← Back

Privacy Policy

Last updated: April 5, 2026

What We Collect

We collect the information you provide when creating your legacy plan: your name, email address, and the content you choose to preserve (letters, wishes, documents, and personal milestones). We also collect payment information through our payment processor, Authorize.net.

How We Use Your Data

Your data is used solely to provide the Last Wish service — storing your legacy plan, delivering sealed letters according to your instructions, and communicating with you about your account. We do not sell, share, or monetize your personal data.

Encryption & Storage

All data is encrypted in transit (TLS) and at rest. Your vault content is stored in secure, access-controlled databases. Document uploads are stored in private cloud storage accessible only to authenticated users. We use Railway (PostgreSQL) for structured data and Vercel Blob for file storage.

Third-Party Services

We use the following services to operate Last Wish:

Each service processes only the minimum data necessary and is bound by their own privacy policies.

Your Rights

You have the right to access, export, correct, and delete your data at any time. You can export your entire legacy plan as a JSON file from Settings. You can delete your account permanently from Settings, which removes all data within 30 days.

Cookies

We use a single essential cookie (auth_token) to maintain your session. This cookie is httpOnly, secure, and cannot be accessed by JavaScript. We do not use analytics, tracking, or advertising cookies.

Data Retention

Your data is retained as long as your account is active. After account deletion, all data is permanently removed within 30 days. Cancelled accounts retain data for 90 days before deletion.

Children

Last Wish is not intended for users under 18 years of age.

Contact

For privacy-related questions, contact us at privacy@solivana.ai.