Privacy

Privacy Policy

HeirVault is a timed digital legacy vault. Your live vault is protected by end-to-end, zero-knowledge encryption on your device. We host ciphertext and account metadata. Delivery mode decides whether a separate beneficiary handoff key is HeirVault-assisted or held only by you and the beneficiary.

In short

  • Vault keys and plaintext contents stay on your devices. We store ciphertext we cannot read for your live vault.
  • We process account, delivery, billing, security, and referral metadata needed to run the service.
  • Free, Pro, and Shield plans share the same live-vault encryption model; plan changes capacity and extras.
  • New accounts are enrolled in optional product update emails; you can opt out in Settings.
  • Optional PostHog analytics load only after you consent. Never vault contents or keys.
  • Export and account deletion are available in Settings.

TrueWear, LLC operates HeirVault. This policy explains what we process, what stays encrypted on your devices, how optional product analytics work, and how you can exercise your rights.

Who we are

TrueWear, LLC ("TrueWear," "we," "us") operates HeirVault at heirvault.io. For account and operational personal data described here, we are the controller. Vault contents you encrypt remain under your control; we act as a processor of opaque ciphertext solely to store and deliver it under your instructions.

Account and privacy requests: support@heirvault.io. Security vulnerability reports: security@heirvault.io.

End-to-end, zero-knowledge encryption design

Your vault encryption key is derived and kept on your devices. While unlocked, key material is held in browser memory and may be cleared when you lock the vault, sign out, or idle auto-lock runs. Optional device unlock may store an encrypted wrap in IndexedDB on that device, and may also store an encrypted wrap on our servers associated with a passkey or device credential (ciphertext we cannot use as a clear vault key). Documents, messages, folder names, and similar fields you encrypt are uploaded as ciphertext (AES-GCM).

We cannot decrypt your live vault contents. We do not receive your passphrase or raw vault key in a form that lets us unlock your live vault. If you lose your vault key and recovery material, we cannot recover your data. For Free system-assisted delivery, we may store a protected key for that beneficiary's separate handoff until claim transfer completes.

Sign-in and unlock

Account sign-in may use:

  • A passphrase with the OPAQUE authentication protocol (the server stores an opaque registration record, not your cleartext passphrase)
  • Passkeys for convenient account access
  • Email one-time codes and, when enabled, Google sign-in for account access only
  • Optional authenticator MFA (TOTP) with backup codes for account sign-in recovery

Email one-time codes and Google sign-in help you access the account. They do not by themselves decrypt vault contents. MFA protects account access; it is separate from vault encryption and from your emergency kit recovery phrase.

What we collect

Account and authentication

Email address, optional display name, optional profile image URL or custom avatar file stored in our file storage, locale preference, idle timeout preference, plan (free, pro, or shield), onboarding status, authentication identifiers, passkey credential metadata, session records, OPAQUE registration material (not your cleartext passphrase), optional Google account identifiers if you choose Google sign-in, MFA enrollment state and related authenticator metadata managed by our auth stack (not your vault passphrase), and trusted-browser records when you choose to remember a browser for MFA (user-agent and hashed IP, with coarse geo when available).

Vault and delivery metadata (readable by us)

Vault display name; check-in interval, due dates, and status; waiting period (grace) and delivery workflow state; any Away until schedule you set; check-in reminder preferences (for example whether pre-due countdown reminders are enabled on eligible plans); plan usage counters; timestamps; audit or rate-limit security metadata needed to protect the service; and similar operational fields needed to run reminders and delivery.

Vault ciphertext (not readable by us)

Encrypted blobs for vault items (docs written in the built-in editor, password entries, spreadsheet workbooks, and related fields); encrypted titles or names you encrypt client-side; wrapped vault keys and recovery wraps; and optional encrypted device key wraps associated with passkey or device unlock helpers. We store these as opaque ciphertext.

