Legal
Privacy Policy
How LifeWyn handles your information under a zero-knowledge model — and, just as importantly, what we deliberately cannot see.
Last updated: July 1, 2026
Under legal review. This policy describes how LifeWyn actually handles your data today. The controller, Data Protection Officer, and grievance-officer details in Section 15 are being finalised with counsel and will be completed before general availability.
1. Introduction
LifeWyn ("LifeWyn", "we", "us", or "our") provides a zero-knowledge digital inheritance platform. This Privacy Policy explains what information we collect when you use our websites, applications, and related services (collectively, the "Service"), how we use and protect it, and the choices you have. By using the Service, you agree to the practices described here.
The defining principle of our Service is that your most sensitive content — the data you store in your vault — is encrypted on your own device before it reaches us, and the keys that decrypt it are never transmitted to us. Your account and contact details are a separate matter and are described in full below.
2. Information we collect
We collect only what we need to operate the Service:
- Account and contact information. Your name, email address, and (optionally) a phone number, used to create and secure your account, authenticate you, and send essential notifications.
- Device and technical information. Device type, operating system, browser, IP address, language, and similar diagnostic data used for security, fraud prevention, and reliability.
- Encrypted vault ciphertext. The encrypted contents of your vault. We store this ciphertext but cannot decrypt it, because the keys required to do so never leave your control.
- Protection Check-In signals. Metadata generated when you complete periodic check-ins, along with the inactivity and verification signals used by your inheritance rules (for example, timestamps of your last confirmed activity).
- Inheritance configuration. The nominees you designate, the rules and thresholds you set, and encrypted key-shares — never their decrypted contents.
- Billing metadata. Subscription plan, billing status, and transaction identifiers. Card and payment details are handled by our payment processors; we do not store full card numbers.
3. What we cannot access
To make our commitment concrete, the following are technically inaccessible to us by design:
- Your plaintext vault data. Documents, credentials, keys, notes, and files inside your vault are encrypted before upload. We hold only ciphertext.
- Your master password and derived keys. Your master password is never transmitted to or stored by us. We cannot recover it, and we cannot reconstruct the keys derived from it.
Because we do not hold your keys, a legal demand for your vault reaches ciphertext rather than plaintext, and we cannot restore access if you lose your master password and never armed recovery. Account and nominee contact details, which we do hold in readable form, can be produced. This is an intentional trade-off in your favor.
4. How we use information
We use the information we collect to:
- Provide, maintain, and secure the Service and your account;
- Operate Protection Check-Ins and evaluate your inheritance rules using the signals described above;
- Communicate with you about your account, security, service changes, and support requests;
- Process subscriptions, trials, billing, and renewals;
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our terms.
We do not sell your personal information, and we do not use your vault contents for advertising or profiling — your vault reaches us only as ciphertext, so it is not available to us for those purposes.
5. Encryption and data security
Vault contents are protected with authenticated symmetric encryption (XChaCha20-Poly1305) using keys derived on your device from your master password with a strong key-derivation function. Data is encrypted in transit using TLS and encrypted at rest on our infrastructure. We apply access controls, network segmentation, logging, and routine review to our systems. No system is perfectly secure, but the zero-knowledge architecture means that even a compromise of our servers would expose ciphertext, not your readable data.
6. Key management and inheritance data
Recovery for nominees is enabled through encrypted key-shares that you configure. These shares are stored in encrypted form and are only made available to a nominee when the conditions you defined are satisfied and verified. We store the rules, thresholds, and encrypted shares required to orchestrate this process; we do not store anything that would let us assemble your keys ourselves ahead of a valid, verified release.
7. Sharing and disclosure
We disclose information only in limited circumstances:
- Nominees. When your inheritance rules are met and verified, designated nominees receive the encrypted key-shares and vault access you granted them — and nothing more.
- Service providers. We share limited data with vendors who process it on our behalf (for example, cloud hosting, email delivery, and payment processing) under contractual confidentiality and security obligations.
- Legal and safety. We may disclose information if required by law, subpoena, or valid legal process, or to protect the rights, safety, and security of users, the public, or LifeWyn. Even so, we cannot disclose plaintext vault data we do not have the ability to decrypt.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, your information may be transferred subject to this Policy.
8. Data retention
We retain account, configuration, and billing metadata for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Deletion requests are honored per our retention schedule: when you ask us to close your account we deactivate it and remove or anonymize the associated data over the retention periods set out in that schedule, except where longer retention is required by law. Fully automated, self-service account erasure is not yet available; to request deletion, contact us using Section 14. Because vault contents are encrypted with keys we do not hold, deleting the ciphertext renders it permanently unrecoverable.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. You can manage much of this directly in your account settings, including exporting your data. Account deletion is handled as a request today (see Section 8) rather than a fully self-service action. To make a formal data-rights request, contact us at support@lifewyn.com. We will respond within the timeframes required by applicable law and may need to verify your identity first.
10. Cookies and local storage
We use cookies and browser local storage to keep you signed in, remember preferences, secure sessions, and understand aggregate usage. Some local storage is essential to the Service — for instance, holding keys derived on your device so your vault can be decrypted locally. You can control non-essential cookies through your browser settings, though disabling essential storage may break core functionality.
11. International transfers
We may process and store information in countries other than your own, including where our service providers operate. Where we transfer personal data across borders, we rely on appropriate safeguards, such as standard contractual clauses, consistent with applicable data-protection law.
12. Children's privacy
The Service is not directed to children, and we do not knowingly collect personal information from anyone under the age required to form a binding contract in their jurisdiction (and in no case under 16). If you believe a child has provided us personal information, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
14. Contact us
If you have questions about this Policy or how we handle your information, contact us at support@lifewyn.com. You can also reach out through our contact page.
15. Data controller, DPO, and supervisory authority
The following disclosures are required under the GDPR and India's DPDP Act. They are being finalised with counsel and will be completed before general availability:
- Data controller. [Legal entity name and registered address — to be confirmed].
- Data Protection Officer (DPO). [Name / contact — to be confirmed]. Interim contact: support@lifewyn.com.
- Grievance Officer (India DPDP Act). [Name and contact — to be confirmed]. Interim contact: support@lifewyn.com.
- Supervisory / data-protection authority. If you are in the EU/EEA, you have the right to lodge a complaint with your local supervisory authority; in India, with the Data Protection Board once constituted. [Named authority — to be confirmed].