Legal

Privacy Policy

Last updated: October 9, 2026

Legend keeps what you choose to keep. We don't sell your data, we don't use it for advertising and we don't train models on your archive. You can take everything with you or delete it all, whenever you want.

1. Who we are

Legend (also called “Legend Collection” or “Collection Legend”) is operated by José Raúl Soriano Cazabal (“we”). Contact for privacy matters: raulcazabal@icloud.com.

2. What data we collect

We collect only what is needed to operate Legend. Specifically, this is what exists today in the app’s data model:

2.1 Account data

  • A stable identifier from Sign in with Apple or Google Sign-In.
  • Display name (displayName), if your sign-in provider supplies it. It is optional; we do not ask for it separately.
  • An invite code (inviteCode) generated automatically so other people can invite you to a Circle of trust. It is not an authentication identifier and is not shared with anyone unless you share it.
  • Your life/professional role and collector archetype (§4 explains what they are for), answered in the welcome questionnaire. Both are optional: you can always choose “Prefer not to say for now” or leave the questionnaire without answering (“Back to start” at any step), and you can change or delete them at any time from Profile.

2.2 Your archive content

  • The text of each entry, the date, the category/subcategory you choose, an optional sentimental value, and an optional economic estimate.
  • Photos, audio and video you attach. They are stored with Cloudinary (our media provider), not on our own servers. See §5.
  • Tags (tags), created by you or suggested by on-device automatic recognition (Terms of Use §3).
  • Location of each entry (optional). If you give the App location permission, we store where you captured an entry (coordinates and the place name), taken from the phone’s location when capturing or from the photo’s location data, and we use your location to show today’s weather in the home greeting (looked up on the spot and not stored). You can turn it off anytime in Settings › Privacy › Use my location, or deny the permission in iOS Settings: the App works the same without it. You can also delete or change the place of any entry.
  • Files you import. With Import (Settings › Connections) you can bring in photos, PDF, JSON, CSV, text, ZIP files or folders. They are read on your phone; only what you mark to keep is uploaded to your archive (each piece’s text, date and image). The rest of the file you chose never leaves the device, and the temporary copy is deleted when you finish.

2.3 Data from external sources you connect

If you connect a third-party account (Spotify, GitHub, Chess.com, Withings and others; the full catalog is in Settings › Connections inside the App), we store:

  • The access token for that account (connectionTokens), so we can bring in new data when you ask to sync. Never your password for that account.
  • The data that source exposes and that you choose to confirm as part of your archive (§2.2 applies to it once confirmed).
  • Unconfirmed drafts (conexionesBorradores): data we fetched from the source that you have not yet decided to keep or discard.

The sensitivity of this data varies by source, and that is deliberate. For example, your Spotify listening history is generally not considered sensitive data under most privacy regulatory frameworks. We treat it with the same technical protections as the rest of your archive, but the reinforced “special category” regime that applies to health data does not apply. For that reason, and for any source you connect: we do not guarantee the sensitivity classification of third-party data. It depends on the provider, the type of data it exposes, and your own jurisdiction. If you have doubts about a particular piece of data, treat it as sensitive to be safe.

Which sources can be connected and which can’t

We only connect a source when it offers an official way for you to authorize Legend to read your own data (an API with explicit permission, or a profile you made public yourself). That leaves three cases:

  • It connects. It’s in the catalog under Settings › Connections: you authorize access, you can see what it brings before saving it, and you can disconnect it whenever you want.
  • It can’t be connected. Some apps don’t let any other app read your data: encrypted messaging (WhatsApp, Signal, iMessage), tools that run only on your computer (such as Claude Code) or dating apps. There is no safe way to do it, so we don’t try.
  • Better to export. Some apps (ChatGPT, Instagram, TikTok, Netflix, Amazon and others) could only be connected through fragile workarounds that would ask for more access to your account than Legend should have, such as your password or reading your session. In those cases we recommend requesting your data export from the app itself (almost all of them offer it in their settings) and keeping in Legend whatever you want to hold on to.

We never ask for the password of another account, and we never read a source you didn’t authorize. When you confirm or discard something a source brought in, we keep a marker (which source and which item) so we don’t suggest it again; it never appears in your archive and it’s deleted when you delete your account.

Apps you suggest

If you look for an app that isn’t in the catalog and suggest it, we store the name you typed, the answer we gave you (we’ll review it, it can’t be connected, or it’s better to export), your user identifier and the date, in sugerenciasFuentes. We use it only to decide which connections to build; it isn’t shown to anyone else, it isn’t shared with that app, and it’s deleted along with your account.

If you already have Plus, reach your plan’s limit and tap “Soy cliente premium” (I’m a premium customer), we store your user identifier, which limit you reached and the date, in avisosTopePlus, so the team can contact you. It isn’t shown to anyone else and it’s deleted along with your account.

