Legal

Privacy Policy

Last updated: October 2, 2026 · AddMyLegacy at https://addmylegacy.com

1. Who we are

AddMyLegacy (“we”, “us”, “our”) operates the preservation and licensing platform at https://addmylegacy.com. Related brand and mark services may be offered under addmymark.com. This Policy explains how we handle data and should be read together with our Terms of Service.

2. Information we collect

  • Account data: username, email, profile fields, role, verification status.
  • Content & metadata: uploaded files, SHA-256 fingerprints, previews, titles, descriptions, rights declarations, and your platform exhibition consent preference per asset.
  • Transaction data: license purchases, preservation orders, payment references (processed by Stripe when enabled), and fulfillment/mailing details (processed by providers such as Lob when applicable).
  • Technical data: IP address, device/browser type, audit logs (views, downloads, reports), cookies/session identifiers.
  • Communications: support messages, DMCA notices, dispute reports.

3. How we use information

We use data to provide, secure, operate, and improve the Service, including proof certificates, Content ID matching, rights review, licensing, the Platform Exhibition (only for assets where you have granted consent), fraud prevention, legal compliance, and product, technology, and model development. We do not sell your personal information.

4. Use of content for AI/LLM and datasets

As described in our Terms of Service (Section 5), we may use uploaded content and associated metadata as input to and output of machine-learning and large language model (LLM) systems; to train, fine-tune, evaluate, and improve such models; and to form, curate, and distribute datasets used to develop or operate them. Where this involves personal data, we rely on the legal bases described below and take steps to limit, aggregate, or de-identify data where appropriate. We will not sell your individual work as a standalone object presenting us or a third party as its author.

5. Target market & EU/UK users

The Service is operated from, and directed to users in, the United States. We do not target, market, or offer the Service to individuals in the European Union, EEA, United Kingdom, or Switzerland, and we do not intentionally monitor the behavior of, or offer goods or services to, data subjects in those territories. If you access the Service from those regions, you do so on your own initiative.

To the extent the GDPR, UK GDPR, or similar law nonetheless applies to you, the legal bases below apply and you retain the mandatory rights described in Section 10. Those mandatory provisions prevail only to the minimum extent legally required.

6. Legal bases (EEA/UK)

Where GDPR applies, processing is based on contract performance, our legitimate interests (security, anti-infringement, product and model improvement, and operating our business), legal obligation, and consent where required (e.g. optional marketing).

7. Sharing & third-party integrations

We share data with service providers and integrations as needed to operate, secure, and improve the Service. These include, without limitation:

  • Payment processors (e.g. Stripe) for checkout, billing, and fraud prevention;
  • Mail, print, and fulfillment providers (e.g. Lob) where physical delivery or document services are used;
  • Cloud hosting, storage, email, analytics, and security vendors that support the Platform;
  • Professional advisers and authorities when required by law or to enforce our Terms; and
  • Any other integration reasonably necessary for Platform operation.

We may also share or transfer data in connection with a merger, acquisition, financing, or sale of assets. Public certificate verification exposes only the non-sensitive certificate fields you choose to verify.

8. Retention & no storage guarantee

We retain account and certificate data while your account is active and as needed for legal, audit, and certificate-integrity purposes. We do not guarantee the storage, retention, or recoverability of uploaded files or User Content; our preservation responsibility is limited to proof certificates (see Terms Section 7). You are responsible for keeping your own backups. Derived data — including fingerprints, embeddings, analytics, models, and datasets — may be retained and used even after individual content is deleted. You may request deletion subject to outstanding disputes, licenses, certificate integrity, or legal holds.

9. Security

We use reasonable, industry-standard measures including hashed file fingerprints, signed certificates, access controls, and staff review for rights claims. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Your rights

Depending on jurisdiction, you may access, correct, delete, or port your data, or object to or restrict certain processing. Contact addmylegacy+privacy@gmail.com. California residents may have additional rights under the CCPA/CPRA. Exercising these rights does not override our retention obligations or the licenses and derived-data rights described in our Terms.

11. Children

The Service is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect their data.

12. International transfers

Data may be processed in the United States and other countries where our providers operate, with appropriate safeguards where required.

13. Changes

We may update this Policy at any time; material changes will be posted here with an updated date. Continued use after changes constitutes acceptance.

14. Contact

addmylegacy+privacy@gmail.com · https://addmylegacy.com