Privacy Policy
Last updated: July 14, 2026
1. Who we are and scope
This Privacy Policy explains how DoneAfter (“DoneAfter,” “we,” “us”) collects, uses, discloses, and protects personal information when you use DoneAfter.com and related services (the “Service”). It applies to account holders, trusted contacts using portals, visitors, and people who contact us.
Related documents: Terms of Service, Security Policy, Data Deletion Policy, Executor Verification Policy, and Mail Fulfillment Policy.
2. Information we collect
2.1 You provide
- Account & profile: name, email, phone, timezone, password (stored hashed), optional profile details.
- Legacy content: messages, letters, documents, digital-asset notes, business/crypto instructions, AI identity policy settings, timelines, checklists, and similar User Content.
- Trusted circle: contact names, relationships, emails, phones, mailing addresses, roles, permissions, and invite status.
- Billing: plan selection and payment-related identifiers processed via our payment provider (we do not store full card numbers on our servers).
- Gifts After: gift selections, recipient details, scheduling/trigger choices, delivery notes, and fulfillment status.
- Support & reports: messages you send us, impersonation reports, dispute materials, and uploaded evidence.
2.2 Trusted contacts and recipients provide
When a contact accepts an invite, submits a trigger, uploads evidence, votes on an approval, or accesses a released item, we process identity, contact, and activity data needed for that role.
2.3 Automatically collected
- Device/browser type, IP address, approximate location (best-effort), pages viewed, referrers, and timestamps.
- Security telemetry: login history, session/device identifiers, rate-limit events, emergency-code attempt logs, and audit events.
- Operational cookies necessary for authentication and CSRF protection.
2.4 Sensitive categories
Depending on what you store, User Content may include sensitive personal data (e.g., family details, health-related funeral wishes, financial instructions). You decide what to upload. We apply heightened technical controls described in the Security Policy.
3. How we use information
- Provide, maintain, and improve the Service
- Authenticate users and contacts; secure accounts; detect abuse and fraud
- Send transactional email (verification, invites, check-in reminders, release notices — typically secure links, not sensitive bodies)
- Execute release rules, verification reviews, approvals, and staged releases
- Generate letter PDFs, manage print/mail queues, and fulfill Gifts After orders
- Process payments and subscriptions
- Provide customer support and investigate disputes
- Comply with law, enforce Policies, and protect rights and safety
- Produce de-identified or aggregated analytics that do not reasonably identify you
We do not sell your personal information. We do not use your legacy content for advertising.
4. Legal bases (where applicable, e.g. GDPR)
Where required, we process personal data based on: (a) performance of a contract with you; (b) our legitimate interests in operating a secure legacy platform, preventing fraud, and improving the Service (balanced against your rights); (c) compliance with legal obligations; and/or (d) consent where we request it (e.g., optional communications).
5. How we share information
- According to your rules: after verification and release conditions are met, with trusted contacts and recipients you designate, via secure access mechanisms.
- Service providers: hosting, email delivery, payment processing, and (if enabled) mail/fulfillment partners — under confidentiality and processing obligations.
- Professional advisors: legal, accounting, or security advisors under confidentiality.
- Legal and safety: when required by law, legal process, or to protect DoneAfter, users, or the public from harm or fraud.
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to continued protection of personal information.
Administrators accessing private content for support or verification must do so under restricted procedures with justification and audit logging.
6. International transfers
We may process data in the United States or other countries where we or our providers operate. Where required, we use appropriate safeguards for cross-border transfers.
7. Retention
We retain personal information while your account is active and as needed to provide the Service, resolve disputes, enforce agreements, secure the platform, and meet legal obligations. After deletion requests, we follow the Data Deletion Policy, including grace periods, legal holds, and backup rotation.
Security and audit logs may be retained longer where necessary for security, fraud prevention, and compliance.
8. Security
We implement technical and organizational measures described in our Security Policy, including encryption in transit, encryption at rest for sensitive fields/files, hashed passwords, access controls, private file storage, signed expiring links, and audit logging. No method of transmission or storage is 100% secure; you also play a role by using strong authentication and careful content choices.
9. Your rights and choices
Depending on your location (including under GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have rights to:
- Access and receive a copy of personal information
- Correct inaccurate data
- Delete data (subject to legal exceptions and holds)
- Export/port data in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Opt out of “sale” or “sharing” for cross-context behavioral advertising — we do not sell personal information or use it for such advertising
- Appeal or lodge a complaint with a supervisory authority
To exercise rights, use in-account tools where available or open a ticket via Contact / Support. We may verify your identity before fulfilling requests. Authorized agents may submit requests where law allows, with proof of authority.
California residents: We do not sell personal information. You may request know/access, delete, and correct rights as described above. We will not discriminate against you for exercising privacy rights.
10. Cookies and similar technologies
We use strictly necessary cookies/session storage to keep you signed in and protect forms (CSRF). We do not use third-party advertising cookies. If we add optional analytics cookies in the future, we will update this Policy and provide choices where required.
11. Children’s privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from children for account registration. If you believe a child provided information, contact us to delete it.
12. Do Not Track
There is no consistent industry standard for Do Not Track signals. We treat privacy as described in this Policy regardless of DNT headers.
13. Changes
We may update this Policy by posting a revised version with a new “Last updated” date. Material changes may be communicated by email or in-product notice where appropriate.
14. Contact
Privacy requests and questions: Contact or member Support tickets.