Privacy Policy
Last updated: June 27, 2026
At KinCoffer, your privacy isn’t a setting — it’s the foundation. This policy explains what we collect, how we use and protect it, and the control you keep over your information when you use KinCoffer (the “service”).
1. Information We Collect
We collect only what we need to provide KinCoffer and keep your account secure.
Information you give us
- Account details — your name, email address, and password (stored only as a salted hash, never in plain text).
- Vault content — the messages, documents, wishes, directives, and other materials you add. This content is encrypted (see “Encryption & Your Privacy” below).
- People you designate — the names and contact details of recipients, family members, and executors you choose to share with.
- Verification materials — where applicable, documents (such as a death certificate) submitted to verify a passing before any content is released.
- Payments — if you subscribe to a paid plan, billing is handled by our payment processor; we receive limited transaction data and never store full card numbers.
Information we collect automatically
- Security and audit logs — sign-ins, vault unlocks, and other privileged actions, with timestamps and approximate origin (IP, user agent), to protect your account.
- Device and usage data — basic, aggregated information needed to operate and improve the service.
2. How We Use Your Information
We use your information to:
- Provide, maintain, and secure your account and vault;
- Verify identity and, where you have configured it, verify a passing before releasing content;
- Deliver your designated content to the people you have chosen, at the time you have specified;
- Send essential service communications (security alerts, verification, and account notices);
- Detect, prevent, and respond to fraud, abuse, and security incidents; and
- Comply with our legal obligations.
We do not sell your personal information, and we do not use your vault content for advertising or to train models.
3. Encryption & Your Privacy
Privacy is the product. Your vault content is encrypted at rest with AES-256-GCM using a key derived from your passphrase (PBKDF2). Your passphrase is never stored, and recovery keys are entrusted only to the recovery contacts you choose — never to us.
Because of this design, KinCoffer cannot read your vault content, reset your passphrase, or recover your data without you or your designated recovery contacts. This is intentional: it is what keeps your most personal materials private, even from us.
Keep your passphrase and recovery contacts safe. If you lose your passphrase and all recovery options, your encrypted content cannot be recovered by anyone — including us.
5. Data Security
We apply industry-standard technical and organizational safeguards, including:
- Encryption of data in transit (TLS) and at rest;
- Vault content encrypted with a key derived from your passphrase;
- Multi-factor authentication and account-lockout protections;
- Least-privilege access controls and audit logging of privileged actions; and
- Regular review of our security posture.
No method of transmission or storage is ever completely secure. While we work hard to protect your information, we cannot guarantee absolute security.
6. Your Privacy Rights
Depending on where you live (including under the GDPR and CCPA/CPRA), you may have the right to:
- Access the personal information we hold about you;
- Export your data in a portable format;
- Correct inaccurate information;
- Delete your account and associated data; and
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
You can export or delete your data at any time from Settings → Privacy in the app, or by contacting us at privacy@kincoffer.com. We will not discriminate against you for exercising these rights.
7. Data Retention & Posthumous Release
We keep your information for as long as your account is active, and as needed to provide the service and meet legal obligations.
When you delete your account, we begin deletion after a short grace period (currently 30 days) during which you can sign back in to cancel. After that, your encrypted content and personal data are deleted from active systems, subject to limited retention required for legal, security, or backup purposes.
Because KinCoffer is designed for end-of-life planning, your account may continue to hold content until a passing is verified and your designated content is released according to your instructions. You remain in control of these settings while your account is active.
8. International Data Transfers
We may process and store information in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.
10. Children's Privacy
KinCoffer is intended for adults and is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us and we will delete it.
11. Important Disclaimer
KinCoffer is a private place to organize and store your wishes, messages, and documents. It is not a law firm, financial adviser, or medical provider, and it does not provide legal, financial, or medical advice. KinCoffer does not draft, witness, notarize, or execute wills or other legal instruments. For legally binding documents, consult a qualified professional in your jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
Questions about this policy or your data? Contact our privacy team at privacy@kincoffer.com, or our security team at security@kincoffer.com.
KinCoffer is the controller responsible for your personal data, governed by the laws of the State of Delaware, United States.