Your feedback (“Cuéntanos”)

If you send us feedback from Help or by shaking your iPhone, we store what you picked (for example “Me encanta” or “Algo falla”), the text you wrote, your user identifier, the Legend version, the iOS version, your iPhone model and the date, in feedback. If you attach a screenshot (with your markings), a voice note or a recording of Legend’s screen, we store it in a private folder only the team can see. Nothing is attached automatically: you choose it before sending. We use it only to improve the app, and it’s deleted along with your account.

Google user data (Google Sign-In, Google Books, YouTube and Google Calendar)

Legend uses these Google permissions, and only when you authorize them on Google’s consent screen:

Feature Permission (scope) we request Google data we receive
Sign in with Google Basic Google Sign-In identity Account identifier, name and email
“Google Books” connection (Settings › Connections) https://www.googleapis.com/auth/books and email Your bookshelves and the books you have already marked in Google Books, and the email of the connected account
“YouTube” connection (Settings › Connections) https://www.googleapis.com/auth/youtube.readonly (read-only) The channels you subscribed to, with the subscription date, and the playlists you created. We do not read your watch history, and we never post, comment or change anything in your account
“Google Calendar” connection (Settings › Connections) https://www.googleapis.com/auth/calendar.events.readonly (read-only) Past events from your primary calendar (title, date, location), of which we only suggest the ones that look like memories (a trip, a wedding, a concert). We do not read other calendars or create or change events
  • How we use it. Only to (1) identify you inside the App, and (2) suggest, as drafts, the books on your Google Books shelves, your YouTube subscriptions and playlists, or your past Google Calendar events, so you can decide whether to keep them in your archive. Drafts do not become part of your archive until you confirm them.
  • Who we share it with. No one. We do not sell, rent or transfer Google user data to third parties, we do not use it for advertising or profiling, and we do not use it to train artificial intelligence models. No person at Legend reads your bookshelves, subscriptions or calendar: access is automated and only for the purposes described above.
  • Where and how it is stored. The Google access token is stored on the server (encrypted at rest by Google Cloud), in a collection that not even the App itself can access: only our server functions read it. We do not store your Google password.
  • How long. While the connection is active. When you disconnect Google Books, YouTube or Google Calendar from Settings › Connections, we stop reading your account and revoke access with Google. When you delete your account, we also delete the token, the connection record and the pending drafts (§8). What you already confirmed as part of your archive is yours and stays until you delete it or delete your account.
  • How to revoke access. From Legend (Settings › Connections › Disconnect) or from your Google account at https://myaccount.google.com/permissions. You can also ask us to delete your data by writing to raulcazabal@icloud.com.

Legend’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2.4 Circle of trust (social features)

If you create or join a Group, we store the invitation, the membership, and which collections/items you explicitly choose to share with that Group (groupSharedCollections, groupSharedItems). Nothing in your archive is shared with anyone unless you explicitly turn it on for that specific Group.

2.5 Safeguard / Legacy

If you fill in the Safeguard section of an item (holding, evidence of ownership, transferability), that text is stored as part of your archive. It is not a legal instrument; it is information you declare for your own use. See Terms of Use §2.

2.6 Technical and diagnostic data

We use Firebase Crashlytics and Sentry to detect errors and crashes in the app. These tools may automatically collect: device/session identifiers, operating system version, and the technical trace (stack trace) of an error, but not the content of your archive.

2.7 Data we do NOT collect

  • We do not receive a history of where you’ve been: the only location that reaches our servers is each entry’s, and only if you allow it (§2.2). If you turn on “Remember where you listen” in Connections (off by default; it asks for “Always” location permission), your iPhone notes the places you arrive at and leave so it can place what you listened to on Spotify and tell your routine apart from your moments. Those visits are stored only on your phone, never uploaded, deleted automatically after 60 days and all deleted when you turn it off; only the place of a moment saved as an entry reaches your archive.
  • We do not run facial recognition on your photos.
  • From a photo’s metadata (EXIF) we only read the date and place it was taken, to suggest them for the entry; nothing else.

2.8 Cookies and similar technologies on this website

The Collection Legend website uses an equivalent technical cookie (kept in your browser’s local storage) to remember your cookie choice. It is strictly necessary so the notice is not shown again on every visit, and it is not used to identify you.

If you choose Analytics, we load Google Analytics 4 to measure, in aggregate, which pages are visited and to improve the site. This category is optional, is not activated before your consent, and we do not use these metrics for personalized advertising. If you choose Reject non-essential, Google Analytics is not loaded.

You can change or withdraw your choice at any time from the Cookie preferences link in the footer. Your consent is recorded in your browser for the current version of the notice. For the general handling of your data, see the rest of this Privacy Policy.

2.9 Email lists and roll photo on this website

From this website you can join two separate lists: the launch notice (we email you when Legend is available) and the Mail Club waitlist. For both we store your email, the date and record of your consent, your browser language and, if you arrived through a campaign link, its parameters (utm_medium, utm_campaign, utm_content). We send you an email to confirm; until you confirm it we won’t write to you again. Every email includes a link to leave that list.

