LegaKeep is a product published by MEMOPYK EURL.
Privacy Policy
Last updated : 21 mars 2026
1. Who are we?
LegaKeep is published by MEMOPYK EURL, SIRET 990 228 736 00015, 2 rue de la Peyrolerie, 46100 CAPDENAC.
Contact : privacy@legakeep.com
2. Zero-knowledge architecture
Your documents are encrypted on your device before being sent to our servers. We cannot read them. Your vault key is never transmitted to our servers. Even in the event of unauthorized access to our servers, your documents remain unreadable without your vault key.
The encryption used is AES-256-GCM with a KEK/DEK key hierarchy. Key derivation uses Argon2id (64 MB memory, 3 iterations), per NIST recommendations.
3. Data collected
- Email address - authentication and notifications
- Documents - client-side encrypted, unreadable by our servers
- Metadata - name, category, file type (in clear for search)
- Sessions - device name, hashed IP fingerprint, user agent
- Audit log - immutable hash chain of all actions
- Emergency contacts - stored encrypted locally on your device
4. Data we do NOT collect
- No analytics data (no Google Analytics or equivalent)
- No advertising trackers or third-party cookies
- No biometric data (stays on your device)
- No vault key (never transmitted, never stored)
5. Sub-processors
- Backblaze B2 (UE) - encrypted blob storage only
- Expo (US) - push notifications (token + title/body)
- Have I Been Pwned (UK) - breach check (k-anonymity, vault key never transmitted)
- FreeTSA - RFC 3161 certified timestamp (hash only)
6. Your rights
Under the GDPR, you have rights of access, rectification, erasure, restriction, portability, and objection.
Exercise your rights directly in the app (Settings > Data & Privacy) or by email at privacy@legakeep.com.
Lodge a complaint with the CNIL : www.cnil.fr
Full document
This page is a summary. The full privacy policy text is available on request at privacy@legakeep.com.