TrueWear, LLC operates HeirVault. This policy explains what we process, what stays encrypted on your devices, how optional product analytics work, and how you can exercise your rights.
Who we are
TrueWear, LLC ("TrueWear," "we," "us") operates HeirVault at heirvault.io. For account and operational personal data described here, we are the controller. Vault contents you encrypt remain under your control; we act as a processor of opaque ciphertext solely to store and deliver it under your instructions.
Account and privacy requests: support@heirvault.io. Security vulnerability reports: security@heirvault.io.
End-to-end, zero-knowledge encryption design
Your vault encryption key is derived and kept on your devices. While unlocked, key material is held in browser memory and may be cleared when you lock the vault, sign out, or idle auto-lock runs. Optional device unlock may store an encrypted wrap in IndexedDB on that device, and may also store an encrypted wrap on our servers associated with a passkey or device credential (ciphertext we cannot use as a clear vault key). Documents, messages, folder names, and similar fields you encrypt are uploaded as ciphertext (AES-GCM).
We cannot decrypt your live vault contents. We do not receive your passphrase or raw vault key in a form that lets us unlock your live vault. If you lose your vault key and recovery material, we cannot recover your data. For Free system-assisted delivery, we may store a protected key for that beneficiary's separate handoff until claim transfer completes.
Sign-in and unlock
Account sign-in may use:
- A passphrase with the OPAQUE authentication protocol (the server stores an opaque registration record, not your cleartext passphrase)
- Passkeys for convenient account access
- Email one-time codes and, when enabled, Google sign-in for account access only
- Optional authenticator MFA (TOTP) with backup codes for account sign-in recovery
Email one-time codes and Google sign-in help you access the account. They do not by themselves decrypt vault contents. MFA protects account access; it is separate from vault encryption and from your emergency kit recovery phrase.
What we collect
Account and authentication
Email address, optional display name, optional profile image URL or custom avatar file stored in our file storage, locale preference, idle timeout preference, plan (free, pro, or shield), onboarding status, authentication identifiers, passkey credential metadata, session records, OPAQUE registration material (not your cleartext passphrase), optional Google account identifiers if you choose Google sign-in, MFA enrollment state and related authenticator metadata managed by our auth stack (not your vault passphrase), and trusted-browser records when you choose to remember a browser for MFA (user-agent and hashed IP, with coarse geo when available).
Vault and delivery metadata (readable by us)
Vault display name; check-in interval, due dates, and status; waiting period (grace) and delivery workflow state; any Away until schedule you set; check-in reminder preferences (for example whether pre-due countdown reminders are enabled on eligible plans); plan usage counters; timestamps; audit or rate-limit security metadata needed to protect the service; and similar operational fields needed to run reminders and delivery.
Vault ciphertext (not readable by us)
Encrypted blobs for vault items (docs written in the built-in editor, password entries, spreadsheet workbooks, and related fields); encrypted titles or names you encrypt client-side; wrapped vault keys and recovery wraps; and optional encrypted device key wraps associated with passkey or device unlock helpers. We store these as opaque ciphertext.
Beneficiaries, witnesses, and portals
Names, emails, relationship or role fields you enter; access levels and notification preferences; beneficiary-specific handoff key wraps and re-encrypted handoff bundles (ciphertext); and hashes of claim, check-in, and witness portal tokens (not the raw secret links at rest).
Billing
Subscription plan, status, Stripe customer and subscription identifiers, customer balance / credit adjustments (including referral credits), and related payment metadata from Stripe. We do not store full card numbers on our servers. Card data is handled by Stripe Checkout.
Referrals
If you use the referral program, we process your referral code, whether another user signed up through your link, referral event status (for example pending, credited, or blocked), invite emails you send (friend email address and message metadata), attribution from the `heirvault_ref` cookie or equivalent referral parameter, and limited payment-method fingerprints used only to block abusive self-referral or reuse. Credits are applied through Stripe as described in the Terms.
Shield check-in API keys
On Shield, if you create device check-in API keys, we store key hashes, display prefixes, labels, and last-used timestamps. We do not store the full raw key after creation. API check-ins reset your check-in timer; they do not unlock vault contents.
Email and communications
Transactional email content we send or queue (for example verification codes, security notices, billing receipts, check-in reminders, and referral invites), including recipient address, subject, and HTML body. When the product enables it, we may also send claim or witness notices. Support messages you send us.
Security and sessions
Hashed IP addresses for abuse prevention; user-agent strings; and coarse location enrichment (country, city, ASN) for login sessions via MaxMind when configured (shown in Pro and Shield session history where available). Bot-protection signals from Cloudflare Turnstile on sign-up when enabled.
Important: when MaxMind or Turnstile lookups run, those providers may receive your raw IP address at request time. HeirVault stores a hashed IP plus coarse geo fields, not the raw IP, in login session records.
Product analytics (optional)
If you accept analytics cookies, PostHog may receive pseudonymous product events and survey or announcement interactions. See Product analytics and messaging.
