Prepared August 30, 2026 from the current My Legacy Console document at /privacy. Please use Microsoft Word Track Changes and comments for revisions./privacy
1. Introduction & Scope
Who we are and what this policy covers
My Legacy Console is a product owned and operated by Montauk Trading Company, LLC, a Delaware limited liability company authorized to do business in New York ("Montauk Trading," "we," "us," or "our"; My Legacy Console is the "Service"). The Service is your secure, web-based daily command center for generational wealth โ a privacy-first financial management platform built for the $124 trillion Great Wealth Transfer from Baby Boomers to Gen X, Millennials, and Gen Z. The platform accesses only your cloud drives, never stores your underlying data or documents, and helps individuals and families organize, protect, and transfer their physical and digital legacy across generations. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application, mobile interfaces, APIs, and related services.
Key Commitment
We treat your financial data with the highest standard of care. All sensitive fields are encrypted using AES-256-GCM field-level encryption at rest. We never sell your personal or financial data to third parties. Period.
By accessing or using My Legacy Console, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
2. Information We Collect
Categories of personal and financial data
๐ค Account Information
- Full name, email address, and profile photo (provided via Replit authentication or direct registration)
- Organization name and membership role (owner, admin, or member)
- Subscription tier (Free, Standard, or Pro) and billing information processed by Stripe
- Mobile phone number (optional) โ provided only if you choose to enable SMS features at registration or in Settings
๐ฑ Mobile Phone & SMS Communications (Optional)
Providing a mobile phone number is entirely optional. If you choose to add one, here is exactly how it is used and protected:
- Daily net-worth snapshot text: Each morning we send one short SMS containing your total net worth, the day-over-day change, and any flagged accounts. This is the headline benefit of providing your number.
- Optional login verification codes: One-time SMS codes sent only when you choose code-based login or two-factor authentication.
- Critical security alerts: Limited to events such as a sign-in from a new device or a password change you did not initiate.
- What we will NEVER do with your phone number: we will never sell it, rent it, share it with marketers or data brokers, use it for promotional or upsell campaigns, or pass it to any third party except the SMS delivery vendor (Twilio) strictly for the purpose of transmitting the messages above.
- You stay in control: reply STOP to any text to opt out instantly, or remove your number anytime from Settings โบ Profile. Standard message and data rates from your carrier may apply.
๐ฐ Financial Data
- Assets, liabilities, net worth calculations, and investment portfolio data
- Bank account information linked via Plaid (account names, balances, and transaction metadata). Your bank username and password are entered directly with Plaid and are never received, transmitted, or stored by us โ we hold only a read-only Plaid access token, stored encrypted (AES-256-GCM), which cannot move money or log in to your bank
- Budget items, income sources, expense categories, and spending histories
- Insurance policies, legal documents, tax document records, and estate plans
- Stock holdings, investment analysis results, and credit report data
๐ Documents & Files
- Document metadata (names, categories, dates) for items linked from Microsoft OneDrive
- Scanned document images uploaded temporarily for OCR processing โ processed in memory and not permanently stored on our servers
- OneDrive file references (file IDs, share links) โ actual documents remain stored in your personal OneDrive account
- Google Drive file references (file IDs, names, links) accessed read-only โ actual files remain stored in your personal Google Drive account and are never copied to our servers
๐ง Connected Email (Gmail & Outlook)
- When you connect Gmail (read-only) or Microsoft Outlook, we scan incoming messages to detect bills, invoices, statements, and financial documents
- Message content, sender, subject, and attachments are processed in memory for this purpose โ we store only the extracted financial details (e.g., payee, amount, due date), not full copies of your emails
- Gmail access is strictly read-only โ we never send, modify, or delete your Gmail messages. For a connected Outlook account, we send email only when you explicitly initiate it from within the Service
๐ป Usage & Technical Data
