Privacy notice

What GuidedEstate stores, who can see it, and how long it is kept. Last updated 26 August 2026.

This notice describes what the software actually does. It is not legal advice, and it does not replace the terms you agreed to when you signed up. If you want something removed and cannot find how, ask us and we will do it.

The short version

What we hold

Your account

Your email address, your name, a hashed password, and the dates you verified your email and last signed in. Recovery codes are stored only as hashes — the codes themselves are shown once and cannot be recovered by anyone, including us.

Your record

Whatever you choose to put in it: who you are, where you live, the banks and policies, where the will is, who your executor is, your professional contacts, your property, and where documents are kept. Most of it is optional. A record with three things in it works.

Health and care

If you use the health and care section, we hold what you record there — wishes about treatment, allergies, conditions, medications, your doctor, and where your directive is kept. This is the most sensitive part of the record and it is encrypted like the rest. It can be switched off entirely in some countries, in which case the section does not appear and nothing can be stored in it. It is not a medical record and does not replace the notes your doctor holds.

Payments

Handled by Stripe. Card numbers never reach us — we hold a customer reference, what you bought, and when. Stripe has its own privacy notice covering what it does with the payment itself.

What is encrypted, and what is not

Names, addresses, account numbers, tax identifiers, notes and everything else that identifies a person or an account are encrypted in the database. Somebody who obtained a copy of the database without the key would find ciphertext.

Some fields are deliberately left readable, and it is worth saying which and why: amounts, dates, currencies and the kind of a thing — that a row is a chequing account rather than a mortgage. They are what the totals are computed from, an encrypted column cannot be added up, and a figure with no name attached says very little on its own. The identity is what is protected.

Our application logs record which field was decrypted and which key was used. They never record the value.

The vault is different

The vault is encrypted with a password only you know, which is not the same as your account password and is never sent to us in a form we can use. We cannot read the vault, and we cannot recover it. If you forget that password the contents are gone — for you, for us, and for your executor. That is the trade the vault exists to make, and it is why the rest of the record is not built that way.

Who can see your record

Only people you have given access to, and only as much as the role you gave them:

We email you whenever somebody with power of attorney opens your record, at most once a day each, and you can take their access away in one click. Somebody trusted with your affairs should never be able to look at them without you knowing.

Our staff do not read records in the ordinary course of running the service. The encrypted fields are not visible in our administration tools.

How long we keep it

Your record is kept until you delete it. We do not age it out, and we will not delete it because you have not signed in. The moment it matters may be years after the last time you looked at it, and deleting somebody's record because they stayed healthy for long enough would defeat the whole purpose of keeping one.

What we do clear out, automatically:

WhatKept forWhy it goes
Invitations that were accepted, revoked or expired 90 days They carry an email address and a spent token. The access itself is recorded separately.
Used or expired email verification links 30 days Single use. Once used, the row is a spent key.
Finished background jobs 30 days One row per notification email, plus a traceback where one failed.
Refused sign-in, password reset and vault attempts 30 days Counted so that nobody can hammer these pages. The address and the network it came from are stored only as a one-way hash, so the table cannot be read back as a list of people.
Uploaded scans Until the record is deleted The file is removed from disk with the row, not left behind.

Some things are kept on purpose rather than cleared. A suspended membership and a disputed death declaration stay, because they are the evidence of what happened and deleting them would leave nothing to look at. A removed forum message leaves a marker where it was, so the replies to it still make sense.

Getting it out, and getting rid of it

Export. Every record has an export that gives you everything in it as a structured file — not a screenshot, not a summary. It is on the record's own page.

Deletion. Deleting a record deletes what is in it, including any scans, immediately and for good. It is not a soft delete and we do not keep a copy. If you want your account closed as well, ask us and we will do it; anything we are required to keep for accounting — what you paid and when — is kept and nothing else.

Where it is

On servers we run, with the encryption key held outside the database. Backups are encrypted. We use Stripe for payments and a mail provider to send the emails this service sends; neither is given anything from the encrypted parts of your record.

Asking us

You can ask what we hold about you, ask us to correct it, or ask us to delete it. Most of that you can do yourself from inside the application, which is faster. For anything else, the contact address is in the footer.