What we do not collect as plaintext
We do not collect plaintext vault documents, messages, folder titles you encrypt, owner vault passphrases, or recovery phrases, because those never reach our servers in readable form (or, for recovery material, remain your responsibility on your devices). When a beneficiary uses HeirVault-assisted handoff (system-assisted delivery), we may store a protected handoff key (or, for legacy rows, a sealed beneficiary passphrase) solely to transfer access after a valid claim; we delete that protected material after transfer or delivery. Invite now (direct account) and Shared beneficiary passphrase (owner-shared) delivery do not store a server-usable handoff key.
Vault display names, beneficiary and witness names and emails, and similar operational fields are not zero-knowledge. Operators and processors can read them as needed to run the service.
How we use data
We use personal data to:
- Create and secure accounts, sessions, passkeys, MFA, trusted browsers, and OPAQUE authentication
- Store and serve encrypted blobs and optional encrypted device key wraps
- Run check-in reminders, waiting period logic, witness steps, and beneficiary delivery according to your configuration
- Operate Shield check-in API keys when you create them
- Process subscriptions, referral attribution, and account credits, and prevent fraud or referral abuse
- Protect the service (rate limits, Turnstile, session review, audit logs)
- Provide support and required legal compliance
- Improve HeirVault, including via optional analytics and surveys when you consent
We do not sell personal data. We do not use personal data for third-party advertising networks.
Email types
Transactional messages
We send messages needed to operate your account and the workflows you configure. Examples include email verification and one-time codes, security alerts, billing and receipt notices, check-in reminders (including overdue waiting-period notices and, on Shield when enabled, pre-due countdown reminders), referral invite emails you request, and (when the product enables them) claim or witness notices. You generally cannot unsubscribe from transactional messages while your account or an active delivery workflow requires them.
Optional product emails
When you create a HeirVault account, we enroll you in our optional product emails. These share a single opt-in and include:
- Product newsletter: occasional emails about product updates, tips, and related HeirVault news
- Activation tips: early setup guidance (for example finishing onboarding, adding a first letter, adding contacts, or completing a first check-in) sent while you are getting started
- Upgrade suggestions: occasional prompts about Pro or Shield when your usage suggests they would help
These are frequency limited and de-duplicated so we do not repeat the same message. We do not sell your email or use it for third-party advertising networks.
You can opt out anytime in Account settings (Email preferences), by using the one-click unsubscribe link included in these emails, or by contacting support@heirvault.io. Opting out stops all of these optional emails but does not stop transactional messages.
Product analytics and messaging
When you choose Accept analytics on our cookie banner, we load PostHog (PostHog Inc., United States cloud) in your browser. PostHog helps us understand product and marketing usage, show optional surveys or in-product announcements, and (when enabled) provide an in-app Support chat for signed-in account holders.
After consent, we may associate events with an opaque internal user id (not your email) and limited non-sensitive account attributes such as plan tier, locale, and onboarding status. Session recording is disabled. You can withdraw consent anytime via Cookie settings in the footer.
If you use in-app Support, PostHog may process the messages you send and any contact email you provide so we can reply. That is support processing, separate from marketing analytics.
Analytics and Support traffic may be routed through a first-party subdomain (for example `e.heirvault.com`) operated as PostHog's managed reverse proxy. That path may involve Cloudflare as a PostHog subprocessor for proxying only.
We do not send to PostHog: vault encryption keys, passphrases, recovery phrases, decrypted titles or bodies, plaintext folder names you encrypt, beneficiary portal tokens, claim or witness secret links, or other confidential vault content.
Analytics identifiers may be deleted when you delete your account or on request, subject to vendor tooling and reasonable technical limits.
Beneficiaries, witnesses, and portals
When you invite beneficiaries or witnesses, we process the contact details and token material needed to operate claim, witness, or check-in portals, and to email them when the product sends those notices. Portal visitors may use the service without a full HeirVault owner account.
If you are a beneficiary or witness, the vault owner provided your name and email (and related fields) so HeirVault can contact you or operate a portal under their instructions. We process that information to deliver those features. You may contact support@heirvault.io about your personal data; some requests may require coordination with the owner or be limited by encryption and the owner's configuration.
You (as owner) are responsible for having a lawful basis to share their information and for keeping portal links confidential. Anyone with a valid link may perform the actions that link allows until it expires or is revoked under product rules.
Referral program
When you share a referral link or send an invite, we process the referral data listed under What we collect so we can attribute signups, apply credits after a qualifying paid invoice, prevent abuse, and send invite email you request. Friends who open your link may receive a short-lived attribution cookie (`heirvault_ref`) as described in the Cookie Policy. Referral and credit rules are in the Terms of Service.
