Privacy notice
What GuidedEstate stores, who can see it, and how long it is kept. Last updated 26 August 2026.
The short version
- We store what you type into your record, so that the people you choose can find it later.
- We never sell it, and we do not advertise against it.
- The sensitive parts are encrypted. The vault is encrypted with your own password, which means we cannot read it — not even if you ask us to.
- We will not delete your record because you stopped signing in. The point of it is that it waits.
- You can export everything, and you can delete it, whenever you like.
What we hold
Your account
Your email address, your name, a hashed password, and the dates you verified your email and last signed in. Recovery codes are stored only as hashes — the codes themselves are shown once and cannot be recovered by anyone, including us.
Your record
Whatever you choose to put in it: who you are, where you live, the banks and policies, where the will is, who your executor is, your professional contacts, your property, and where documents are kept. Most of it is optional. A record with three things in it works.
Health and care
If you use the health and care section, we hold what you record there — wishes about treatment, allergies, conditions, medications, your doctor, and where your directive is kept. This is the most sensitive part of the record and it is encrypted like the rest. It can be switched off entirely in some countries, in which case the section does not appear and nothing can be stored in it. It is not a medical record and does not replace the notes your doctor holds.
Payments
Handled by Stripe. Card numbers never reach us — we hold a customer reference, what you bought, and when. Stripe has its own privacy notice covering what it does with the payment itself.
What is encrypted, and what is not
Names, addresses, account numbers, tax identifiers, notes and everything else that identifies a person or an account are encrypted in the database. Somebody who obtained a copy of the database without the key would find ciphertext.
Some fields are deliberately left readable, and it is worth saying which and why: amounts, dates, currencies and the kind of a thing — that a row is a chequing account rather than a mortgage. They are what the totals are computed from, an encrypted column cannot be added up, and a figure with no name attached says very little on its own. The identity is what is protected.
Our application logs record which field was decrypted and which key was used. They never record the value.
The vault is different
The vault is encrypted with a password only you know, which is not the same as your account password and is never sent to us in a form we can use. We cannot read the vault, and we cannot recover it. If you forget that password the contents are gone — for you, for us, and for your executor. That is the trade the vault exists to make, and it is why the rest of the record is not built that way.
Who can see your record
Only people you have given access to, and only as much as the role you gave them:
- An executor sees how complete the record is and what is missing — and not one actual value — until a death has been declared and has gone unchallenged.
- A viewer can read the record now. You choose who.
- An attorney for property can read your accounts, property, documents and contacts. Not your will, not the vault.
- An attorney for personal care can read your contacts, documents and health and care record. Not your money.
We email you whenever somebody with power of attorney opens your record, at most once a day each, and you can take their access away in one click. Somebody trusted with your affairs should never be able to look at them without you knowing.
Our staff do not read records in the ordinary course of running the service. The encrypted fields are not visible in our administration tools.
How long we keep it
What we do clear out, automatically:
| What | Kept for | Why it goes |
|---|---|---|
| Invitations that were accepted, revoked or expired | 90 days | They carry an email address and a spent token. The access itself is recorded separately. |
| Used or expired email verification links | 30 days | Single use. Once used, the row is a spent key. |
| Finished background jobs | 30 days | One row per notification email, plus a traceback where one failed. |
| Refused sign-in, password reset and vault attempts | 30 days | Counted so that nobody can hammer these pages. The address and the network it came from are stored only as a one-way hash, so the table cannot be read back as a list of people. |
| Uploaded scans | Until the record is deleted | The file is removed from disk with the row, not left behind. |
Some things are kept on purpose rather than cleared. A suspended membership and a disputed death declaration stay, because they are the evidence of what happened and deleting them would leave nothing to look at. A removed forum message leaves a marker where it was, so the replies to it still make sense.
Getting it out, and getting rid of it
Export. Every record has an export that gives you everything in it as a structured file — not a screenshot, not a summary. It is on the record's own page.
Deletion. Deleting a record deletes what is in it, including any scans, immediately and for good. It is not a soft delete and we do not keep a copy. If you want your account closed as well, ask us and we will do it; anything we are required to keep for accounting — what you paid and when — is kept and nothing else.
Where it is
On servers we run, with the encryption key held outside the database. Backups are encrypted. We use Stripe for payments and a mail provider to send the emails this service sends; neither is given anything from the encrypted parts of your record.
Asking us
You can ask what we hold about you, ask us to correct it, or ask us to delete it. Most of that you can do yourself from inside the application, which is faster. For anything else, the contact address is in the footer.