Cookies

Cookie Policy

How HeirVault uses cookies and browser storage to run the product and, with your consent, optional analytics.

In short

  • Essential cookies power sign-in, sessions, and security checks.
  • Vault unlock material stays in browser memory on your device (and optional IndexedDB device unlock when you enable it). It is cleared when you lock or sign out.
  • A short-lived referral cookie may remember which invite link you opened before sign-up.
  • Optional analytics and in-app messages use PostHog only after Accept analytics.
  • Change your mind anytime via Cookie settings in the footer.

HeirVault uses a small set of cookies and browser storage so the product works. Essential cookies keep you signed in. Optional analytics via PostHog load only if you consent. We do not use advertising trackers.

Overview

This Cookie Policy explains how TrueWear, LLC uses cookies, local storage, IndexedDB, and similar technologies on heirvault.io and the HeirVault web app. It should be read with our Privacy Policy and Terms of Service.

We use these technologies to keep you signed in, remember preferences, hold vault unlock state on your device during a session, protect sign-up from bots, and, only with your consent, run product analytics and in-product surveys or announcements. It should be read alongside our Privacy Policy, which covers the email preferences and optional product emails that are separate from cookies.

Categories

Essential

Required for the service to function. They are not used for advertising.

Examples:

  • Authentication and session cookies managed with Better Auth and Convex so you stay signed in, rotate sessions securely, and use passkeys
  • Cloudflare Turnstile cookies or storage during bot checks on sign-up when Turnstile is enabled
  • Security and load-balancing cookies that our hosting edge may set for the web application

If you block essential cookies, sign-in and authenticated features may not work.

Functional

Remember choices that make the product nicer to use but are not strictly required for basic security:

  • Theme (light or dark)
  • Locale / language preference (NEXT_LOCALE cookie)
  • Cookie consent choice stored in local storage (heirvault-cookie-consent) after you respond to the banner
  • Referral attribution cookie `heirvault_ref` when you open a personal invite link such as `/r/[code]` (about 30 days). It helps attach a referral at sign-up. It is not used for advertising networks.

Vault device storage (device-only)

When you unlock your vault, encryption key material is held in browser memory (application state) so you are not prompted on every navigation. Signing out or idle auto-lock clears this material and ends the account session.

If you enable device unlock helpers, an encrypted key wrap may be stored in IndexedDB on that device so a passkey or device factor can unwrap it later. The product may also store an encrypted wrap on our servers associated with that credential. Those wraps are not your raw vault key in cleartext, and they are never sent to PostHog or other analytics tools.

TrueWear servers never receive your raw vault key in a form that lets us unlock your vault.

Analytics and messaging (optional)

If you choose Accept analytics, we load PostHog (PostHog Inc., United States cloud). PostHog may set cookies or use local storage to:

  • Measure product and marketing usage with minimized, pseudonymous events (including an opaque user id after you sign in)
  • Deliver surveys and in-product announcements for feedback and support-style prompts
  • Power an optional in-app Support chat for signed-in users (message content and reply email when you provide them)

Browser requests to PostHog may go through our first-party path (for example `/relay-hv` locally or a subdomain such as `e.heirvault.com` in production) so analytics is less likely to be blocked.

Session recording is disabled. If you choose Essential only, PostHog does not load and analytics cookies from PostHog are not set.

We do not use third-party advertising networks or sell cookie data.

We never send vault contents, encryption keys, passphrases, recovery phrases, decrypted titles or bodies, or portal secret tokens through analytics cookies or PostHog events.

Third-party sign-in (when you choose it)

If you use Google sign-in, Google may set its own cookies or local storage according to Google's terms and privacy policy. Those technologies are controlled by Google. You can avoid them by using email, passphrase, or passkey sign-in instead.

Your choices

  • Accept analytics: enables PostHog as described above.
  • Essential only: authenticated use and functional preferences without product analytics.
  • Change your mind: open Cookie settings in the site footer to reset your choice and see the banner again, or clear site data in your browser settings.
  • Browser controls: most browsers let you block or delete cookies. Blocking essential cookies will break sign-in.

Essential cookies are required for authenticated use. Questions: support@heirvault.io.

Do Not Track

Some browsers send a "Do Not Track" signal. There is no common industry standard for responding to it. Our analytics load based on your explicit cookie choice, not on DNT alone.

Updates

We will revise this page when our practices or vendors change. The "Last updated" date at the top will change when we do.

Questions?

Reach us at support@heirvault.io. You can also review our Terms of Service and Privacy Policy.