Legal
Privacy Policy
Last updated: August 4, 2026
Introduction
Recivity is an encrypted vault with a dead-man switch. You store critical information encrypted in your browser, check in on a schedule, and if you go silent, trusted beneficiaries can unlock access. This Privacy Policy describes what information we collect and how we use it.
Information we collect
Account information: name, email address, and a password hash if you register with email and password. If you sign in with Google or Facebook, we receive that provider’s profile name, email, and profile image.
Vault information: encrypted document ciphertext, an owner wrap secret used to unlock the vault while you are signed in, recovery question text, beneficiary names, email addresses, and optional phone numbers, check-in timestamps, and escalation logs (reminder and release notifications).
We do not collect or store document plaintext or recovery answer text. Those stay on your device or are derived only in the browser for encryption and decryption.
How we use information
We use account and vault metadata to authenticate you, operate check-in reminders and release notifications, and maintain vault state (active, warning, or released).
We do not sell your personal information.
Social login (Google and Facebook)
If you continue with Google, Google shares profile information with us according to your Google account settings and Google’s policies. See the Google Privacy Policy for how Google handles your data.
If you continue with Facebook, Meta shares profile information with us according to your Facebook account settings and Meta’s policies. See the Meta Privacy Policy for how Meta handles your data.
Third-party services
We use Vercel for hosting, Neon for Postgres database storage, and Resend for transactional email (check-in reminders and release notices). Those providers process data under their own privacy policies.
Data security
Vault documents are encrypted in the browser with AES-GCM before upload. A random document key is wrapped with a key derived from an owner wrap secret stored with your account (so you can unlock while signed in) and separately with a key from recovery answers (for beneficiaries after release).
Because the owner wrap secret is stored with the ciphertext, anyone with access to the database can decrypt vault contents as the owner. Recovery answers are not stored and remain the end-to-end path for beneficiaries. You are responsible for protecting your account credentials.
Data retention
We keep your account and vault data while your account is active. If you want your data deleted, contact us at the address below. Self-serve account deletion is not available in the current version of the product.
Your rights
You may request access to or deletion of your account data by emailing us. We will respond within a reasonable time.
Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Continued use of Recivity after a change means you accept the updated policy.
Contact
Questions about this Privacy Policy: admin@recivity.com.
Disclaimer
This document is for informational purposes only and is not legal advice. It is an MVP draft and has not been reviewed by an attorney.