- IP address, browser type, device information, and operating system
- Pages visited, features used, and timestamps of interactions
- Calendar events synced from Microsoft Outlook (titles, dates, and categories only)
- AI assistant conversation logs (queries and responses within the application)
3. How We Use Your Information
Purposes for processing your data
Purpose | Description | Legal Basis |
|---|---|---|
Service Delivery | Provide core features including dashboard analytics, budget tracking, investment analysis, document management, and estate planning tools | Contractual Necessity |
AI-Powered Insights | Generate personalized financial summaries, document analysis via OCR, and contextual assistance through AI agents | Contractual Necessity |
Account Management | Authenticate users, manage subscriptions, process payments via Stripe, and enforce access controls | Contractual Necessity |
SMS Communications (Opt-in) | If you provide a mobile number, send your daily net-worth snapshot text, optional login verification codes, and critical security alerts (e.g., new-device sign-in). Never used for marketing, never sold, never shared except with our SMS carrier (Twilio) for delivery. Reply STOP at any time to opt out. | Consent |
Security | Detect and prevent unauthorized access, fraud, and security threats; maintain audit logs | Legitimate Interest |
Service Improvement | Analyze usage patterns to improve features, fix bugs, and optimize performance | Legitimate Interest |
Communications | Send essential service notifications, security alerts, and subscription updates via email (Outlook integration) or SMS (Twilio) | Consent |
Legal Compliance | Respond to legal requests, comply with applicable laws, and enforce our Terms of Service | Legal Obligation |
4. Data Storage & Encryption
How we protect your sensitive information
AES-256-GCM Field-Level Encryption
Sensitive financial fields โ including asset values, account numbers, Social Security numbers, and policy details โ are encrypted at the field level using AES-256-GCM before being written to the database. Each encrypted value uses a unique initialization vector (IV). Encryption keys are managed separately from the database and are never stored alongside encrypted data.
Security Layers
Layer | Technology | Details |
|---|---|---|
Transport | TLS 1.3 | All data in transit is encrypted via HTTPS with modern TLS |
At Rest | AES-256-GCM | Field-level encryption for all sensitive financial data |
Authentication | Replit Auth / OAuth 2.0 | Secure authentication with session management |
Authorization | RBAC + Org Isolation | Role-based access control with organization-level data isolation |
Database | PostgreSQL | Hosted on Replit with automatic backups and encrypted volumes |
Documents | OneDrive & Google Drive | Documents remain in your Microsoft OneDrive or Google Drive (read-only) โ only metadata and links stored |
5. Third-Party Services
External services we integrate with
Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
Stripe | Payment processing | Email, payment method, subscription details | stripe.com/privacy |
Plaid | Bank account linking | Read-only access token only โ bank credentials are entered directly with Plaid and never received or stored by us; the token is stored encrypted (AES-256-GCM) and cannot initiate transfers | plaid.com/legal |
Microsoft (OneDrive/Outlook) | Document storage & calendar | OAuth tokens, file metadata, calendar events | privacy.microsoft.com |
Google (Gmail & Drive) | Email scanning for bills/invoices & document access (read-only) | OAuth tokens; email content processed in memory; Drive file metadata & content (read-only) | policies.google.com/privacy |
OpenRouter (Google Gemini) | AI agent responses | Contextual prompts (no PII sent to AI models) | openrouter.ai/privacy |
xAI (Grok) | Global AI assistant | Contextual prompts (no PII sent to AI models) | x.ai/legal/privacy-policy |
Twilio | SMS notifications | Phone number, message content | twilio.com/legal/privacy |
AwardWallet | Rewards-points tracking (loyalty account balance retrieval) | Loyalty-program account identifiers and current balances for programs the user connects | awardwallet.com/privacy |
Polygon.io | Stock market data | Stock ticker queries only | polygon.io/privacy |
Replit | Hosting & authentication | User profile, session data | replit.com/site/privacy |
AI Data Handling
When you interact with AI assistants in My Legacy Console, contextual data (such as page-level summaries) may be sent to AI providers to generate responses. We strip personally identifiable information (PII) before sending prompts. AI providers do not use your data to train their models. Conversations are ephemeral and not stored by AI providers beyond the request lifecycle.
