Inherit Vault logo Inherit Vault

Privacy Policy

1. Who we are

Inherit Vault ("we", "us") provides a digital inheritance vault: an encrypted record of where your assets and important information can be found, released to your nominated executor through a verified process. We are the data controller for the personal data described in this policy. Contact: support@inheritvault.com. Inherit Vault Ltd is registered in England and Wales, company number 17403417, registered office Suite A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE.

2. The one thing to understand first

The contents of your vault are encrypted in your browser before they reach us, with keys derived from secrets only you hold. We cannot read them, we hold no master key, and no employee, attacker, or authority can compel from us what we do not possess. Vault contents are therefore not personal data we can access, and everything below concerns the ACCOUNT data around your vault, not what is inside it.

3. What we collect, and why

Account data: your name, email address, password (stored only as a cryptographic hash), country, and your chosen check-in frequency. Used to operate your account, run the check-in and escalation process, and contact you about the service. Lawful basis: performance of our contract with you. Executor and contact details: the name and email of anyone you nominate (executor, family member, will-provider contact). Used solely to operate the invitation, notification, and release processes you set up. Lawful basis: performance of the contract; it is your responsibility to tell them you have named them. Optional phone data: if you choose to add a phone number, it is used only for the SMS alert that warns you when someone claims access to your vault, and, if you choose to set a support-word, to verify your identity on support calls. Both are entirely optional, the service works fully without them, and you can remove them at any time in Account Settings. Lawful basis: consent, withdrawable at any time. Billing data: handled by Stripe, our payment processor. We never see or store your card details; we store your subscription status, plan, currency, and payment outcomes. Lawful basis: performance of the contract and our legal obligations (tax and accounting records). Security and audit data: login attempts, IP addresses, and security-relevant actions, kept in an append-only audit log. Lawful basis: our legitimate interest in protecting accounts whose entire purpose is to be trustworthy, and in detecting fraudulent death claims. Re-engagement contact data: if we delete a never-activated vault because it was never subscribed and went unused (clause 8.4 of the Terms), we keep your name and contact details, and the fact that you once held a vault, so we can invite you to start again or tell you about a relevant offer. The vault's contents are deleted, not kept, and this never includes anything from inside a vault. Lawful basis: our legitimate interest in inviting back people who started with us and did not finish, alongside the direct marketing rules that apply to people who previously enquired about the service. Every such message carries a one-click unsubscribe, and you can opt out at any time by emailing support@inheritvault.com. Analytics: our public marketing pages use self-hosted, cookieless analytics that collect no personal data and set no identifiers. Nothing inside a signed-in session is ever tracked.

4. Who we share it with

Nobody, for marketing, ever. We use a small number of processors strictly to run the service: our hosting provider (encrypted data at rest in the EU/UK), our email delivery provider (to send account emails), our SMS provider (only if you opted in to SMS), and Stripe (payments). Each processes data only on our instructions. Vault contents are never shared with Probate, HMRC, or anyone else unless you explicitly request it, or your vault completes the verified executor release process you configured.

5. International transfers

We keep service data in the UK/EU. Where a processor operates outside the UK, transfers are protected by UK-approved safeguards (adequacy or standard contractual clauses).

6. How long we keep it

Account data: while your account is active, then up to 12 months for security and legal record-keeping before erasure, except records we must keep longer by law (e.g. billing records, 6 years). The append-only audit log keeps security events for the same period. Deletion requests are reviewed by a human before processing, deliberately, so a stolen password cannot be used to destroy your family's vault, and are then honoured fully. Re-engagement contact data: up to 24 months from the date the never-activated vault was deleted, or until you opt out, whichever comes first.

7. Your rights

You can access, correct, export, or erase your data, object to or restrict processing, withdraw consent for optional features, and complain to the Information Commissioner's Office (ico.org.uk). Start with Account Settings or support@inheritvault.com; we respond within one month.

8. Security

End-to-end envelope encryption for vault contents; mandatory two-factor authentication; progressive lockouts on failed logins; encrypted off-site backups; an append-only audit log; and a release process that combines human review, a mandatory waiting period, and a physical paper key we never hold. A breach of our servers cannot expose readable vault contents, and if we are ever compelled or hacked, all anyone gets is unreadable code.

9. Children

The service is for adults putting their affairs in order and is not directed at children under 18.

10. Changes to this policy

Material changes are announced by email with a new version number before they take effect. Continued use after the effective date constitutes acceptance; if you disagree, you may export your vault and close your account at any time.

Questions? Contact support@inheritvault.com.