Skip to main content

Privacy Policy

Effective: August 12, 2026

Privacy at a Glance

  • Your notes, passwords, structured vault entries, and the files you upload are end-to-end encrypted on your device, so we can't read them. The documents we generate for you (such as legal-template PDFs) use server-side AES-256, which we manage to operate the Service.
  • We don't sell or rent your personal data. The only advertising-related sharing is a limited amount of usage data sent to Meta to measure our ads, which you can opt out of at any time.
  • LifeVault Secure uses a zero-knowledge architecture for your notes, passwords, structured vault entries, and the files you upload — these are end-to-end encrypted and our staff cannot read them. The documents we generate for you (such as legal-template PDFs) use server-side AES-256; staff access to those generated documents is restricted, logged, and limited to operating the Service.
  • You control your data. Export, correct, or delete it at any time from your account settings.
  • You have privacy rights under GDPR, CCPA/CPRA, and other applicable laws.

1. Introduction and Scope

This Privacy Policy describes how LifeVault Secure ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our web application and related API services (collectively, the "Service").

This policy applies to all users of the Service regardless of location. Where specific laws grant you additional rights, those rights are described in Section 10.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

2. Who We Are

LifeVault Secure is a security-first digital vault platform for storing, managing, and conditionally releasing sensitive digital assets. We act as the data controller for the personal information we process.

  • Legal Entity: Edukas Solutions LLC
  • Address: 8605 Santa Monica Blvd PMB 875080, West Hollywood, California 90069-4109 US
  • Privacy Inquiries: privacy@lifevaultsecure.com
  • Privacy Contact: privacy@lifevaultsecure.com

3. Our Encryption Commitment

LifeVault Secure is built on a zero-knowledge architecture for your vault content. We do not have the technical ability to access, read, or decrypt your notes, password entries, structured vault entries, or the files you upload — these are end-to-end encrypted on your device. A limited set of data is necessarily server-readable: the documents we generate for you (such as legal-template PDFs), which we render and encrypt on our servers, and operational metadata such as file names, sizes, and timestamps. This is a design choice, not just a policy decision.

We use envelope encryption to protect your data. Each vault has its own Data Encryption Key (DEK) that is wrapped by a Key Encryption Key (KEK) stored in hardware security modules (Azure Key Vault). Password fields are encrypted with AES-256-GCM (authenticated encryption) using a unique initialization vector for each field.

Data We Cannot Access (End-to-End Encrypted)

  • Note contents (text, and the metadata of audio notes)
  • Password entries, including usernames, passwords, URLs, notes, and TOTP secrets
  • Other structured entries you store in your vaults (such as identity and card records)

Data We Encrypt and Can Access (to operate the Service)

Documents we generate for you — such as legal-template PDFs — are rendered on our servers and encrypted at rest with server-side AES-256 under keys we manage. Because we hold these keys, we can decrypt these generated documents to render and deliver them to you, and we may be required to produce them in response to valid legal process. Files you upload yourself are end-to-end encrypted and appear above under the data we cannot access.

Metadata We Can Access (Not Encrypted)

To operate the Service, we must process certain metadata that is not encrypted:

  • File names, sizes, and MIME types
  • Vault names, creation dates, and member lists
  • Timestamps of uploads, downloads, and access events
  • Your account profile information (email, display name)

Your notes, passwords, structured vault entries, and the files you upload are end-to-end encrypted on your device: only you hold the decryption keys, and no recovery is possible if you lose your vault password. The documents we generate for you (such as legal-template PDFs) are encrypted with server-side AES-256 under keys we manage, which we can access to render and deliver those documents and to operate the Service.

4. Information We Collect

4.1 Vault Data

This is the content you store in your vaults. Your notes, password entries, structured vault entries, and the files you upload are end-to-end encrypted before they reach us, and we cannot access them in a readable format. The documents we generate for you (such as legal-template PDFs) are encrypted with server-side AES-256 under keys we manage; we can access these generated documents to render, deliver, and operate the Service. The categories of vault content we collect are:

  • Files and documents you upload
  • Password entries (usernames, passwords, URLs, notes, TOTP secrets)
  • Any other content you choose to store in your vaults

4.2 Account and Profile Data

  • Email address and display name
  • Phone number (if you enable SMS verification via Twilio)
  • Authentication identifiers from your identity provider
  • Account preferences, theme settings, and notification preferences

4.3 Billing and Payment Data

Payment processing is handled by Stripe and PayPal. LifeVault Secure does not store your full credit card number, CVV, or bank account details.

