Legal

Privacy Policy

Legatus encrypts vault contents in your browser before transmission, so the service stores ciphertext it cannot read. This policy states what Legatus does collect — including the visits it logs on its public pages, and how to switch that off — who processes it, how long it survives deletion, and how to raise a grievance under the Digital Personal Data Protection Act, 2023.

Last reviewed 8 September 2026Legatus · Digital Legacy Vault

Who operates Legatus

Legatus is operated by Suman Debnath, trading as House of Namus, an unregistered sole proprietorship based in India. For the purposes of the Digital Personal Data Protection Act, 2023, that proprietorship is the Data Fiduciary responsible for the personal data described in this policy.

House of Namus is a trading name, not a registered company. Legatus is currently a pre-launch service offered free of charge, and is operated by an individual rather than a funded organisation. That is stated plainly because it is relevant to how much you should rely on it.

What Legatus collects

Legatus collects your email address, a hashed authentication credential, your encrypted vault payload, the names and email addresses of nominees you designate, uploaded death certificates where an expiry claim is made, and system audit logs. It also records visits to its public pages, including your IP address and approximate location — see Visit logging below. It does not collect your master passphrase, your plaintext vault contents, or your private keys.

CollectedNever collected
Email addressYour master passphrase
Hashed authentication credentialPlaintext vault contents
Encrypted vault payload (ciphertext)Nominee private keys
Nominee name and email addressPayment details — there are none
Death certificates, on an expiry claimAnything you type into a field
Audit logs of vault and account eventsAdvertising or cross-site tracking identifiers
IP address, approximate location and browsing behaviour on public pagesPrecise device location — the browser location permission is never requested

Legatus runs no advertising pixels and no third-party scripts. The Content-Security-Policy served with every page permits scripts only from this origin. Typefaces are self-hosted, so loading a page sends no request to Google Fonts or any other font service. It does run first-party visit logging, described in full below, which an earlier version of this policy incorrectly said did not exist.

What zero-knowledge does and does not mean

Vault contents are encrypted in your browser with AES-256-GCM before transmission, under a key derived from your master passphrase with PBKDF2. That passphrase is never transmitted to Legatus and never stored. Legatus therefore holds no key capable of decrypting your vault, and cannot produce your plaintext contents on request, on subpoena, or after a server breach.

The honest qualification

That is a property of the design, and a design is not a guarantee. It depends on the integrity of the code your browser receives. An attacker who compromised the delivery of that code could, in principle, capture a passphrase at the moment it is typed — before any encryption happens. Legatus has not undergone a third-party cryptographic audit or penetration test. An earlier version of this policy claimed no party could decrypt a vault “under any circumstance”. That was an overstatement and has been removed.

Who else processes your data

Five processors are involved. Supabase provides the database, authentication and file storage. Vercel hosts and serves the application. Resend delivers transactional email such as nominee invitations and check-in reminders. Telegram carries the visit alerts described below, and ipwho.is converts an IP address into an approximate location. Each receives only what it needs, and none receives anything that would decrypt a vault.

ProcessorPurposeWhat it sees
SupabaseDatabase, auth, file storage, scheduled jobsEmail addresses, ciphertext, death certificates, audit logs
VercelApplication hosting and deliveryRequest metadata such as IP address and user agent
ResendTransactional email deliveryRecipient email addresses and message contents
TelegramDelivery of visit alerts to a private chatThe contents of each alert: IP address, approximate location, pages viewed, and the account name when signed in
ipwho.isIP address to approximate location and network operatorThe visitor’s IP address, and nothing else

Telegram is operated by Telegram FZ-LLC and ipwho.is by its operator, both outside India. Alerts are therefore transferred outside India in the ordinary course of delivery. Neither receives anything capable of decrypting a vault, and neither is sent your vault contents, your passphrase or your email address.

Email sent through Resend is delivered over Amazon SES infrastructure. Legatus does not sell, rent, share or monetise personal data, and does not permit any processor to use it for their own purposes.

Death certificates

Where a nominee raises an expiry claim, the death certificate they upload is stored in a private bucket that is not publicly readable. Access requires a signed URL that expires after 15 minutes, and only an administrator can generate one. Review is a human reading a document, not a check against a government registry.

Visit logging

Legatus sends a real-time alert to a private Telegram chat when someone visits its public pages. Each alert records the visitor’s IP address, approximate city-level location, network operator, browser and device, which pages were viewed and for how long, how far they scrolled, and what they clicked. Alerts exist only as messages in that chat. Nothing is written to a database, and there is no analytics account, cookie or advertising identifier involved.

It runs on public pages only — the home page and the guides, glossary, FAQ, and legal pages. It does not run inside your vault, on the nominee area, on the administrator area, on a nominee invitation link, or on the sign-in and account-creation pages. Which pages you open inside your vault, and how long you spend there, are never recorded.

