Privacy Policy
Last updated: April 5, 2026
What We Collect
We collect the information you provide when creating your legacy plan: your name, email address, and the content you choose to preserve (letters, wishes, documents, and personal milestones). We also collect payment information through our payment processor, Authorize.net.
How We Use Your Data
Your data is used solely to provide the Last Wish service — storing your legacy plan, delivering sealed letters according to your instructions, and communicating with you about your account. We do not sell, share, or monetize your personal data.
Encryption & Storage
All data is encrypted in transit (TLS) and at rest. Your vault content is stored in secure, access-controlled databases. Document uploads are stored in private cloud storage accessible only to authenticated users. We use Railway (PostgreSQL) for structured data and Vercel Blob for file storage.
Third-Party Services
We use the following services to operate Last Wish:
- Vercel — hosting and deployment
- Railway — database hosting
- Resend — transactional email delivery
- Authorize.net — payment processing
Each service processes only the minimum data necessary and is bound by their own privacy policies.
Your Rights
You have the right to access, export, correct, and delete your data at any time. You can export your entire legacy plan as a JSON file from Settings. You can delete your account permanently from Settings, which removes all data within 30 days.
Cookies
We use a single essential cookie (auth_token) to maintain your session. This cookie is httpOnly, secure, and cannot be accessed by JavaScript. We do not use analytics, tracking, or advertising cookies.
Data Retention
Your data is retained as long as your account is active. After account deletion, all data is permanently removed within 30 days. Cancelled accounts retain data for 90 days before deletion.
Children
Last Wish is not intended for users under 18 years of age.
Contact
For privacy-related questions, contact us at privacy@solivana.ai.