  • Subscription tier, billing cycle, and plan history
  • Last four digits of your payment method (for display purposes only)
  • Transaction history and invoice records

4.4 Emergency Access and Life Event Data

If you configure emergency access or life event features, we collect:

  • Trusted contact names, email addresses, and phone numbers you provide
  • Life event type selections and trigger conditions you configure
  • Verification evidence submitted by trusted contacts during a life event claim
  • Policy execution logs and access grant records

4.5 Usage and Diagnostic Data

  • Storage usage, vault counts, and item counts
  • Feature usage patterns (which features are accessed, not their contents)
  • Error logs and diagnostic data for troubleshooting

4.6 Automatically Collected Data

  • IP address and approximate geographic location
  • Browser type, operating system, and device information
  • Referring URL and pages visited within the Service
  • Cookies and similar tracking technologies (see Section 9)

5. How We Use Your Information

We use your information only for the purposes described below. For each purpose, we identify the legal basis under the GDPR:

PurposeLegal Basis
Provide, maintain, and operate the Service (vault storage, encryption, file management)Performance of contract
Process payments and manage subscriptionsPerformance of contract
Send transactional notifications (account alerts, security warnings, policy triggers)Performance of contract
Enforce emergency access policies and verify life event declarationsLegitimate interest and your explicit consent
Prevent fraud, abuse, and unauthorized accessLegitimate interest
Comply with legal obligations (tax records, law enforcement requests)Legal obligation
Improve the Service based on aggregated usage patternsLegitimate interest
Measure the performance of our marketing campaigns and attribute sign-ups to the campaign that produced themLegitimate interest

6. How We Share Your Information

We do not sell or rent your personal data for monetary consideration. We share your personal information only in the following circumstances:

6.1 Service Providers

We use the following third-party service providers to operate the Service. Each provider receives only the minimum data necessary for its function:

ProviderPurposeData Shared
Microsoft AzureAuthentication, key management, encrypted storage, database hostingAuth tokens, key metadata, encrypted blobs, service data (encrypted at rest)
StripePayment processingName, email, payment method, billing address
PayPalAlternative payment processingName, email, payment details
SendGridTransactional email deliveryEmail address, email subject and content
FirebasePush notificationsDevice tokens, notification titles
TwilioSMS verificationPhone number, verification codes
Meta Platforms, Inc.Advertising performance measurement (Meta Pixel), only when you consent to advertising cookiesPseudonymized usage and event data (never your vault contents)
RewardfulAffiliate and referral attributionReferral identifier; sign-up and subscription events

6.2 Vault Members

When you invite someone to a shared vault, that member gains access to vault contents based on their assigned role (Owner, Admin, Contributor, Viewer, or Recipient). You control who has access and at what permission level. Removing a member immediately revokes their access.

6.3 Emergency Access Recipients

If you configure emergency access or life event policies, designated trusted contacts gain access to specified vault contents only after a verified life event (such as death or incapacity) and only after the waiting period you configured has elapsed. This access is initiated by you through your policy settings and is subject to verification safeguards.

6.4 Legal and Compliance

We disclose information when required by law, subpoena, court order, or government request. We will notify you before disclosing your information unless we are legally prohibited from doing so.

For your end-to-end-encrypted vault content — your notes, passwords, structured entries, and the files you upload — any such disclosure can include only the encrypted ciphertext, which we are unable to decrypt. The documents we generate for you (such as legal-template PDFs) and operational metadata are server-readable and may be produced in readable form.

6.5 Business Transfers

If LifeVault Secure is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you via email and an in-app notice before your information is transferred and becomes subject to a different privacy policy.

7. Data Retention

We retain your data only as long as necessary for the purposes described in this policy. Below are the specific retention periods for each data category:

Data CategoryRetention Period
Vault data (encrypted files, passwords)Until you delete the item or your account is terminated
Account and profile dataDuration of your account plus 30 days after deletion
Billing and payment records7 years after the transaction (tax and legal compliance)
Audit logs7 years (retained for security integrity)
Emergency access and life event dataUntil you revoke the policy or your account is terminated
Usage and diagnostic data2 years, then aggregated and anonymized
Automatically collected data (IP, browser)13 months

8. International Data Transfers

LifeVault Secure processes and stores data primarily in Microsoft Azure data centers located in the United States. If you access the Service from outside the United States, your information is transferred to and processed in the US.

For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office. We also evaluate the data protection laws of recipient countries and implement supplementary technical safeguards, including encryption, to protect your data during transfer.

