1. Introduction and Scope
This Privacy Policy describes how LifeVault Secure ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our web application and related API services (collectively, the "Service").
This policy applies to all users of the Service regardless of location. Where specific laws grant you additional rights, those rights are described in Section 10.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
2. Who We Are
LifeVault Secure is a security-first digital vault platform for storing, managing, and conditionally releasing sensitive digital assets. We act as the data controller for the personal information we process.
- Legal Entity: Edukas Solutions LLC
- Address: 8605 Santa Monica Blvd PMB 875080, West Hollywood, California 90069-4109 US
- Privacy Inquiries: privacy@lifevaultsecure.com
- Privacy Contact: privacy@lifevaultsecure.com
3. Our Encryption Commitment
LifeVault Secure is built on a zero-knowledge architecture for your vault content. We do not have the technical ability to access, read, or decrypt your notes, password entries, structured vault entries, or the files you upload — these are end-to-end encrypted on your device. A limited set of data is necessarily server-readable: the documents we generate for you (such as legal-template PDFs), which we render and encrypt on our servers, and operational metadata such as file names, sizes, and timestamps. This is a design choice, not just a policy decision.
We use envelope encryption to protect your data. Each vault has its own Data Encryption Key (DEK) that is wrapped by a Key Encryption Key (KEK) stored in hardware security modules (Azure Key Vault). Password fields are encrypted with AES-256-GCM (authenticated encryption) using a unique initialization vector for each field.
Data We Cannot Access (End-to-End Encrypted)
- Note contents (text, and the metadata of audio notes)
- Password entries, including usernames, passwords, URLs, notes, and TOTP secrets
- Other structured entries you store in your vaults (such as identity and card records)
Data We Encrypt and Can Access (to operate the Service)
Documents we generate for you — such as legal-template PDFs — are rendered on our servers and encrypted at rest with server-side AES-256 under keys we manage. Because we hold these keys, we can decrypt these generated documents to render and deliver them to you, and we may be required to produce them in response to valid legal process. Files you upload yourself are end-to-end encrypted and appear above under the data we cannot access.
Metadata We Can Access (Not Encrypted)
To operate the Service, we must process certain metadata that is not encrypted:
- File names, sizes, and MIME types
- Vault names, creation dates, and member lists
- Timestamps of uploads, downloads, and access events
- Your account profile information (email, display name)
Your notes, passwords, structured vault entries, and the files you upload are end-to-end encrypted on your device: only you hold the decryption keys, and no recovery is possible if you lose your vault password. The documents we generate for you (such as legal-template PDFs) are encrypted with server-side AES-256 under keys we manage, which we can access to render and deliver those documents and to operate the Service.
4. Information We Collect
4.1 Vault Data
This is the content you store in your vaults. Your notes, password entries, structured vault entries, and the files you upload are end-to-end encrypted before they reach us, and we cannot access them in a readable format. The documents we generate for you (such as legal-template PDFs) are encrypted with server-side AES-256 under keys we manage; we can access these generated documents to render, deliver, and operate the Service. The categories of vault content we collect are:
- Files and documents you upload
- Password entries (usernames, passwords, URLs, notes, TOTP secrets)
- Any other content you choose to store in your vaults
4.2 Account and Profile Data
- Email address and display name
- Phone number (if you enable SMS verification via Twilio)
- Authentication identifiers from your identity provider
- Account preferences, theme settings, and notification preferences
4.3 Billing and Payment Data
Payment processing is handled by Stripe and PayPal. LifeVault Secure does not store your full credit card number, CVV, or bank account details.
- Subscription tier, billing cycle, and plan history
- Last four digits of your payment method (for display purposes only)
- Transaction history and invoice records
4.4 Emergency Access and Life Event Data
If you configure emergency access or life event features, we collect:
- Trusted contact names, email addresses, and phone numbers you provide
- Life event type selections and trigger conditions you configure
- Verification evidence submitted by trusted contacts during a life event claim
- Policy execution logs and access grant records
4.5 Usage and Diagnostic Data
- Storage usage, vault counts, and item counts
- Feature usage patterns (which features are accessed, not their contents)
- Error logs and diagnostic data for troubleshooting
4.6 Automatically Collected Data
- IP address and approximate geographic location
- Browser type, operating system, and device information
- Referring URL and pages visited within the Service
- Cookies and similar tracking technologies (see Section 9)
5. How We Use Your Information
We use your information only for the purposes described below. For each purpose, we identify the legal basis under the GDPR:
| Purpose | Legal Basis |
|---|---|
| Provide, maintain, and operate the Service (vault storage, encryption, file management) | Performance of contract |
| Process payments and manage subscriptions | Performance of contract |
| Send transactional notifications (account alerts, security warnings, policy triggers) | Performance of contract |
| Enforce emergency access policies and verify life event declarations | Legitimate interest and your explicit consent |
| Prevent fraud, abuse, and unauthorized access | Legitimate interest |
| Comply with legal obligations (tax records, law enforcement requests) | Legal obligation |
| Improve the Service based on aggregated usage patterns | Legitimate interest |
| Measure the performance of our marketing campaigns and attribute sign-ups to the campaign that produced them | Legitimate interest |
7. Data Retention
We retain your data only as long as necessary for the purposes described in this policy. Below are the specific retention periods for each data category:
| Data Category | Retention Period |
|---|---|
| Vault data (encrypted files, passwords) | Until you delete the item or your account is terminated |
| Account and profile data | Duration of your account plus 30 days after deletion |
| Billing and payment records | 7 years after the transaction (tax and legal compliance) |
| Audit logs | 7 years (retained for security integrity) |
| Emergency access and life event data | Until you revoke the policy or your account is terminated |
| Usage and diagnostic data | 2 years, then aggregated and anonymized |
| Automatically collected data (IP, browser) | 13 months |
8. International Data Transfers
LifeVault Secure processes and stores data primarily in Microsoft Azure data centers located in the United States. If you access the Service from outside the United States, your information is transferred to and processed in the US.