Beneficiaries, witnesses, and portals

Names, emails, relationship or role fields you enter; access levels and notification preferences; beneficiary-specific handoff key wraps and re-encrypted handoff bundles (ciphertext); and hashes of claim, check-in, and witness portal tokens (not the raw secret links at rest).

Billing

Subscription plan, status, Stripe customer and subscription identifiers, customer balance / credit adjustments (including referral credits), and related payment metadata from Stripe. We do not store full card numbers on our servers. Card data is handled by Stripe Checkout.

Referrals

If you use the referral program, we process your referral code, whether another user signed up through your link, referral event status (for example pending, credited, or blocked), invite emails you send (friend email address and message metadata), attribution from the `heirvault_ref` cookie or equivalent referral parameter, and limited payment-method fingerprints used only to block abusive self-referral or reuse. Credits are applied through Stripe as described in the Terms.

Shield check-in API keys

On Shield, if you create device check-in API keys, we store key hashes, display prefixes, labels, and last-used timestamps. We do not store the full raw key after creation. API check-ins reset your check-in timer; they do not unlock vault contents.

Email and communications

Transactional email content we send or queue (for example verification codes, security notices, billing receipts, check-in reminders, and referral invites), including recipient address, subject, and HTML body. When the product enables it, we may also send claim or witness notices. Support messages you send us.

Security and sessions

Hashed IP addresses for abuse prevention; user-agent strings; and coarse location enrichment (country, city, ASN) for login sessions via MaxMind when configured (shown in Pro and Shield session history where available). Bot-protection signals from Cloudflare Turnstile on sign-up when enabled.

Important: when MaxMind or Turnstile lookups run, those providers may receive your raw IP address at request time. HeirVault stores a hashed IP plus coarse geo fields, not the raw IP, in login session records.

Product analytics (optional)

If you accept analytics cookies, PostHog may receive pseudonymous product events and survey or announcement interactions. See Product analytics and messaging.

What we do not collect as plaintext

We do not collect plaintext vault documents, messages, folder titles you encrypt, owner vault passphrases, or recovery phrases, because those never reach our servers in readable form (or, for recovery material, remain your responsibility on your devices). When a beneficiary uses HeirVault-assisted handoff (system-assisted delivery), we may store a protected handoff key (or, for legacy rows, a sealed beneficiary passphrase) solely to transfer access after a valid claim; we delete that protected material after transfer or delivery. Invite now (direct account) and Shared beneficiary passphrase (owner-shared) delivery do not store a server-usable handoff key.

Vault display names, beneficiary and witness names and emails, and similar operational fields are not zero-knowledge. Operators and processors can read them as needed to run the service.

How we use data

We use personal data to:

  • Create and secure accounts, sessions, passkeys, MFA, trusted browsers, and OPAQUE authentication
  • Store and serve encrypted blobs and optional encrypted device key wraps
  • Run check-in reminders, waiting period logic, witness steps, and beneficiary delivery according to your configuration
  • Operate Shield check-in API keys when you create them
  • Process subscriptions, referral attribution, and account credits, and prevent fraud or referral abuse
  • Protect the service (rate limits, Turnstile, session review, audit logs)
  • Provide support and required legal compliance
  • Improve HeirVault, including via optional analytics and surveys when you consent

We do not sell personal data. We do not use personal data for third-party advertising networks.

Email types

Transactional messages

We send messages needed to operate your account and the workflows you configure. Examples include email verification and one-time codes, security alerts, billing and receipt notices, check-in reminders (including overdue waiting-period notices and, on Shield when enabled, pre-due countdown reminders), referral invite emails you request, and (when the product enables them) claim or witness notices. You generally cannot unsubscribe from transactional messages while your account or an active delivery workflow requires them.

Optional product emails

When you create a HeirVault account, we enroll you in our optional product emails. These share a single opt-in and include:

  • Product newsletter: occasional emails about product updates, tips, and related HeirVault news
  • Activation tips: early setup guidance (for example finishing onboarding, adding a first letter, adding contacts, or completing a first check-in) sent while you are getting started
  • Upgrade suggestions: occasional prompts about Pro or Shield when your usage suggests they would help

These are frequency limited and de-duplicated so we do not repeat the same message. We do not sell your email or use it for third-party advertising networks.

