HeirlioEffective: July 28, 2026

Privacy Policy

Last updated: July 28, 2026

Heirlio ("we", "us", or "our") respects your privacy. This policy explains what personal information we collect, how we use it, and your rights regarding that information.

1. Information We Collect

We collect only what is necessary to provide the service:

  • Account data: your first name, last name, and email address.
  • OAuth identity (if you sign in with Google): your Google profile name and email. We never store your Google password.
  • Estate content: item names, descriptions, categories, estimated values, photos of personal property, interest levels, and distribution decisions entered by you or other estate members.
  • Usage data: basic server logs (IP address, browser type, pages visited) for security and debugging. These are not sold or profiled.
  • Session data: a short-lived authentication token (JWT) is stored in your browser to maintain your session. No third-party tracking cookies are used.
  • Campaign attribution: when you arrive through a tagged campaign link, we may retain first-party campaign parameters such as source, campaign, and click identifier with your account to measure which campaigns lead to registrations and purchases and, when applicable, to support conversion measurement as described below.
  • Transaction records: when you make a purchase (Estate Plan or credit pack), we retain a record of the Stripe payment session ID, amount, timestamp, what was purchased, and the resulting credit balance change. We do not store your full card number or CVV. Transaction records are retained for 7 years for tax and legal compliance and are not subject to the estate inactivity deletion policy.

We do not collect payment card data.

2. How We Use Your Information

  • Authenticate your account and maintain your session.
  • Display estate items, interests, and decisions to authorised estate members.
  • Send transactional emails (invite links, account notifications). No marketing without consent.
  • Detect and prevent fraud or misuse of the service.

We do not sell or rent your personal data. Any data shared with advertising partners is used only for conversion measurement as described in the Advertising Measurement section below. We do not use your data to build advertising profiles or to enable third parties to target you with ads.

3. Who We Share Data With

We share data only with the sub-processors needed to run the service:

  • DigitalOcean: cloud infrastructure and file storage (servers located in the United States).
  • Stripe: payment processing for credit purchases. Stripe receives your name, email, and payment information. We never see or store your full card number. See Stripe's Privacy Policy.
  • OpenAI: AI vision analysis for photo imports. When you use the photo import feature, your uploaded image is transmitted to OpenAI for analysis. OpenAI does not use API-submitted content to train its models. See OpenAI's API data usage policy.
  • Unstructured.io: document text extraction for document imports. When you use the document import feature, your uploaded file is transmitted to Unstructured.io for parsing. See Unstructured's Privacy Policy.
  • Google OAuth: only if you choose to sign in with Google.
  • Meta: advertising measurement via Meta Conversions API. We may send hashed conversion data and related attribution metadata to Meta to measure ad performance. Meta acts as a data processor on our behalf for measurement purposes only. See Meta's Privacy Policy.

Advertising Measurement

We use Meta Pixel and Meta Conversions API (CAPI) to measure whether our advertising leads to registrations and purchases. When a conversion occurs, we may send Meta a one-way cryptographic hash (SHA-256) of your email address, along with event metadata such as a deduplication ID and first-party campaign attribution details (for example, UTM parameters or a Facebook click identifier).

Raw email addresses are not transmitted to Meta for this measurement flow. We use this data only to measure ad performance, attribute conversions, and prevent duplicate reporting between browser-side pixel events and server-side CAPI events. We do not use this data to build advertising profiles or to target you with ads.

4. Data Retention

Your account data is retained while your account is active, subject to the following inactivity policy. Transaction records are retained for 7 years for tax and legal compliance regardless of account status. Server logs are automatically purged after 90 days.

  • Free-tier estates: if a free-tier estate has had no activity for 6 months, we will send a single email notice to the estate owner. If the estate remains inactive for 30 days after that notice, all estate content (items, photos, interests, and decisions) will be permanently and immediately deleted. No cold storage step is used. The data is removed from our systems entirely.
  • Paid estates (Estate Plan purchased): if a paid estate has had no activity for 1 year, its content will be moved to long-term archival (cold) storage following a 30-day email notice. Archived estate data is retained for up to 7 years from the date of archival, after which it is permanently deleted. Retrieval of archived data may take up to 48 hours and may be subject to a reactivation fee.
  • Pre-deletion export: where technically feasible, the deletion notice email will include a link to export your records. Once the notice period expires and deletion proceeds, our duty to host your data ends and responsibility for preservation passes to you.

You may request deletion of your own data at any time (see Section 7).

5. Fiduciary Access

In the spirit of the Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA), we may, at our sole discretion, grant read and export access to a deceased account holder's estate data to a person who can demonstrate they are a legally authorised representative of the estate (e.g. by providing a death certificate and evidence of legal authority such as Letters Testamentary). We will make reasonable efforts to respond to such requests in a timely manner but cannot guarantee a specific turnaround time.

Fiduciary access may not be possible if the estate data has already been permanently deleted under the inactivity policy in Section 4. We strongly recommend that estate owners designate a trusted successor or log in periodically to keep the estate active. To submit a request, email [email protected].

6. Security

Passwords are hashed with bcrypt; access tokens are short-lived JWTs; the database is encrypted at rest (Transparent Data Encryption). All traffic is encrypted via HTTPS/TLS. No security system is perfect. Please choose a strong password and do not share your account credentials.

7. Your Rights

Regardless of where you are located, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate information.
  • Erasure ("right to be forgotten"): you can permanently delete your account and all associated data directly from the app (Account → Delete Account), or by contacting us. Estate owners must first transfer ownership to another member to protect the continuity of the estate record for remaining members; this is a proportionate condition under GDPR Article 17(3) and does not negate your right to erasure.
  • Portability: request a copy of your data in a machine-readable format.
  • Object or restrict processing in certain circumstances.

To exercise any of these rights, use the in-app account settings or email us at [email protected]. We will respond within 30 days (GDPR) / 45 days (CCPA).

8. European Users (GDPR)

If you are located in the European Economic Area (EEA), the UK, or Switzerland, we process your personal data under the following legal bases:

  • Contract: processing required to provide the service you signed up for.
  • Legitimate interests: fraud prevention and service security.
  • Consent: optional features such as marketing communications.

Data may be transferred to the United States, where our servers are hosted. Where required, we rely on Standard Contractual Clauses (SCCs) to ensure adequate protection. You have the right to lodge a complaint with your local data protection authority.

9. California Residents (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete, the right to opt out of the sale of personal information (we do not sell personal information), and the right to non-discrimination for exercising these rights.

To submit a verifiable consumer request, email [email protected] or use the in-app "Delete Account" option.

10. Children's Privacy

Heirlio is not directed to individuals under 18. We do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this policy from time to time. If we make material changes we will update the "Last updated" date and, where practical, notify you by email.

12. Contact Us

Questions or requests? [email protected]