Legacy

Privacy Policy

Last updated: September 10, 2026 · Beta

Legacy is in private beta, and this policy may change as the product does. We'll update the date above when it does. This page describes what the app actually stores and sends today — written for a person, not a lawyer.

The short version

Almost everything you enter into Legacy — vault notes, accounts, bills, loans, beneficiaries, documents, and your readiness checklist — is encrypted in your browser before it ever reaches our servers. We store the encrypted result and cannot read it. A few things are not encrypted, because the product needs to read them to work (your email, your survivor contacts, and your obituary draft) — they're listed below.

What's encrypted, and what isn't

Your vault passphrase never leaves your browser. It's used to derive an encryption key on your device (PBKDF2 with 600,000 iterations, then AES-GCM), and that key encrypts your data before it's sent anywhere. What we store for these record types is only ciphertext and an initialization vector (IV) — never the plaintext, never your key:

Two record types are not encrypted, because our servers need to read them to do their job:

What we store about your account

Beyond your encrypted records, we keep a small amount of account data in readable form:

What we can't do

Because we never receive your passphrase or your encryption key, we cannot read your encrypted records, and we cannot recover them for you. If you lose both your passphrase and your recovery code, that data is permanently unreadable — including to us. This is a deliberate tradeoff of zero-knowledge design, and we'd rather tell you plainly than let it be a surprise.

Who else sees your data

Legacy uses two outside services, and only for what each one needs to do its job:

We don't sell your data, and we don't share it with anyone else for advertising or marketing.

Cookies and tracking

Legacy sets exactly one cookie: a session cookie that keeps you signed in. It's httpOnly(your browser's JavaScript can't read it) and is removed when your session ends or you sign out. We don't use analytics scripts, advertising trackers, or any third-party cookies.

What the beta itself records

Running a private beta adds three small things, none of which touch your vault:

Deleting your data

When an account is deleted, every record tied to it — vault notes, accounts, bills, loans, beneficiaries, documents, your readiness checklist, survivor setup, and your obituary — is deleted along with it; nothing is kept behind. During the beta, account deletion is handled by request rather than a self-serve button — reach out and we'll take care of it.

Questions

This is a beta product and this policy will keep evolving with it. If anything here is unclear, or you want to know more about how a specific feature handles your data, ask — we'd rather explain than have you guess.

Write to support@spinachcreations.com and a person will read it.