How your information is handled
The short version of what protects your sign-in and an estate’s records, each fact drawn from our privacy policy or from the code that runs the product.
Signing in
There is no password to steal or reuse from another site. You sign in with a one-time link and a six-digit code sent to your email, and either one gets you in. Both expire after 15 minutes and work only once.
No trackers, no ad pixels
No advertising trackers, no analytics cookies, no pixels, from anyone. The only counts we keep are page views and page-load speed, measured cookieless and first-party from our own domain, and a server-side tally of which page a visit landed on. None of it can identify you or follow you across sites.
Payments
Payments are handled by Stripe. Your card number goes to Stripe, never to our servers. We keep only what was charged and when.
Where things run
Records are stored with our database provider, Neon, on AWS in the United States, and served through Vercel. Sign-in and notification emails are delivered by Resend. Payments run on Stripe. Each processes data only to provide their service to us.
What we keep, and for how long
Sign-in records, the IP address and browser of each session, are deleted daily once that session has expired. Separately, an estate keeps a record of who opened it, which document, and when, so anyone who shouldn’t be in an estate’s records can be noticed; the IP address and browser behind each entry are erased after 90 days, while who opened what and when stays with the estate until it is deleted.
Your controls
Your complete records export free as CSV or JSON at any time, no lock-in. Every estate has a delete option, and deletion is real and immediate: records and uploaded files are destroyed, not archived.
This page is a summary. The full privacy policy is the complete, governing statement of what we collect and what we do with it.