Skip to main content

Privacy Policy

Last updated: June 27, 2026

At KinCoffer, your privacy isn’t a setting — it’s the foundation. This policy explains what we collect, how we use and protect it, and the control you keep over your information when you use KinCoffer (the “service”).

1. Information We Collect

We collect only what we need to provide KinCoffer and keep your account secure.

Information you give us

  • Account details — your name, email address, and password (stored only as a salted hash, never in plain text).
  • Vault content — the messages, documents, wishes, directives, and other materials you add. This content is encrypted (see “Encryption & Your Privacy” below).
  • People you designate — the names and contact details of recipients, family members, and executors you choose to share with.
  • Verification materials — where applicable, documents (such as a death certificate) submitted to verify a passing before any content is released.
  • Payments — if you subscribe to a paid plan, billing is handled by our payment processor; we receive limited transaction data and never store full card numbers.

Information we collect automatically

  • Security and audit logs — sign-ins, vault unlocks, and other privileged actions, with timestamps and approximate origin (IP, user agent), to protect your account.
  • Device and usage data — basic, aggregated information needed to operate and improve the service.

2. How We Use Your Information

We use your information to:

  • Provide, maintain, and secure your account and vault;
  • Verify identity and, where you have configured it, verify a passing before releasing content;
  • Deliver your designated content to the people you have chosen, at the time you have specified;
  • Send essential service communications (security alerts, verification, and account notices);
  • Detect, prevent, and respond to fraud, abuse, and security incidents; and
  • Comply with our legal obligations.

We do not sell your personal information, and we do not use your vault content for advertising or to train models.

3. Encryption & Your Privacy

Privacy is the product. Your vault content is encrypted at rest with AES-256-GCM using a key derived from your passphrase (PBKDF2). Your passphrase is never stored, and recovery keys are entrusted only to the recovery contacts you choose — never to us.

Because of this design, KinCoffer cannot read your vault content, reset your passphrase, or recover your data without you or your designated recovery contacts. This is intentional: it is what keeps your most personal materials private, even from us.

Keep your passphrase and recovery contacts safe. If you lose your passphrase and all recovery options, your encrypted content cannot be recovered by anyone — including us.

4. How and When We Share Information

With the people you choose

Content is shared only with the recipients, family members, and executors you designate — and only on the terms you set (immediately, or only after a verified passing).

With service providers

We use carefully selected vendors to run the service (for example, cloud hosting, database, email delivery, and payment processing). They may process information only on our instructions and under contractual confidentiality and security obligations.

For legal and safety reasons

We may disclose information if required by law, or where we believe in good faith it is necessary to comply with legal process or to protect the rights, safety, and security of our users, the public, or the service.

We do NOT

  • Sell or rent your personal information;
  • Share your vault content with advertisers; or
  • Use your content to train artificial-intelligence models.

5. Data Security

We apply industry-standard technical and organizational safeguards, including:

  • Encryption of data in transit (TLS) and at rest;
  • Vault content encrypted with a key derived from your passphrase;
  • Multi-factor authentication and account-lockout protections;
  • Least-privilege access controls and audit logging of privileged actions; and
  • Regular review of our security posture.

No method of transmission or storage is ever completely secure. While we work hard to protect your information, we cannot guarantee absolute security.

6. Your Privacy Rights

Depending on where you live (including under the GDPR and CCPA/CPRA), you may have the right to:

  • Access the personal information we hold about you;
  • Export your data in a portable format;
  • Correct inaccurate information;
  • Delete your account and associated data; and
  • Object to or restrict certain processing, and withdraw consent where processing is based on consent.

You can export or delete your data at any time from Settings → Privacy in the app, or by contacting us at privacy@kincoffer.com. We will not discriminate against you for exercising these rights.

7. Data Retention & Posthumous Release

We keep your information for as long as your account is active, and as needed to provide the service and meet legal obligations.

When you delete your account, we begin deletion after a short grace period (currently 30 days) during which you can sign back in to cancel. After that, your encrypted content and personal data are deleted from active systems, subject to limited retention required for legal, security, or backup purposes.

Because KinCoffer is designed for end-of-life planning, your account may continue to hold content until a passing is verified and your designated content is released according to your instructions. You remain in control of these settings while your account is active.

8. International Data Transfers

We may process and store information in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.

9. Cookies & Analytics

We use essential cookies needed to sign you in and keep the service secure. We do not use advertising cookies or sell data to advertisers. Any product analytics we use are limited to operating and improving the service, and are described in our in-app cookie notice.

10. Children's Privacy

KinCoffer is intended for adults and is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us and we will delete it.

11. Important Disclaimer

KinCoffer is a private place to organize and store your wishes, messages, and documents. It is not a law firm, financial adviser, or medical provider, and it does not provide legal, financial, or medical advice. KinCoffer does not draft, witness, notarize, or execute wills or other legal instruments. For legally binding documents, consult a qualified professional in your jurisdiction.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

Questions about this policy or your data? Contact our privacy team at privacy@kincoffer.com, or our security team at security@kincoffer.com.

KinCoffer is the controller responsible for your personal data, governed by the laws of the State of Delaware, United States.