If you are on the Mail Club waitlist and have confirmed your email, you can upload up to three photos from the camera at the end of the roll on the page. Your browser shrinks them before sending, and we store them in private Firebase (Google) storage, linked to your email. They are not published or shown to anyone else: we only use them to prepare your Mail Club. On the page, only you see your photo, kept in your own browser.

3. Automatic recognition (on-device AI)

See Terms of Use §5. In short: the processing of photos/audio to suggest a category and tags runs on your own phone, not on our servers or a third party’s. We never see or store the result of that processing until you confirm the entry.

4. What we use your data for

  • To operate the Service: show you your archive, sync your connected sources, run the Circle of trust.
  • To detect and fix errors (Crashlytics/Sentry, §2.6).
  • To tell you about important changes to the Service or to these documents.
  • Your role and collector archetype (§2.1) only decide what to show you first when you enter (which categories to highlight, which Connections sources to suggest) and serve as the starting point of your figure (one of the 12 Legend figures) until you have creations of your own, which are what finally decide it. It is not public data and is not shared with anyone outside Legend.

We do not sell your data. We do not use your content for advertising. We do not train AI models on your photos, audio or text.

5. Third-party providers that process data on our behalf

Provider What it processes
Firebase (Google): Auth, Firestore, Cloud Functions Authentication, your archive’s database, sync logic
Cloudinary Storage of photos/audio/video
Sign in with Apple / Google Sign-In Authentication. We do not receive your password from those providers
Firebase Crashlytics, Sentry Diagnosis of technical errors
Resend Sending the confirmation emails for the website lists (§2.9)
Firebase Storage (Google) Photos uploaded from the roll camera on the website (§2.9)

Each of these providers has its own privacy policy and may process data outside your country of residence.

6. Health and fitness data

Legend only reads health and activity data when you turn it on, and only the minimum needed to create an entry in your archive:

  • Apple Health — workouts (the “Apple Health” connection in Settings › Connections). With your permission, we read your workouts (type, date, duration and distance) to suggest them as drafts. We do not read heart rate, sleep, weight or any other body measurement.
  • Apple Health — state of mind (optional, in Settings › Privacy, off by default). With your permission, we read today’s mood entry that you already logged in the Health app to prefill the sentimental value of the entry you are capturing. It is only saved if you confirm the entry; we do not build a history of your mood.
  • Withings. With your authorization, we read your devices and your workouts. We do not request access to your body measurements (weight, blood pressure, sleep).

Legend never writes data to Health. Data that comes from Apple Health (HealthKit) or Withings is not used for advertising, marketing or data mining, is not sold and is not shared with third parties; it is only used to show you your own archive. We do not store it in iCloud. You can withdraw permission at any time in iOS Settings › Health › Data Access & Devices › Legend, or by disconnecting the source; what you already confirmed in your archive remains yours until you delete it.

7. Your rights

Regardless of where you are, you can:

  • Access your full archive inside the App at any time.
  • Correct any entry by editing it yourself.
  • Delete your account and your data (§8).
  • Disconnect any external source without losing what you have already confirmed.

If you are in the European Union/European Economic Area, you also have (under GDPR) the right to data portability, to object to certain processing, and to lodge a complaint with your local data protection authority.

8. Retention and deletion of data

When you delete your account from Settings, we delete your profile, the items and collections in your archive, the associated media files (photos/audio/video on Cloudinary), your external connections and their access tokens (revoking them with the provider when that provider allows it), your pending drafts, your medals, and your activity history. If you are the organizer of a Group, the Group is deleted along with what you shared there; if you are a member, you leave the Group and only what you shared is deleted. What other members shared continues to exist for them.

If you signed in with Apple, when you delete your account we ask you to confirm with Apple one last time and revoke Legend’s access to your Apple ID: the App stops appearing in “Apps using your Apple ID”. If you cancel that confirmation, nothing is deleted and you can try again whenever you want.

We keep no Safeguard records (safeguardRecords) because that feature is not yet built in the app, so there is nothing to delete there today; this note will be updated when it is implemented.

Your email stays on the website lists (§2.9) until you leave through the link in any of their emails or ask us through the contact in §13; then we stop writing to you. If you ask us to delete your Mail Club waitlist data, we also delete any photos you uploaded.

9. Security

Your archive lives in Firestore with access rules that require that only you (authenticated) can read or write your own documents. No other user of the app can access your archive except what you explicitly share with your Circle of trust (§2.4). The tokens of your external connections are stored separately from your public profile.

No transmission of data over the internet is 100% secure. We make reasonable efforts to protect your information, but we cannot guarantee absolute security.

10. Children’s privacy

Legend is for people 18 and older. It is not directed at minors, and we do not knowingly collect data from minors. If you believe a minor has given us data, write to raulcazabal@icloud.com so we can delete it.

11. International data transfers

Because Legend is available globally and our providers (§5) operate in different countries, your data may be processed outside your country of residence.

12. Changes to this Policy

If we make a material change, we will notify you inside the App before it takes effect.

13. Contact

raulcazabal@icloud.com