Last updated: May 2026
Privacy Policy
Passed Plan is built on a simple principle: your private information should stay private. This policy explains what we collect, why we collect it, and how we protect it.
1. Who We Are
Passed Plan, Inc. ("Passed Plan," "we," "us," or "our") operates the Passed Plan digital estate planning service available at passedplan.com and through our mobile applications (collectively, the "Service"). Our registered address and contact information are available at support@passedplan.com.
2. Information We Collect
2.1 Account Information
When you register, we collect:
- Name and email address
- Password (stored as a salted hash — we never store your plaintext password)
- Date of birth (to verify you are 18 or older)
- Phone number (optional, for account recovery)
- Billing address and payment method details (processed by Stripe; we store only a tokenised reference)
2.2 Vault Data
The core of Passed Plan is your encrypted vault. All vault contents — documents, notes, media, beneficiary designations, last messages, and any other material you upload — are encrypted on your device before transmission using AES-256-GCM with a key derived from your vault passphrase via PBKDF2. We receive and store only ciphertext. We have no technical ability to read, search, or access your vault contents. See Section 5 for more detail on our zero-knowledge architecture.
2.3 Identity Verification Data
To comply with our death-verification obligations and prevent fraud, we may collect government-issued identity documents and biometric photographs through our identity partner, Persona. This data is processed and stored by Persona subject to their own privacy policy and is not retained on our servers beyond the verification transaction.
2.4 Usage and Technical Data
We automatically collect limited technical data including:
- IP address and approximate geolocation (country/region level)
- Browser type, operating system, and device identifiers
- Pages visited, features used, and session duration (via PostHog analytics)
- Error logs and performance metrics
- Check-in timestamps and I'm Alive confirmations
We configure PostHog in privacy-first mode: personally identifiable information is masked, IP addresses are anonymised before storage, and data does not leave our designated EU/US processing regions.
2.5 Communications
If you contact us for support or send us feedback, we retain those communications to respond to you and improve the Service.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account and subscription
- Deliver the Service, including storing and serving encrypted vault data
- Process payments through Stripe
- Send transactional emails (account notices, check-in reminders, death-event alerts) via Resend
- Send SMS notifications where you have opted in, via Twilio
- Verify identity during the trusted-contact access flow, via Persona and VitalChek
- Generate AI-assisted estate planning guidance via Anthropic's Claude API (prompts contain no vault ciphertext)
- Host and serve video Last Goodbyes via Mux and store encrypted media files via Backblaze B2
- Detect fraud, abuse, and security threats
- Comply with legal obligations
- Improve and develop the Service using aggregated, de-identified analytics
We do not sell your personal information to third parties. We do not use your data for advertising.
4. Third-Party Service Providers
We share data with the following categories of processors only to the extent necessary to deliver the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database and authentication infrastructure (SOC 2 Type II) | Account data, encrypted vault blobs, audit logs |
| Stripe | Payment processing | Email, billing address, payment token |
| Anthropic | AI estate planning guidance | User prompts only (no vault contents) |
| Twilio | SMS notifications | Phone number, message content |
| Resend | Transactional email delivery | Email address, message content |
| Mux | Video encoding and delivery | Encrypted video files |
| Backblaze B2 | Encrypted object storage | Encrypted vault files |
| Persona | Identity verification | Government ID, selfie photograph |
| VitalChek | Death certificate verification | Deceased's name, date of birth |
| Vercel | Application hosting and edge network | Request logs, IP addresses |
| PostHog | Privacy-first product analytics | Anonymised usage events |
Each provider is bound by data processing agreements that restrict them from using your data for purposes beyond the services they provide to us.
5. Zero-Knowledge Encryption
Passed Plan is designed so that we are technically incapable of reading your vault contents. Your vault passphrase never leaves your device. All encryption and decryption occurs locally in your browser or application before any data is sent to our servers. The keys we store are encrypted with your passphrase; without it, they are useless.
Practical implications:
- We cannot recover your vault passphrase if you forget it.
- We cannot comply with government requests to disclose vault contents because we do not have the plaintext.
- We cannot search, index, or train AI models on your vault data.
- If you lose your passphrase and have no recovery keys configured, your vault data is permanently inaccessible.
6. Posthumous Access by Trusted Contacts
You may designate one or more trusted contacts who are authorised to access your vault after your death. When a trusted contact initiates an access request, the following process applies:
- The trusted contact submits a death certificate for verification via VitalChek.
- The trusted contact completes identity verification via Persona.
- A 72-hour fraud window begins, during which you (if alive) can halt access using the I'm Alive function.
- After 72 hours with no halt, the trusted contact is granted access to the decryption keys you have pre-authorised for them.
This process involves sharing your name and date of birth with VitalChek and the trusted contact's identity documents with Persona. We retain verification records as part of our immutable audit log.
7. Data Retention
- Active accounts: We retain all account and vault data for as long as your subscription remains active.
- After cancellation: We retain your data for 90 days following the end of your subscription to allow reactivation. After 90 days, all vault data is permanently and irreversibly deleted from our systems and backups.
- After death and vault access: Data is retained for 12 months following successful trusted-contact access, then permanently deleted unless the estate requests earlier deletion.
- Audit logs: Immutable audit records are retained for 7 years for fraud prevention and legal compliance.
- Backups: Encrypted backups cycle on a 30-day rolling window and are subject to the same retention schedule.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you (excluding encrypted vault contents, which only you can decrypt).
- Correction: Ask us to correct inaccurate account information.
- Deletion: Request deletion of your account and all associated data. Note the 90-day retention window described above.
- Export: Request a machine-readable export of your account metadata. Vault data is always available for export through the application itself because only you hold the decryption key.
- Objection: Object to certain processing activities.
- Restriction: Request that we restrict processing in certain circumstances.
To exercise any of these rights, email support@passedplan.com. We will respond within 30 days. We may need to verify your identity before processing your request. Note that export requests are subject to a 90-day waiting period from subscription start to prevent fraudulent data harvesting.
9. California Residents — CCPA Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Opt Out of Sale: We do not sell personal information. No opt-out is necessary.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- Right to Correct: You may request correction of inaccurate personal information.
To submit a CCPA request, contact us at support@passedplan.com with the subject line "CCPA Request." You may also designate an authorised agent to make a request on your behalf; the agent must provide written authorisation.
10. Children
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe we may have collected such information, please contact us at support@passedplan.com.
11. International Transfers
Our services are operated primarily from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate. We rely on Standard Contractual Clauses and other lawful transfer mechanisms for transfers from the European Economic Area and United Kingdom.
12. Security
We employ technical and organisational measures to protect your data, including TLS in transit, AES-256-GCM encryption at rest, multi-factor authentication for administrative access, and immutable audit logging. For a detailed description of our security practices, see our Security Overview.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and by posting a notice in the application at least 30 days before the changes take effect. Your continued use of the Service after the effective date of the revised policy constitutes acceptance of the changes. The date at the top of this page reflects the most recent revision.
14. Contact Us
For privacy-related questions, requests, or concerns, please contact our privacy team:
Email: support@passedplan.com
Mail: Passed Plan, Inc., Attn: Privacy, [Address on file]