You can opt out anytime in Account settings (Email preferences), by using the one-click unsubscribe link included in these emails, or by contacting support@heirvault.io. Opting out stops all of these optional emails but does not stop transactional messages.

Product analytics and messaging

When you choose Accept analytics on our cookie banner, we load PostHog (PostHog Inc., United States cloud) in your browser. PostHog helps us understand product and marketing usage, show optional surveys or in-product announcements, and (when enabled) provide an in-app Support chat for signed-in account holders.

After consent, we may associate events with an opaque internal user id (not your email) and limited non-sensitive account attributes such as plan tier, locale, and onboarding status. Session recording is disabled. You can withdraw consent anytime via Cookie settings in the footer.

If you use in-app Support, PostHog may process the messages you send and any contact email you provide so we can reply. That is support processing, separate from marketing analytics.

Analytics and Support traffic may be routed through a first-party subdomain (for example `e.heirvault.com`) operated as PostHog's managed reverse proxy. That path may involve Cloudflare as a PostHog subprocessor for proxying only.

We do not send to PostHog: vault encryption keys, passphrases, recovery phrases, decrypted titles or bodies, plaintext folder names you encrypt, beneficiary portal tokens, claim or witness secret links, or other confidential vault content.

Analytics identifiers may be deleted when you delete your account or on request, subject to vendor tooling and reasonable technical limits.

Beneficiaries, witnesses, and portals

When you invite beneficiaries or witnesses, we process the contact details and token material needed to operate claim, witness, or check-in portals, and to email them when the product sends those notices. Portal visitors may use the service without a full HeirVault owner account.

If you are a beneficiary or witness, the vault owner provided your name and email (and related fields) so HeirVault can contact you or operate a portal under their instructions. We process that information to deliver those features. You may contact support@heirvault.io about your personal data; some requests may require coordination with the owner or be limited by encryption and the owner's configuration.

You (as owner) are responsible for having a lawful basis to share their information and for keeping portal links confidential. Anyone with a valid link may perform the actions that link allows until it expires or is revoked under product rules.

Referral program

When you share a referral link or send an invite, we process the referral data listed under What we collect so we can attribute signups, apply credits after a qualifying paid invoice, prevent abuse, and send invite email you request. Friends who open your link may receive a short-lived attribution cookie (`heirvault_ref`) as described in the Cookie Policy. Referral and credit rules are in the Terms of Service.

Processors and subprocessors

We use providers that process data only as needed for their function:

ProviderRole
ConvexApplication backend, database, file storage (encrypted blobs and metadata)
Better Auth (on Convex)Authentication, sessions, passkeys, MFA, OPAQUE plugin
GoogleOptional OAuth sign-in; Google Cloud Platform hosts the web application (for example Cloud Run)
StripePayments, Checkout, billing portal, and customer balance credits (including referral credits)
Cloudflare TurnstileBot protection on sign-up (may see IP at verify time)
ResendTransactional email
MaxMindCoarse geo enrichment for login sessions when enabled (may see IP at lookup time)
PostHogOptional product analytics, surveys, announcements, and Support inbox/widget after consent; managed reverse proxy may use Cloudflare as PostHog's subprocessor

Vault ciphertext remains opaque to us and to analytics vendors. Each provider's own terms and privacy notices also apply to their processing.

Sharing and disclosure

We share data with processors above, with beneficiaries or witnesses as you instruct, and when required by law, legal process, or to protect rights, safety, and security. We may share aggregated or de-identified information that does not reasonably identify you.

Law enforcement and legal process

If we receive a subpoena, court order, or similar legal demand, we may disclose account and operational personal data and, where demanded, encrypted vault blobs we cannot decrypt. We do not have keys that would let us produce plaintext vault contents. Where we are legally permitted to do so, and where it would not create a risk of harm or obstruct an investigation, we will try to notify the affected account holder before or after disclosure.