For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office. We also evaluate the data protection laws of recipient countries and implement supplementary technical safeguards, including encryption, to protect your data during transfer.
10. Your Privacy Rights
10.1 Rights for All Users
- Access your personal data and receive a copy of it
- Correct inaccurate or incomplete personal data
- Delete your account and associated personal data
- Export your data in a portable, machine-readable format
10.2 Additional Rights for EEA/UK Residents (GDPR)
If you are located in the European Economic Area or the United Kingdom, you have the following additional rights under the General Data Protection Regulation:
- Request that we restrict the processing of your personal data in certain circumstances
- Object to our processing of your personal data based on legitimate interests
- Withdraw your consent at any time where processing is based on consent
- Lodge a complaint with your local data protection supervisory authority
10.3 Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act and its amendments grant you the following rights:
- Know what personal information we collect, use, disclose, and sell
- Request deletion of your personal information
- Request correction of inaccurate personal information
- Opt out of the sale or sharing of your personal information
- Not be discriminated against for exercising your privacy rights
LifeVault Secure does not sell your personal information for monetary consideration. We do share a limited amount of usage data with our advertising partner, Meta Platforms, Inc., for advertising measurement; under California law, this may be treated as a "sale" or a "share" of personal information for cross-context behavioral advertising. You can opt out of this sharing at any time using the "Do Not Sell or Share My Personal Information" link, or by enabling a Global Privacy Control (GPC) signal in your browser. We honor these opt-out requests.
To opt out of the sharing of your personal information for advertising, use the "Do Not Sell or Share My Personal Information" link in the website footer, or enable a Global Privacy Control (GPC) signal in your browser. We treat a GPC signal as a valid opt-out request.
10.4 How to Exercise Your Rights
You can exercise most of these rights directly through your account settings, including downloading your data, correcting your profile, and deleting your account.
You can review and revoke third-party app access from Settings integrations.
For requests that cannot be handled through the self-service tools, email us at privacy@lifevaultsecure.com. We will respond within 30 days (GDPR) or 45 days (CCPA/CPRA). We may ask you to verify your identity before processing your request.
11. Deceased Users and Digital Estate Access
LifeVault Secure includes features specifically designed for digital estate planning. This section explains how we handle accounts and data of deceased users.
If you configure life event policies and trusted contacts, the following process applies upon a verified life event declaration:
- A trusted contact submits a life event claim with supporting documentation (such as a death certificate)
- The claim is verified according to the verification requirements you configured
- After the waiting period you set has elapsed, the trusted contact gains access to the vault contents specified in your policy
- All access events are recorded in the audit log
If no life event plan is configured, the account remains in its current state. We comply with the Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA) and applicable state laws governing fiduciary access to digital assets. Courts or estates with proper legal authority may request access through legal@lifevaultsecure.com, subject to the same encryption limitations described in Section 6.4.
12. Children's Privacy
LifeVault Secure is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@lifevaultsecure.com and we will promptly delete it. Account holders must additionally meet the minimum age set out in Section 2 of our Terms of Service.
For Family Legacy plan accounts, all members must be at least 16 years old. The account owner is responsible for ensuring that all invited family members meet this age requirement.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make changes, we will update the effective date at the top of this page.
For material changes that affect how we process your personal data, we will notify you at least 30 days in advance via email and an in-app notification. Your continued use of the Service after the updated policy takes effect constitutes your acknowledgment of the changes.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, you can reach us through the following channels:
- General Inquiries: help@lifevaultsecure.com
- Privacy Requests: privacy@lifevaultsecure.com
- Privacy Contact: privacy@lifevaultsecure.com