Legal basis (EEA/UK and similar)
Where required, we rely on:
- Contract to provide HeirVault and deliver features you configure
- Legitimate interests for security, abuse prevention, service reliability, limited product improvement that does not override your rights, and (where allowed) the product newsletter when you create an account, with an easy way to opt out
- Consent for optional analytics cookies and PostHog surveys or announcements, and for optional marketing where consent is required
- Legal obligation when we must retain or disclose information
You may withdraw consent for analytics or opt out of the product newsletter without affecting essential account processing.
Processors and subprocessors
We use providers that process data only as needed for their function:
| Provider | Role |
|---|---|
| Convex | Application backend, database, file storage (encrypted blobs and metadata) |
| Better Auth (on Convex) | Authentication, sessions, passkeys, MFA, OPAQUE plugin |
| Optional OAuth sign-in; Google Cloud Platform hosts the web application (for example Cloud Run) | |
| Stripe | Payments, Checkout, billing portal, and customer balance credits (including referral credits) |
| Cloudflare Turnstile | Bot protection on sign-up (may see IP at verify time) |
| Resend | Transactional email |
| MaxMind | Coarse geo enrichment for login sessions when enabled (may see IP at lookup time) |
| PostHog | Optional product analytics, surveys, announcements, and Support inbox/widget after consent; managed reverse proxy may use Cloudflare as PostHog's subprocessor |
Vault ciphertext remains opaque to us and to analytics vendors. Each provider's own terms and privacy notices also apply to their processing.
Retention
We retain account and vault-related data while your account is active. After you delete your account, we schedule removal of vault metadata, encrypted blobs, messages, referral records tied to your account, API key metadata, trusted-browser records, and related records, subject to short backup windows, security log retention needed for abuse investigation, and data our processors need a brief period to purge.
Billing records may be kept longer as required for tax and accounting. Stripe and other processors may retain records under their own obligations.
Queued email content is retained only as long as needed to send messages and operate the queue, then removed with related account data on deletion subject to the same windows.
Security
We use measures appropriate to a hosted application that stores encrypted blobs and account metadata, including access controls, transport encryption (TLS), hashed portal tokens and hashed IPs where applicable, client-side vault encryption, and operational monitoring. No method of transmission or storage is perfectly secure. Client-side zero-knowledge design means your passphrase and vault key practices are a critical part of overall security.
We do not claim specific third-party compliance certifications in this policy unless we publish them separately.
If we become aware of a security incident that compromises personal data we control, we will investigate and notify affected users and regulators as required by applicable law. Report suspected account compromise or vulnerabilities to support@heirvault.io or security@heirvault.io as appropriate.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing or withdraw consent.
- Access / portability: Use Export my data in Settings for account and operational metadata. Encrypted vault fields remain encrypted in the export; decrypt them locally with your vault key. Binary attachments may be represented as metadata rather than full file bytes in the export package.
- Erasure: Use Delete account in Settings or email support@heirvault.io.
- Correction: Update profile and vault settings in the product, or contact support for help.
- Sessions: Review and revoke login sessions in Security settings where your plan includes that feature.
- Analytics consent: Use Cookie settings or clear site data, then choose Essential only.
- Optional email / newsletter: Turn off product updates in Account settings, use unsubscribe links where provided, or contact support. Transactional messages may continue.
- Complaints: Contact us first; you may also contact your supervisory authority.
Beneficiaries and witnesses may contact us about their own personal data as described above. We may need to verify your request and may decline requests that are unlawful, highly repetitive, or that would break encryption guarantees (for example, we cannot produce plaintext we never received).
International transfers
Data may be processed in the United States and other countries where we or our processors operate, including PostHog's US cloud and Google Cloud regions we use. Where required, we rely on appropriate safeguards (such as standard contractual clauses or equivalent frameworks).
Children
HeirVault is not directed at children under 16. We do not knowingly create accounts for children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps.
California and similar U.S. state notices
We do not sell personal information as "sell" is commonly defined under California law, and we do not share it for cross-context behavioral advertising. U.S. state privacy rights (access, deletion, correction, appeal) can be exercised through the channels above. We will not discriminate against you for exercising privacy rights.
Categories of personal information we process typically include identifiers (email, account ids, referral codes), commercial information (plan and billing status, credits), internet or network activity (sessions, hashed IP, coarse geo, user-agent, API key last-used metadata), and inferences limited to product usage when you consent to analytics. Sensitive vault contents are encrypted client-side and are not readable by us.
Automated decisions
HeirVault uses automated workflows for check-in reminders, waiting period timing, and delivery triggers based on rules you configure. These are not credit, hiring, or similar legally significant profiling decisions about you by us; they execute your instructions. We do not investigate the real-world reason a check-in was missed.
Changes
We post updates here with a revised "Last updated" date. Material changes to analytics or processors will also be reflected in our Cookie Policy. Where required, we will provide additional notice.
Contact
TrueWear, LLC Account and privacy: support@heirvault.io Security reports: security@heirvault.io
Questions?
Reach us at support@heirvault.io. You can also review our Terms of Service and Cookie Policy.