Privacy Policy

Last updated 31 July 2026

The short version

  • Your vault is encrypted. We do not read it, sell it, or train anything on it.
  • We contact your nominated people only when your switch requires it.
  • We never text anyone who has not personally agreed to be texted.
  • You can delete everything, permanently, at any time.

What we collect

Your account: name, email, optional mobile number, a hashed password, and — if you enable two-step sign-in — an encrypted authenticator secret and hashed recovery codes.

Your vault: whatever you put in it — documents, credentials, letters, instructions, wishes. This is the sensitive part, and it is encrypted (see below).

Your people: the names, email addresses, optional phone numbers, and relationships of the recipients and verifiers you nominate, plus any personal note you write for them.

Operational records: when you checked in, when messages were sent and whether they were delivered, when a claim link was opened, and consent records. Message bodies are stored with links and access codes redacted, so the log cannot be used to open anyone’s vault.

How your vault is protected

Every vault item is encrypted with its own key using AES-256-GCM, and each of those keys is wrapped by a master key held separately from the database. A stolen copy of the database alone does not reveal your documents. Uploaded files are encrypted before they are stored. Passwords and access codes are hashed with scrypt, never stored in readable form.

Honest limitation: this is encryption we hold the key to, because the service must be able to deliver your vault when you cannot act. We do not have a design where only you hold the key and delivery still works. If that matters to you, it is a reasonable reason not to store your most sensitive passwords here.

Who ever sees your information

  • You.
  • The people you nominate — and only the items you specifically designate for each of them, and only after a release.
  • Our service providers, limited to what they need: cloud hosting (Google Cloud), email delivery, and SMS delivery. They handle message metadata and contents of the messages we send them — which never include your vault contents.
  • Nobody else. We do not sell your information, share it with advertisers, or use it to train machine-learning models.

We may disclose information if legally compelled. If we receive such a demand, we will try to notify you unless we are legally prohibited from doing so.

Text messages and consent

Because the phone numbers of your recipients are supplied by you rather than by them, we ask each person directly before we ever text them, and we record when and how they agreed. Anyone can reply STOP or use the link in that message to opt out at any time, and we will tell you if that happens so you can arrange another way to reach them. Message and data rates may apply. We do not send marketing messages.

How long we keep things

Your vault is kept while your account is active. After a release, claim access is retained so that your recipients can return to it — estates take time. If you delete your account, we permanently delete your vault, contacts, encrypted files, and pending claim links. Deletion cannot recall anything already delivered.

Your rights

You can access and correct your information in the app, and delete your account and all its contents at any time from Settings. Depending on where you live, you may have additional rights to a copy of your data or to object to certain processing — write to us and we will help.

Children

The service is not intended for anyone under 18.

Changes

If we make a material change to this policy, we will notify account holders by email before it takes effect.

Contact

privacy@breakglass.life

Note for launch: this is a working draft, accurate to what the software currently does. It must be reviewed by a licensed attorney — particularly for GDPR/CPRA obligations and the data-processing terms with each provider — before real customers rely on it.