Privacy Policy
Legatus encrypts vault contents in your browser before transmission, so the service stores ciphertext it cannot read. This policy states what Legatus does collect — including the visits it logs on its public pages, and how to switch that off — who processes it, how long it survives deletion, and how to raise a grievance under the Digital Personal Data Protection Act, 2023.
Who operates Legatus
Legatus is operated by Suman Debnath, trading as House of Namus, an unregistered sole proprietorship based in India. For the purposes of the Digital Personal Data Protection Act, 2023, that proprietorship is the Data Fiduciary responsible for the personal data described in this policy.
House of Namus is a trading name, not a registered company. Legatus is currently a pre-launch service offered free of charge, and is operated by an individual rather than a funded organisation. That is stated plainly because it is relevant to how much you should rely on it.
What Legatus collects
Legatus collects your email address, a hashed authentication credential, your encrypted vault payload, the names and email addresses of nominees you designate, uploaded death certificates where an expiry claim is made, and system audit logs. It also records visits to its public pages, including your IP address and approximate location — see Visit logging below. It does not collect your master passphrase, your plaintext vault contents, or your private keys.
| Collected | Never collected |
|---|---|
| Email address | Your master passphrase |
| Hashed authentication credential | Plaintext vault contents |
| Encrypted vault payload (ciphertext) | Nominee private keys |
| Nominee name and email address | Payment details — there are none |
| Death certificates, on an expiry claim | Anything you type into a field |
| Audit logs of vault and account events | Advertising or cross-site tracking identifiers |
| IP address, approximate location and browsing behaviour on public pages | Precise device location — the browser location permission is never requested |
Legatus runs no advertising pixels and no third-party scripts. The Content-Security-Policy served with every page permits scripts only from this origin. Typefaces are self-hosted, so loading a page sends no request to Google Fonts or any other font service. It does run first-party visit logging, described in full below, which an earlier version of this policy incorrectly said did not exist.
What zero-knowledge does and does not mean
Vault contents are encrypted in your browser with AES-256-GCM before transmission, under a key derived from your master passphrase with PBKDF2. That passphrase is never transmitted to Legatus and never stored. Legatus therefore holds no key capable of decrypting your vault, and cannot produce your plaintext contents on request, on subpoena, or after a server breach.
That is a property of the design, and a design is not a guarantee. It depends on the integrity of the code your browser receives. An attacker who compromised the delivery of that code could, in principle, capture a passphrase at the moment it is typed — before any encryption happens. Legatus has not undergone a third-party cryptographic audit or penetration test. An earlier version of this policy claimed no party could decrypt a vault “under any circumstance”. That was an overstatement and has been removed.
Who else processes your data
Five processors are involved. Supabase provides the database, authentication and file storage. Vercel hosts and serves the application. Resend delivers transactional email such as nominee invitations and check-in reminders. Telegram carries the visit alerts described below, and ipwho.is converts an IP address into an approximate location. Each receives only what it needs, and none receives anything that would decrypt a vault.
| Processor | Purpose | What it sees |
|---|---|---|
| Supabase | Database, auth, file storage, scheduled jobs | Email addresses, ciphertext, death certificates, audit logs |
| Vercel | Application hosting and delivery | Request metadata such as IP address and user agent |
| Resend | Transactional email delivery | Recipient email addresses and message contents |
| Telegram | Delivery of visit alerts to a private chat | The contents of each alert: IP address, approximate location, pages viewed, and the account name when signed in |
| ipwho.is | IP address to approximate location and network operator | The visitor’s IP address, and nothing else |
Telegram is operated by Telegram FZ-LLC and ipwho.is by its operator, both outside India. Alerts are therefore transferred outside India in the ordinary course of delivery. Neither receives anything capable of decrypting a vault, and neither is sent your vault contents, your passphrase or your email address.
Email sent through Resend is delivered over Amazon SES infrastructure. Legatus does not sell, rent, share or monetise personal data, and does not permit any processor to use it for their own purposes.
Death certificates
Where a nominee raises an expiry claim, the death certificate they upload is stored in a private bucket that is not publicly readable. Access requires a signed URL that expires after 15 minutes, and only an administrator can generate one. Review is a human reading a document, not a check against a government registry.
Visit logging
Legatus sends a real-time alert to a private Telegram chat when someone visits its public pages. Each alert records the visitor’s IP address, approximate city-level location, network operator, browser and device, which pages were viewed and for how long, how far they scrolled, and what they clicked. Alerts exist only as messages in that chat. Nothing is written to a database, and there is no analytics account, cookie or advertising identifier involved.
