Security
A vault is a target. A map is not.
We designed this product so that a total breach of our database would still not unlock a single one of your accounts.
What we store
- Account name and category
- Provider and login identifier
- Where the password is kept (safe, manager, notebook)
- Which sign-in and recovery methods are turned on
- What you want done with the account
- Who your trusted people are
What we never store
- Passwords, PINs, or passcodes
- One-time codes or authenticator secrets
- Recovery codes or seed phrases
- Private keys or wallet backups
- Card numbers or account balances
- Copies of your documents
It is enforced by the schema, not by policy
There is no password column, no PIN column, no recovery-code column and no seed-phrase column anywhere in our database. We could not store your secrets without redesigning the product. Where a password lives is recorded as a location — "1Password", "the safe", "the green notebook" — never as a value.
Your data is isolated to your account
Every row we keep is tied to your user ID and readable only by you. There is no shared workspace, no team access, and no support tool that browses your inventory. We test this isolation directly: a second account must see zero of your rows and be denied every write.
Hints are not secrets
You can leave a short hint for your trusted person — "same pattern as the one in the estate binder", "ask Mom about the safe". We check that field as you type and block anything that looks like an actual secret: long random strings, six-digit codes, twelve or twenty-four word phrases.
How access actually works for your family
Under RUFADAA, the Revised Uniform Fiduciary Access to Digital Assets Act adopted with variations in most US states, there is an order of authority: a platform's own online tool first, then your will or power of attorney, then the platform's terms of service. Because the platform tools win, we push you to set them up first — Google Inactive Account Manager, Apple Legacy Contact, Facebook Legacy Contact. They are free, and no third-party product can override them.
Platform terms can still limit what a designated contact receives. Some services release account data but never message contents, and some never release anything without a court order. Your printed plan is what makes those conversations possible at all.
What we deliberately do not build
No encrypted secret vault. No automatic release on death, because we cannot verify a death honestly and a self-attested trigger invites fraud and coercion. No death-certificate workflow we would have to staff. The handoff is physical and human: you decide, you print, you hand it over.
You can leave with everything
Export your map as JSON at any time, and delete your account and every row tied to it in one action. If DigitalLifeMap ever shut down, you would still hold your printed plan and your export — and because we never held a secret, nothing of yours would be trapped here.