This policy describes what Lifevault collects, why each item is necessary, and the boundary beyond which we cannot read your data even if compelled to.
Lifevault Systems Ltd (Company No. 00000000, registered in England & Wales), registered at 1 Example Street, London EC1A 1BB, United Kingdom, is the data controller for the personal data described here. Privacy enquiries go to privacy@lifevault.example.
Vault contents — letters, documents, credentials and any file you seal — are encrypted on your device with a key derived from your passphrase before they reach us. We hold ciphertext only. We cannot read them, cannot recover them, and cannot produce them in response to any legal demand.
Everything else in the table below is readable by us, because the service cannot function otherwise: a system that sends an SMS to your guardian must be able to read your guardian's number.
Purpose: authentication and contacting you on the first three escalation rungs. Basis: performance of contract. Retained for the life of the account.
Purpose: contacting the people you nominated when the ladder advances. Basis: performance of contract, and our legitimate interest in reaching them. Deleted when you remove the guardian.
Purpose: deciding whether a window closed, and showing you your own history. Basis: performance of contract. Retained 24 months, then aggregated.
Purpose: storing what you sealed until release conditions are met. We can see that an item exists and how large it is. We cannot see what it is.
Purpose: taking payment. Card details are held by our payment processor and never touch our servers. Basis: contract and legal obligation. Invoices retained 7 years.
Purpose: security, abuse prevention and debugging. Basis: legitimate interest. Retained 90 days.
We use a small number of processors, each bound by contract to process data only on our instructions. Vault ciphertext passes through some of them; none of them can decrypt it.
Primary storage and processing is in the European Union. Where a processor transfers data outside the UK or EEA, that transfer relies on Standard Contractual Clauses or an equivalent adequacy mechanism.
A guardian sees your name, whether your most recent window closed, and whether a travel hold is in place. When the ladder reaches the rung that notifies them, they additionally receive whatever you chose to record for that purpose — typically an address, medical notes, and who else has been contacted.
Guardians never see your vault contents before release, your other guardians' contact details, or your billing information.
If the ladder completes and the seven-day vault delay expires, sealed items are released to the recipients you assigned to each one — and only to those recipients. This is the purpose you signed up for, and it is the one disclosure of your data that happens without a further instruction from you.
Release is irreversible. It cannot be triggered early by us, by a guardian, by a family member, or by a court order directed at us, because the delay is enforced independently of any account setting.
Under the UK GDPR and the EU GDPR you may request access to your personal data, correction of it, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. You may also withdraw consent where consent is the basis.
Exercise any of these at privacy@lifevault.example or through the data requests page. We answer within 30 days and do not charge a fee. We will ask you to authenticate, but we will not ask why.
You have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office.
Closing your account triggers an export to you and destruction of your data on our side within 30 days. Backups age out on a rolling 35-day cycle. Invoices are retained for seven years because tax law requires it; they contain a name, an amount and a date, and nothing about your vault or your guardians.
The service is not directed at, and may not be used by, anyone under 18. We do not knowingly hold data about children. A guardian must also be over 18.
Material changes are announced by email at least 30 days before they take effect, and every version is listed in the changelog. If you object to a change, you can export and close your account before it applies.