Google API Services โ Limited Use Disclosure
If you connect a Google account, My Legacy Console requests read-only access to your Gmail (gmail.readonly) to detect bills, invoices, statements, and financial documents, and read-only access to your Google Drive (drive.readonly) so you can browse, search, preview, and open your own documents from within the Service. We never send, modify, or delete your email or files.
My Legacy Console's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Google Gmail and Google Drive is used only to provide or improve the user-facing features described above; is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; is not used or transferred for advertising purposes; and is not used to train generalized or non-personalized artificial-intelligence or machine-learning models. You can disconnect a connected Google account at any time in Settings, or revoke access directly from your Google Account security settings.
6. Data Sharing & Disclosure
When and how we may share your information
We do not sell, rent, or trade your personal or financial data. We may share information only in the following circumstances:
- Service Providers: With the third-party services listed above, strictly for the purposes described (payment processing, document storage, etc.)
- Within Your Organization: Data is shared among members of your organization based on role-based access controls you configure
- Legal Requirements: When required by law, subpoena, court order, or governmental request
- Safety: To protect the rights, property, or safety of My Legacy Console, our users, or the public
- Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified before your data is transferred and becomes subject to a different privacy policy)
- With Your Consent: When you explicitly authorize sharing with a specific party
7. Your Rights & Choices
How you can control your data
All Users
- Access: Request a copy of all personal data we hold about you
- Correction: Update or correct inaccurate information through your account settings
- Deletion: Request deletion of your account and associated data
- Export: Download your data in a portable format
- Restrict Processing: Request that we limit how we use your data
- Disconnect: Revoke access to connected services (Plaid, OneDrive, Outlook) at any time
California Residents (CCPA)
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your CCPA rights
EU/EEA Residents (GDPR)
- Right to access, rectify, erase, and port your personal data
- Right to restrict or object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
How to Exercise Your Rights
To exercise any of the rights described above, contact us at privacy@mylegacyconsole.com or use the "Delete Account" option in your account settings. We will respond to verified requests within 30 days.
8. Cookies & Tracking
Technologies we use to enhance your experience
Type | Purpose | Duration | Required |
|---|---|---|---|
Session Cookies | Maintain your login session and authentication state | Session | Essential |
Preference Cookies | Remember your theme (dark/light mode), sidebar state, and display preferences | 1 year | Functional |
localStorage | Store UI preferences, dashboard layout, and subscription tier caching | Persistent | Functional |
We do not use advertising cookies, analytics trackers, or third-party tracking pixels. We do not participate in cross-site tracking or behavioral advertising.
9. Children's Privacy
Our policy regarding minors
My Legacy Console is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take immediate steps to delete that information. If you believe a child under 18 has provided us with personal data, please contact us at privacy@mylegacyconsole.com.
10. Data Retention
How long we keep your information
Data Category | Retention Period | After Deletion |
|---|---|---|
Account Data | Duration of account + 30 days | Permanently deleted |
Financial Records | Duration of account + 30 days | Permanently deleted |
Document References | Duration of account | References deleted; files remain in your OneDrive |
Payment Records | 7 years (legal requirement) | Anonymized after retention period |
AI Conversations | Session only | Not retained after session ends |
Scanned Documents | Processing only (minutes) | Immediately purged from memory after OCR |
Audit Logs | 90 days | Automatically purged |
11. International Transfers
Cross-border data handling
My Legacy Console is hosted in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer of your information to the United States. We implement appropriate safeguards, including encryption and access controls, to protect your data regardless of where it is processed.
12. Changes to This Policy
How we notify you of updates
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by posting a prominent notice in the application at least 30 days before the changes take effect. The "Last Updated" date at the top of this policy reflects the date of the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Information
How to reach us about privacy matters
Privacy Inquiries | privacy@mylegacyconsole.com |
|---|---|
Data Protection Officer | dpo@mylegacyconsole.com |
General Support | support@mylegacyconsole.com |
Mailing Address | Montauk Trading Company, LLC Attn: Privacy Department |