It runs on public pages only — the home page and the guides, glossary, FAQ, and legal pages. It does not run inside your vault, on the nominee area, on the administrator area, on a nominee invitation link, or on the sign-in and account-creation pages. Which pages you open inside your vault, and how long you spend there, are never recorded.
| Recorded | Never recorded |
|---|---|
| IP address, and the city, region and country it resolves to | Precise device location — the browser location permission is never requested |
| Network operator and whether the address is a datacenter or mobile network | Anything typed into any field, including passwords and passphrases |
| Browser, operating system, screen and window size, language, timezone | Any page inside the vault, nominee, admin or invitation areas |
| Pages viewed on public pages, time on page, active versus idle time, scroll depth | Cookies set for tracking — the beacon sets none |
| That an element was clicked, and its visible label | The contents of any field, and any value you enter |
| A score estimating whether the visitor is a person or a script, and the reasons for it | Your email address |
| Your display name, when you are signed in | Any identifier linking you across other websites |
The number of key presses during a visit is counted, because a script does not type and a person does. Whichkeys were pressed is never read, stored or sent. The labels recorded against clicks come from an element’s visible text, such as “Create your vault”, and never from a value you entered.
Why it exists. Legatus is a pre-launch service run by one person. The alerts answer whether anyone is arriving, from where, what they read, and whether traffic is real people or automated crawlers. That is the whole purpose. It is not used for advertising, profiling, scoring you as a customer, or any decision that affects you or your vault.
Sign-in alerts. An alert is also sent when a password is accepted on the sign-in page and when a new account is created. This is a security signal: it tells the operator that someone authenticated successfully, and from where, which is how an unexpected access to an account would be noticed. It carries your display name, the location and the device — never your email address, your password or your passphrase, none of which leave your browser for this purpose. The alert for sign-in fires when the password is accepted, which is before any two-factor challenge, so it can represent an attempt that was subsequently blocked.
How long it is kept. There is no retention period, because there is no store. Alerts are messages in a private Telegram chat and persist there until deleted, in the same way any chat message does. They are not written to the Legatus database, not exported, and not aggregated into a profile. Deleting your account does not delete past alerts, because they are not linked to your account record — but they are also never retrieved or used after the moment they are read.
Do Not Track is recorded, not obeyed. If your browser sends a Do Not Track or Global Privacy Control signal, that fact is noted in the alert, but visit logging continues. An earlier version of this policy said the opposite, and the change is stated here rather than quietly made.
Legatus did honour those signals. It stopped because they are switched on by the browser rather than chosen by you for this site — Brave, DuckDuckGo and Firefox private windows all send Global Privacy Control by default — so treating them as consent decisions silently removed a large share of visits while telling nobody. The opt-out below is the control that does stop collection, and it is unambiguous: you choose it, for this site, and it takes effect immediately.
How to switch it off. Use the control below, or add ?notrack=1 to any Legatus URL. Either stops collection immediately and permanently for that browser — nothing is gathered and nothing is sent, rather than gathered and discarded. ?notrack=0 reverses it. The choice is stored in that browser alone, so it does not carry across your devices, and clearing site data forgets it. Adding ?notrack=status shows, on screen, whether the browser you are using is currently being logged and why.
How long data survives deletion
You may delete your account and vault at any time from account settings. Records and encrypted payloads are removed from the live database immediately. Legatus currently runs on Supabase’s Free plan, which does not include automated backups, so there is no backup archive retaining copies of a deleted vault.
Short-lived operational copies — database write-ahead logs and provider-side caches — may persist briefly as a normal part of how a database works, but they are not kept as a restorable archive. Any such copy is ciphertext, and because Legatus never held your passphrase it is not readable by Legatus or by anyone obtaining it.
An earlier version of this policy said deletion was “immediate and irretrievable” everywhere, which overstated it, and a later revision referred to a provider backup retention window, which does not exist on this plan. This is the accurate position.
Your rights under the DPDP Act, 2023
As a Data Principal you may request access to a summary of your personal data and how it is processed, request correction or erasure, nominate another individual to exercise these rights on your death or incapacity under Section 14, and raise a grievance. Requests go to the address in the next section.
Note the distinction the product itself is built around: a Section 14 nominee may exercise your data rights. That is not the same as inheriting your assets, which is governed by your will and by succession law. Naming nominees inside a Legatus vault is a technical arrangement for access, not a testamentary act.
Grievance redressal
Grievances about the handling of your personal data should be sent to Suman Debnath at defy@houseofnamus.com with “DPDP Grievance” in the subject line. Legatus aims to acknowledge within 72 hours and to resolve within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India.
Legatus is operated by one person, so a grievance is read and answered by that person rather than routed through a support desk. If a personal data breach occurs, affected users and the Data Protection Board will be notified as required by the Act.
Eligibility
Legatus is intended for use by adults aged 18 or over. It is not designed for children, and accounts are not knowingly created for anyone under 18. If you believe a child has created an account, contact defy@houseofnamus.com and it will be removed.
Governing law
This policy is governed by the laws of India. Disputes arising from it are subject to the jurisdiction of courts in India. Nothing in this policy limits rights you hold under the Digital Personal Data Protection Act, 2023 or the Consumer Protection Act, 2019, which cannot be waived by agreement.
Questions, data rights requests and vulnerability reports: defy@houseofnamus.com.