9. Cookies and Tracking Technologies

We use a limited number of cookies and similar technologies to operate the Service:

  • Strictly Necessary: Authentication tokens, session identifiers, and security cookies required for the Service to function. These cannot be disabled.
  • Functional: Theme preferences, locale settings, and UI state cookies that remember your choices.
  • Analytics: Pseudonymized, aggregated usage data to understand how the Service is used and to identify areas for improvement. We use Google Analytics 4 for this purpose. Advertising and affiliate cookies are described separately under the "Advertising / Marketing" category below.
  • Advertising / Marketing: Cookies and similar technologies that measure the performance of our advertising. When you consent to advertising cookies, we use the Meta Pixel — provided by Meta Platforms, Inc. — to measure the results of ads we run on Facebook and Instagram, which involves sharing a limited amount of usage data with Meta. You can opt out of the Meta Pixel at any time using the "Do Not Sell or Share My Personal Information" link, or by enabling a Global Privacy Control (GPC) signal in your browser. We also use Rewardful, an affiliate cookie that credits partners who refer you to LifeVault.
  • Campaign Attribution: When you arrive from one of our ads, emails, or partner links, the campaign tags carried in that link (utm_source, utm_medium, utm_campaign, utm_content, utm_term) are stored in your browser's session storage, on your own device, so we can tell which campaign led to a sign-up. Each tag is capped at 255 characters and nothing else is stored. This storage is first-party: the tags it holds are sent only to LifeVault Secure, and only when you create an account. The entry is erased when you close the browser tab, and it is cleared as soon as your account is created. If you do not arrive from a tagged link, nothing is stored.

You can manage cookies through your browser settings. Disabling strictly necessary cookies may prevent the Service from functioning properly. The legacy Do Not Track (DNT) signal has been deprecated and is no longer a reliable standard; instead, we treat a Global Privacy Control (GPC) signal as a valid request to opt out of the sale or sharing of your personal information. You can also opt out using the "Do Not Sell or Share My Personal Information" link.

10. Your Privacy Rights

10.1 Rights for All Users

  • Access your personal data and receive a copy of it
  • Correct inaccurate or incomplete personal data
  • Delete your account and associated personal data
  • Export your data in a portable, machine-readable format

10.2 Additional Rights for EEA/UK Residents (GDPR)

If you are located in the European Economic Area or the United Kingdom, you have the following additional rights under the General Data Protection Regulation:

  • Request that we restrict the processing of your personal data in certain circumstances
  • Object to our processing of your personal data based on legitimate interests
  • Withdraw your consent at any time where processing is based on consent
  • Lodge a complaint with your local data protection supervisory authority

10.3 Additional Rights for California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act and its amendments grant you the following rights:

  • Know what personal information we collect, use, disclose, and sell
  • Request deletion of your personal information
  • Request correction of inaccurate personal information
  • Opt out of the sale or sharing of your personal information
  • Not be discriminated against for exercising your privacy rights

LifeVault Secure does not sell your personal information for monetary consideration. We do share a limited amount of usage data with our advertising partner, Meta Platforms, Inc., for advertising measurement; under California law, this may be treated as a "sale" or a "share" of personal information for cross-context behavioral advertising. You can opt out of this sharing at any time using the "Do Not Sell or Share My Personal Information" link, or by enabling a Global Privacy Control (GPC) signal in your browser. We honor these opt-out requests.

To opt out of the sharing of your personal information for advertising, use the "Do Not Sell or Share My Personal Information" link in the website footer, or enable a Global Privacy Control (GPC) signal in your browser. We treat a GPC signal as a valid opt-out request.

10.4 How to Exercise Your Rights

You can exercise most of these rights directly through your account settings, including downloading your data, correcting your profile, and deleting your account.

You can review and revoke third-party app access from Settings integrations.

For requests that cannot be handled through the self-service tools, email us at privacy@lifevaultsecure.com. We will respond within 30 days (GDPR) or 45 days (CCPA/CPRA). We may ask you to verify your identity before processing your request.

11. Deceased Users and Digital Estate Access

LifeVault Secure includes features specifically designed for digital estate planning. This section explains how we handle accounts and data of deceased users.

If you configure life event policies and trusted contacts, the following process applies upon a verified life event declaration:

  • A trusted contact submits a life event claim with supporting documentation (such as a death certificate)
  • The claim is verified according to the verification requirements you configured
  • After the waiting period you set has elapsed, the trusted contact gains access to the vault contents specified in your policy
  • All access events are recorded in the audit log

If no life event plan is configured, the account remains in its current state. We comply with the Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA) and applicable state laws governing fiduciary access to digital assets. Courts or estates with proper legal authority may request access through legal@lifevaultsecure.com, subject to the same encryption limitations described in Section 6.4.

12. Children's Privacy

LifeVault Secure is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@lifevaultsecure.com and we will promptly delete it. Account holders must additionally meet the minimum age set out in Section 2 of our Terms of Service.

For Family Legacy plan accounts, all members must be at least 16 years old. The account owner is responsible for ensuring that all invited family members meet this age requirement.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make changes, we will update the effective date at the top of this page.

For material changes that affect how we process your personal data, we will notify you at least 30 days in advance via email and an in-app notification. Your continued use of the Service after the updated policy takes effect constitutes your acknowledgment of the changes.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, you can reach us through the following channels:

  • General Inquiries: help@lifevaultsecure.com
  • Privacy Requests: privacy@lifevaultsecure.com
  • Privacy Contact: privacy@lifevaultsecure.com