacy Account yourself in the app (Legacy Account → Delete account). For everything else, email info@thelegacywallet.app. We'll reply within one month. Some limits come from how Legacy Wallet works:
- Nobody can change or delete blockchain records, including us.
- We can't decrypt your vault for you. You can read your items in the app at any time with your wallet.
- Deleting some data stops parts of the service working. For example, without an alert contact, warnings can't reach you that way.
If you're unhappy with how we've handled your data, please tell us first. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or to the data protection authority where you live. In Estonia, that is the Andmekaitse Inspektsioon (aki.ee).
If you've been named as an heir
The owner gives us your wallet address, not your name or contact details. We use it to seal a share of each vault item's key to you and, once a claim is finalised, to release the items the owner chose. The owner may mention you inside encrypted vault items, which we cannot read. When you use the app yourself, this policy covers you like any other user.
When an owner dies
Releasing an owner's vault items to their chosen heir after a finalised claim is what the owner set Legacy Wallet up to do. UK data protection law does not cover people who have died, but some countries, including Estonia, France and Italy, do protect their data, and we handle a deceased owner's data with the same care as anyone else's.
Children
Legacy Wallet is for adults: you must be 18 or over to use it. We don't knowingly collect data from children. If you think a child has given us personal data, email us and we'll delete it.
Security
Vault items are encrypted on your phone before upload. Data travels over encrypted connections. Your keys stay in your phone's secure keychain, and each vault key is split so that nobody but you, including us, can decrypt your vault alone. No system is perfectly secure. If a breach affects your data, we'll tell you and the regulator as the law requires.
Changes to this policy
We'll post any update here and change the date at the top. If a change materially affects how we use your data, we'll tell you in the app or by email before it takes effect.