RecordedNever recorded
IP address, and the city, region and country it resolves toPrecise device location — the browser location permission is never requested
Network operator and whether the address is a datacenter or mobile networkAnything typed into any field, including passwords and passphrases
Browser, operating system, screen and window size, language, timezoneAny page inside the vault, nominee, admin or invitation areas
Pages viewed on public pages, time on page, active versus idle time, scroll depthCookies set for tracking — the beacon sets none
That an element was clicked, and its visible labelThe contents of any field, and any value you enter
A score estimating whether the visitor is a person or a script, and the reasons for itYour email address
Your display name, when you are signed inAny identifier linking you across other websites
Keystrokes are counted, never captured

The number of key presses during a visit is counted, because a script does not type and a person does. Whichkeys were pressed is never read, stored or sent. The labels recorded against clicks come from an element’s visible text, such as “Create your vault”, and never from a value you entered.

Why it exists. Legatus is a pre-launch service run by one person. The alerts answer whether anyone is arriving, from where, what they read, and whether traffic is real people or automated crawlers. That is the whole purpose. It is not used for advertising, profiling, scoring you as a customer, or any decision that affects you or your vault.

Sign-in alerts. An alert is also sent when a password is accepted on the sign-in page and when a new account is created. This is a security signal: it tells the operator that someone authenticated successfully, and from where, which is how an unexpected access to an account would be noticed. It carries your display name, the location and the device — never your email address, your password or your passphrase, none of which leave your browser for this purpose. The alert for sign-in fires when the password is accepted, which is before any two-factor challenge, so it can represent an attempt that was subsequently blocked.

How long it is kept. There is no retention period, because there is no store. Alerts are messages in a private Telegram chat and persist there until deleted, in the same way any chat message does. They are not written to the Legatus database, not exported, and not aggregated into a profile. Deleting your account does not delete past alerts, because they are not linked to your account record — but they are also never retrieved or used after the moment they are read.

Do Not Track is recorded, not obeyed. If your browser sends a Do Not Track or Global Privacy Control signal, that fact is noted in the alert, but visit logging continues. An earlier version of this policy said the opposite, and the change is stated here rather than quietly made.

Why that changed

Legatus did honour those signals. It stopped because they are switched on by the browser rather than chosen by you for this site — Brave, DuckDuckGo and Firefox private windows all send Global Privacy Control by default — so treating them as consent decisions silently removed a large share of visits while telling nobody. The opt-out below is the control that does stop collection, and it is unambiguous: you choose it, for this site, and it takes effect immediately.

How to switch it off. Use the control below, or add ?notrack=1 to any Legatus URL. Either stops collection immediately and permanently for that browser — nothing is gathered and nothing is sent, rather than gathered and discarded. ?notrack=0 reverses it. The choice is stored in that browser alone, so it does not carry across your devices, and clearing site data forgets it. Adding ?notrack=status shows, on screen, whether the browser you are using is currently being logged and why.

Checking this browser…

How long data survives deletion

You may delete your account and vault at any time from account settings. Records and encrypted payloads are removed from the live database immediately. Legatus currently runs on Supabase’s Free plan, which does not include automated backups, so there is no backup archive retaining copies of a deleted vault.

Short-lived operational copies — database write-ahead logs and provider-side caches — may persist briefly as a normal part of how a database works, but they are not kept as a restorable archive. Any such copy is ciphertext, and because Legatus never held your passphrase it is not readable by Legatus or by anyone obtaining it.

An earlier version of this policy said deletion was “immediate and irretrievable” everywhere, which overstated it, and a later revision referred to a provider backup retention window, which does not exist on this plan. This is the accurate position.

Your rights under the DPDP Act, 2023

As a Data Principal you may request access to a summary of your personal data and how it is processed, request correction or erasure, nominate another individual to exercise these rights on your death or incapacity under Section 14, and raise a grievance. Requests go to the address in the next section.

Note the distinction the product itself is built around: a Section 14 nominee may exercise your data rights. That is not the same as inheriting your assets, which is governed by your will and by succession law. Naming nominees inside a Legatus vault is a technical arrangement for access, not a testamentary act.

Grievance redressal

Grievances about the handling of your personal data should be sent to Suman Debnath at defy@houseofnamus.com with “DPDP Grievance” in the subject line. Legatus aims to acknowledge within 72 hours and to resolve within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India.

Legatus is operated by one person, so a grievance is read and answered by that person rather than routed through a support desk. If a personal data breach occurs, affected users and the Data Protection Board will be notified as required by the Act.

Eligibility

Legatus is intended for use by adults aged 18 or over. It is not designed for children, and accounts are not knowingly created for anyone under 18. If you believe a child has created an account, contact defy@houseofnamus.com and it will be removed.

Governing law

This policy is governed by the laws of India. Disputes arising from it are subject to the jurisdiction of courts in India. Nothing in this policy limits rights you hold under the Digital Personal Data Protection Act, 2023 or the Consumer Protection Act, 2019, which cannot be waived by agreement.

Questions, data rights requests and vulnerability reports: defy@houseofnamus.com.