Privacy Policy
Effective Date: February 16, 2026
Last Updated: February 16, 2026
Legacy Key, LLC
8400 NW 36th Street, Suite 450
Doral, FL 33166
United States
Legacy Key operates https://www.legacykey.com (the "Service"), a secure SaaS platform that helps users document and manage the locations of their hardware cryptocurrency wallet backups, recovery contacts, multisig configurations, and inheritance planning—without ever storing, seeing, or processing actual seed phrases, private keys, wallet balances, addresses, or transaction data.
Our core principle is zero-knowledge where possible: for all subscribers, your sensitive data is encrypted entirely in your browser before it reaches our servers—we hold no decryption keys.
This Privacy Policy explains what information we collect, how we use and protect it, and your rights.
1. Information We Collect
We collect only the minimum data required to provide secure backup location management and inheritance features.
Information You Provide
| Category | Examples | Notes |
|---|---|---|
| Account & Authentication | Email address, password (hashed), name (optional) | Required for login |
| Wallet Metadata | Brand, model, serial number, firmware, purchase date, notes, photos/documents (≤10 MB each) | Never includes seeds or keys |
| Backup Details | Storage format (metal/paper/etc.), word count, share splits, physical locations, recovery instructions | Encrypted; no actual words stored |
| Accounts & Multisig | Cryptocurrency type, derivation path nickname, quorum settings, coordinator software, member roles | Encrypted; configuration only |
| Trusted Contacts & Sharing | Names, relationships, emails, access level (read/write) | Linked to wallets; invitations require verification |
| Inheritance Settings | Designated contacts, keepalive schedules, emergency document instructions | Legacy only; encrypted |
| Billing & Subscription | Subscription tier, billing metadata (handled by Stripe) | No full card details stored |
Automatically Collected / Usage Data
- Device/browser information: IP address (anonymized where possible), browser type/version, OS, access times, pages visited
- Usage events: Feature interactions (e.g., wallet created, onboarding step completed), anonymized via PostHog (UUID only—no email or PII)
- Security logs: Login attempts, IP/user-agent for fraud detection, audit trail entries (encrypted for ZKE users)
We do not collect: seed phrases, private keys, wallet balances, addresses, transaction history, blockchain data, or any sensitive financial content.
2. How We Use Your Information
- Deliver core functionality: Display wallet locations, send verification reminders, generate emergency documents, manage sharing/inheritance
- Security & integrity: Detect suspicious logins, send alerts (new sign-in, password changed, MFA events), maintain encrypted audit logs (1 year retention)
- Communication: Transactional emails (verification, password reset, MFA codes—never suppressed), optional marketing/onboarding drips (suppressed after repeated bounces to protect deliverability)
- Product improvement: Anonymized analytics (opt-out available in Settings) to understand feature usage and conversion funnels
- Legal/compliance: Prevent abuse, respond to valid legal requests (limited to what we can access—see encryption section)
3. Data Sharing & Third-Party Processors
We do not sell your personal data. We share only what is necessary with trusted, contracted providers:
| Provider | Data Shared | Purpose | Location |
|---|---|---|---|
| Railway.app | All application data (encrypted where applicable) | Hosting & compute | US |
| AWS S3 | Uploaded files (photos/documents—encrypted) | Secure file storage | US-East-1 |
| Stripe | Billing info (name, email, payment method) | Subscriptions & payments | Global (PCI DSS) |
| SendGrid | Email address | Transactional & marketing emails | US |
| PostHog | Anonymized UUID + usage events (no PII) | Product analytics (opt-out available) | US/EU |
| PostgreSQL/Redis (hosted) | Encrypted metadata & sessions | Application persistence & caching | US |
For ZKE users, encrypted blobs (recovery instructions, notes, multisig configs, etc.) remain unreadable to all processors—even us.
Sharing occurs only:
- With your explicit action (e.g., inviting a shared user or inheritance contact)
- In business transfers (merger/acquisition)
- To comply with law (we provide only encrypted data for ZKE users)
4. Encryption & Security Model
| Plan | Encryption Type | Key Location | Password Reset | Our Access to Data |
|---|---|---|---|---|
| All Plans | Client-side Zero-Knowledge | You hold keys only | LK- Recovery Key | Impossible—even with full DB access |
ZKE protects against server compromise, insider access, subpoenas for plaintext, and data breaches. We use:
- PBKDF2 (600,000 iterations) for key derivation
- AES-256-GCM for encryption
- Bcrypt (high cost) for passwords
- Secure HttpOnly/SameSite=Strict session cookies (1-hour rolling)
- Rate limiting, CSRF tokens, security headers, audit logging
No system is 100% secure—use strong passwords, enable MFA, and safeguard your Recovery Key (all plans).
5. Data Retention
| Data Type | Retention Period | Notes |
|---|---|---|
| Active account data (wallets, contacts, files) | Lifetime of account | Deleted on user-initiated deletion |
| Audit logs | 1 year | Auto-purged; cascade-deleted on account deletion |
| Sessions | 1 hour (rolling) | Redis TTL |
| Inactive accounts | Warnings at 11 months; suspend at 13 months; delete at 16 months | With email notifications |
| Billing records (Stripe) | 7+ years | Stripe policy (we delete local metadata on account deletion) |
You may export your data (decrypted in-browser for ZKE users) or request deletion via Settings > Delete Account (requires password confirmation; cascades to S3).
6. Your Rights & Choices
- Access/Correct/Delete: Request via support or Settings
- Opt-out of analytics: Disable in Settings > Privacy
- Email preferences: Manage in Settings > Email Notifications (some security emails cannot be disabled)
- MFA & Recovery: Enable MFA for added protection; store backup codes securely; all users rely on an LK- Recovery Key for recovery. We do not recover accounts with a 24-word BIP39 phrase.
For GDPR/CCPA: We process under contract performance/legitimate interest. ZKE users have enhanced protection as we cannot access plaintext.
7. International Transfers
Data is primarily processed in the United States. For EU/EEA users, we rely on adequacy decisions, standard contractual clauses with processors, and the fact that ZKE data remains encrypted with user-held keys.
8. Children's Privacy
The Service is not directed to individuals under 18 (or the applicable minimum age in your jurisdiction). We do not knowingly collect data from children.
9. Changes to This Policy
We may update this policy. Changes will be posted here with a new effective date. Significant changes (e.g., encryption model) will be communicated via email or in-app notice. Continued use after changes constitutes acceptance.
10. Contact Us
Legacy Key, LLC
8400 NW 36th Street, Suite 450
Doral, FL 33166
United States
Questions, data rights requests, or security concerns:
- Email: [email protected] (for security/vulnerabilities)
- In-app support: Via the dashboard for general inquiries
We respond to valid requests in accordance with applicable law (typically within 30–45 days).
We are committed to earning and keeping your trust—your cold wallet security is our only mission.