Frequently Asked Questions

How Legacy Key helps you plan crypto recovery and inheritance without storing your keys.

Does Legacy Key store my seed phrases or private keys?

Absolutely not. Legacy Key only stores metadata about your wallets and backup locations - never the actual seeds or private keys themselves. We designed it this way intentionally because your seeds should never be entered into any online system. The app helps you document WHERE your seeds are stored, not WHAT they are.

What happens to my data if Legacy Key shuts down?

You can export all your data at any time in JSON format. Your data is always yours to keep.

Is my data encrypted?

Yes, with multiple layers of protection. All data is encrypted in transit using TLS 1.3 and at rest using AES-256-GCM with unique initialization vectors for each encryption operation. Unlike basic database encryption, we implement field-level encryption: wallet details, serial numbers, location data, notes, and contact information are each encrypted separately with their own keys. This means even in the unlikely event of a database breach, attackers would see only ciphertext — not your actual data. We use industry-standard key derivation (PBKDF2) and secure key storage practices.

What is zero-knowledge encryption?

Zero-knowledge encryption (ZKE) means your data is encrypted in your browser before it ever reaches our servers. We literally cannot see your data, even if we wanted to. Your password is used to derive an encryption key locally — we never receive the password or the key. Legacy Key uses zero-knowledge encryption, providing the highest level of privacy: protection from server breaches, insider threats, and even legal requests.

Can Legacy Key employees see my data?

All data is encrypted with zero-knowledge encryption (AES-256-GCM). It's impossible for anyone but you to see your data — we don't have your encryption keys, so even with full database access we would only see encrypted ciphertext. Your password derives the encryption key locally in your browser, and we never receive either.

What happens if Legacy Key is hacked?

Attackers would only obtain encrypted data that is useless without your password. Each user's data is encrypted with unique keys derived from their password using 600,000 PBKDF2 iterations — making brute-force attacks impractical. Even with full database access, all an attacker would see is encrypted ciphertext.

What is the Recovery Key?

When you create your account, you receive a Recovery Key in the format LK-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX — a Crockford Base32 alphanumeric code with 128 bits of entropy. This code is generated in your browser and never sent to our servers. It is the only way to recover your data if you forget your password. We do not recover accounts with a 24-word BIP39 phrase. Store the Recovery Key securely, just like you would a wallet seed phrase.

What if I lose my Recovery Key?

If you forget your password AND lose your Recovery Key, your encrypted data cannot be recovered — not by you, not by us, not by anyone. This is the tradeoff for maximum privacy. However, if you have trusted contacts with inheritance access, they can recover your data after the inactivity period triggers. This is intentional and designed to prevent permanent data loss.

Can you reset my password?

We cannot reset your password because we don't have your encryption keys. You can reset your password, but this will clear your encrypted data unless you use your Recovery Key to restore access. Your Recovery Key is your password reset.

How do I get access?

Join the waitlist. We're in private beta and we'll email you when a spot opens. Join the Waitlist.

How do I delete my account?

Email [email protected] from the email address associated with your account and request account deletion. We'll verify your identity and delete your account within 48 hours. You'll receive a confirmation email once your account has been deleted.

What happens to my account if I stop using the service?

If an account has no login activity: we send a reactivation email at 11 months, suspend the account at 13 months, and permanently delete all data at 16 months. You can reactivate at any time before deletion by logging in. We recommend exporting your data periodically as a precaution.

How does inheritance access work?

You can designate trusted contacts with inheritance access. After a configurable inactivity period (30, 60, 90, 180, or 365 days without logging in), these contacts automatically receive read-only access to your wallet documentation. You'll receive warning emails at 30, 15, and 5 days before the trigger activates. Any login resets the timer, and you can revoke access at any time. Learn more about inheritance planning.

What if I forget to log in and the trigger activates?

Don't worry — you remain the account owner. If the inheritance trigger activates while you're still alive and well, simply log in to immediately regain full control. You can revoke your contacts' access and reset the inactivity timer. The warning emails (at 30, 15, and 5 days) help prevent accidental triggers.

Can I revoke inheritance access after it triggers?

Yes, absolutely. You remain the owner at all times. If the trigger activates and you return, you can immediately revoke access. Your trusted contacts only have read-only access — they cannot modify anything. You can also disable inheritance entirely or change the inactivity period.

How can I verify your security claims?

We believe in transparency over trust. Our encryption implementation uses AES-256-GCM, a well-documented NIST-approved algorithm that security professionals can evaluate. We publish our security architecture details on our Security page so experts can assess our approach — including what's encrypted, what's not, and why. As we grow, we plan to pursue SOC 2 Type II certification and engage third-party penetration testers. We welcome questions from security-minded users.

What security alerts will I receive?

We send email alerts for important security events: new sign-ins from unrecognized devices, password changes, two-factor authentication being enabled or disabled, and multiple failed login attempts. Each alert includes device and location details so you can verify if the activity was legitimate. You can customize these notifications in your settings.

Can I share access with family members or advisors?

Yes. You can invite other users with either Read Only or Read & Write access. This is useful for inheritance planning — you can give a spouse or attorney view access to your wallet documentation without giving them edit rights.

What hardware wallets are supported?

Legacy Key is hardware-agnostic. You can document any hardware wallet including Ledger, Trezor, Coldcard, BitBox, Keystone, Foundation Passport, and any other device. The app tracks metadata about the devices, not the devices themselves.

Does the app connect to the blockchain or track prices?

No. Legacy Key is purely a documentation and organization tool. It does not connect to any blockchain, track balances, monitor transactions, or display price information. This is intentional - it keeps the app simple, secure, and focused on its core purpose.

What is the Emergency Access Document?

The Emergency Access Document is a printable PDF that contains all your wallet locations, backup locations, account information, and custom instructions. It's designed to give your trusted contacts clear directions on how to access your crypto in an emergency, without including the actual seeds.

How do verification reminders work?

You can schedule periodic health checks for each wallet (we recommend every 90 days). The dashboard will alert you when a verification is due, and you can also receive email reminders (daily, weekly, or monthly) with a checklist to verify each wallet. The checklist includes: device powers on, PIN works, seed backup verified, and firmware is current. Every verification is timestamped for your records.

Still have questions?

Contact our support team

We typically respond within 24 hours.