Business transfers

If we are involved in a merger, acquisition, reorganization, or asset sale, personal data may transfer to a successor subject to continuing privacy protections. Where required or reasonably practicable, we will provide notice (for example by email or a prominent site notice) and remind you of export and deletion options in Settings.

Retention

We retain account and vault-related data while your account is active. After you delete your account, we schedule removal of vault metadata, encrypted blobs, messages, referral records tied to your account, API key metadata, trusted-browser records, and related records, subject to short backup windows, security log retention needed for abuse investigation, and data our processors need a brief period to purge.

Billing records may be kept longer as required for tax and accounting. Stripe and other processors may retain records under their own obligations.

Queued email content is retained only as long as needed to send messages and operate the queue, then removed with related account data on deletion subject to the same windows.

Security

We use measures appropriate to a hosted application that stores encrypted blobs and account metadata, including access controls, transport encryption (TLS), hashed portal tokens and hashed IPs where applicable, client-side vault encryption, and operational monitoring. No method of transmission or storage is perfectly secure. Client-side zero-knowledge design means your passphrase and vault key practices are a critical part of overall security.

We do not claim specific third-party compliance certifications in this policy unless we publish them separately.

If we become aware of a security incident that compromises personal data we control, we will investigate and notify affected users and regulators as required by applicable law. Report suspected account compromise or vulnerabilities to support@heirvault.io or security@heirvault.io as appropriate.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing or withdraw consent.

  • Access / portability: Use Export my data in Settings for account and operational metadata. Encrypted vault fields remain encrypted in the export; decrypt them locally with your vault key. Binary attachments may be represented as metadata rather than full file bytes in the export package.
  • Erasure: Use Delete account in Settings or email support@heirvault.io.
  • Correction: Update profile and vault settings in the product, or contact support for help.
  • Sessions: Review and revoke login sessions in Security settings where your plan includes that feature.
  • Analytics consent: Use Cookie settings or clear site data, then choose Essential only.
  • Optional email / newsletter: Turn off product updates in Account settings, use unsubscribe links where provided, or contact support. Transactional messages may continue.
  • Complaints: Contact us first; you may also contact your supervisory authority.

Beneficiaries and witnesses may contact us about their own personal data as described above. We may need to verify your request and may decline requests that are unlawful, highly repetitive, or that would break encryption guarantees (for example, we cannot produce plaintext we never received).

International transfers

Data may be processed in the United States and other countries where we or our processors operate, including PostHog's US cloud and Google Cloud regions we use. Where required, we rely on appropriate safeguards (such as standard contractual clauses or equivalent frameworks).

Children

HeirVault is not directed at children under 16. We do not knowingly create accounts for children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps.

California and similar U.S. state notices

We do not sell personal information as "sell" is commonly defined under California law, and we do not share it for cross-context behavioral advertising. U.S. state privacy rights (access, deletion, correction, appeal) can be exercised through the channels above. We will not discriminate against you for exercising privacy rights.

Categories of personal information we process typically include identifiers (email, account ids, referral codes), commercial information (plan and billing status, credits), internet or network activity (sessions, hashed IP, coarse geo, user-agent, API key last-used metadata), and inferences limited to product usage when you consent to analytics. Sensitive vault contents are encrypted client-side and are not readable by us.

Automated decisions

HeirVault uses automated workflows for check-in reminders, waiting period timing, and delivery triggers based on rules you configure. These are not credit, hiring, or similar legally significant profiling decisions about you by us; they execute your instructions. We do not investigate the real-world reason a check-in was missed.

Changes

We post updates here with a revised "Last updated" date. Material changes to analytics or processors will also be reflected in our Cookie Policy. Where required, we will provide additional notice.

Contact

TrueWear, LLC Account and privacy: support@heirvault.io Security reports: security@heirvault.io

Questions?

Reach us at support@heirvault.io. You can also review our Terms of Service and Cookie Policy.