Effective July 5, 2026
Legacy Pulse · Legal notice
General Privacy Policy
What Legacy Pulse collects, how it is used to deliver the service, and the rights you have over it.
Who we are and what this policy covers
Legacy Pulse is a family health data vault: a place to store your family's health records as you received them, organize them into searchable entries, and turn them into summaries you can bring to an appointment. This policy explains what information Legacy Pulse collects, how it is used, who processes it on our behalf, how long it is kept, and the rights you have over it.
This policy applies to the Legacy Pulse web application at pulse.lgc.my and to the records you store there. Health information is additionally covered by our Consumer Health Data Privacy Policy, AI processing is described in the AI Processing Notice, child profiles in the Children & Family Profile Notice, and genomic files in the Genomic File Notice. Where those notices are more specific, they control.
Information we collect
Account information. When you create an account we collect your email address and the credentials used to sign in. We do not ask for more identity information than the service needs.
Household setup. During onboarding you provide a household name and a zip code. The zip code is used to show environmental context for your area, such as local air quality. Environmental information is shown as context and awareness only — it is not health guidance.
Family member profiles. You can add profiles for the people in your household: names, ages, relationships, and household roles. Child profiles include additional guardianship details described in the Children & Family Profile Notice.
Records you upload. The core of Legacy Pulse is the vault: PDFs, photos, and scans of health records you choose to upload, and phone-health exports you choose to import (for example, an Apple Health export file). These records can contain lab results, vital signs, medication lists, immunization histories, visit notes, and similar health information.
Information created by processing your records. When you ask Legacy Pulse to organize a document, it creates structured entries linked back to the source document, search indexes over those entries, and any summaries you generate. We treat this derived information with the same care as the records it came from.
Operational records. We keep an audit log of material actions on your account — uploads, downloads, deletions, exports, and AI requests — and a record of each consent you grant or withdraw, with a timestamp and the version of the notice it covered. These records exist so that you can see what happened in your account and so that we can meet our legal obligations.
How we use your information
Your information is processed only to deliver your vault, search, and summaries. Concretely, that means: storing your original files and preserving them as uploaded; organizing uploads into source-linked entries; answering your questions from your own records, with citations; generating the summaries you request; showing environmental context for your zip code; and operating, securing, and supporting the service.
Your records are never used to train AI models. We do not use your information for advertising, and we do not build advertising or marketing profiles from it.
We do not run third-party advertising technology, tracking pixels, or analytics tools that would disclose the health-data context of your activity to anyone else.
Service providers who process data for us
Legacy Pulse runs on infrastructure operated by a small number of service providers who process data on our behalf, under contracts that limit what they may do with it. They may use your information only to provide their service to us — not for their own purposes.
Cloud hosting, database, and file storage. Your original files, structured entries, and indexes are stored with our cloud infrastructure providers, encrypted in transit and at rest.
AI processing. When you ask Legacy Pulse to organize a document or answer a question, the relevant content is processed by our contracted AI provider on their servers. Our vendor terms prohibit the provider from training models on your data and limit how long they may retain it. The AI Processing Notice describes this in detail.
Transactional email. We use an email provider to send account messages such as sign-in links. It does not receive the contents of your vault.
We maintain a current list of these service providers and the countries where they process data, and we will provide it on request through the contact below. When a provider changes, we update the list before the change takes effect.
No sale, no advertising use
We do not sell your personal information, and we do not sell your health data. We do not share personal information for cross-context behavioral advertising, and we do not use health data to target advertising of any kind.
If our business model ever changed in a way that affected these commitments, we would update this policy, give you prominent notice, and ask for your consent before anything new happened to data already in your vault.
Retention and deletion
We keep your information for as long as your account is active, so your vault is there when you need it. You are always in control of what stays.
You can delete a single document, one person's entire profile, or the whole account. Every deletion follows the same full cascade: the original files are removed from the vault; every entry extracted from them is removed; the related search index and embedding entries are removed; summaries and reports that reference them are updated or removed; our service providers are instructed to delete the corresponding data they hold for us; and backup copies are cleared within 90 days.
Deletion is tracked through each of those stages so that nothing is silently left behind. A limited operational record (for example, the audit entry that a deletion was requested and completed, without the deleted content) may be retained where the law requires or permits it, so we can demonstrate that we honored your request.
Your rights
Access. You can see everything in your vault at any time by signing in, and you can ask us to confirm what categories of information we hold about you.
Export. You can export a portable copy of your data — your original files and the structured entries created from them — from Settings.
Correction. You can correct information in your profiles, and you can flag any AI-extracted value as disputed or corrected. A disputed value stays visibly marked, and your correction travels with it wherever that value appears, including in search results and summaries.
Deletion. You can delete a document, a profile, or your whole account, with the full cascade described above.
Exercising these rights costs nothing, and we will not treat you differently for using them. If we ever decline a request (for example, because we cannot verify it), we will explain why and how to appeal. Rights specific to consumer health data, including the appeal process, are described in the Consumer Health Data Privacy Policy.
How we protect your information
Your information is encrypted in transit and at rest — across original files, structured entries, search indexes, summaries, and backups. Access inside Legacy Pulse follows least-privilege rules: systems and people can reach only what their role requires, administrative access requires multi-factor authentication, and material access is recorded in audit logs. Each household's data is segregated from every other household's.
No online service can eliminate security risk entirely. Our security program is designed to reduce that risk and, if something does go wrong, to detect it, contain it, and notify you as the law requires. Our incident-response plan is maintained and reviewed with counsel.
Children
Legacy Pulse accounts are for adults. Children under 13 cannot create or sign in to accounts. A parent or guardian who administers a household can create and manage profiles for their children; how that works — and the limits on what we do with child data — is described in the Children & Family Profile Notice.
Changes to this policy
If we change this policy, we will post the new version here with a new effective date. For material changes — anything that expands what we collect or how it is used — we will notify you in the app before the change applies to you, and where the change concerns health data we will ask for renewed consent rather than assuming it.
Contact us
Questions about this notice, or requests you would rather not make in the app, can be sent to privacy@lgc.my. You can also exercise most of your choices directly in Settings.
We respond to privacy requests within the timelines required by applicable law, and we will always tell you what we did in response.