How Aftr Limited collects, uses, and protects your personal information. Includes CCPA rights for California residents.
Aftr Limited (“Aftr”, “we”, “our”) is a New Zealand company (Company No. 9429120) that operates the Aftr service at app.useaftr.com and useaftr.com. We provide a digital estate planning tool for individuals.
This policy explains what personal information we collect, why we collect it, who we share it with, and your rights. It also includes a specific section for California residents explaining your rights under the California Consumer Privacy Act (CCPA / CPRA).
This policy is governed by New Zealand law and applies to users accessing Aftr from anywhere in the world.
When you register, we collect your name, email address, and a hashed form of your password (using industry-standard adaptive hashing). Your password is never stored in readable form. We also store an optional date of birth if you provide one. We collect the country you select at signup (a self-declared dropdown on this site) and an approximate country derived from your network connection (via a Cloudflare geo header processed server-side). This is used to route your account to the correct regional service and determine which legal requirements and features apply to you. It is not used for advertising.
Your Vault stores credentials, identity documents, notes, files, Bookshelf entries, Letters, and Life Story content. All Vault content is encrypted with AES-256-GCM before it reaches our servers using a key derived from your password on your device. While you are alive, we cannot read your Vault contents. After your death, the vault can be released to your chosen executor only after a guardian quorum of 3 of 5 confirms your passing and a dispute window closes.
If you use the Life Story feature, we collect voice recordings, photos, scrapbook entries, and text entries you create. These are sent to OpenAI for transcription or story generation (see below), then encrypted and stored on our servers.
When you add a guardian or executor, we store their name and email address to send invitations and notifications.
Names, relationships, and optionally email addresses and dates of birth for family members you add.
Payments are processed by Stripe. We do not store card numbers or full payment details. We store only a Stripe customer ID and subscription ID.
If you submit your email address on our website via the interest capture form, we store your email address to send you product updates. You can unsubscribe at any time.
We log IP addresses, browser/device type, and actions taken in the app for security and compliance. Anonymised audit log entries are retained for 7 years. Raw IP address and device data is retained for 90 days, then anonymised.
We may derive inferences about your preferences from your use of the service (for example, feature engagement patterns). These are used only for product improvement via PostHog analytics and are not used for profiling or advertising.
Your Vault encryption key is derived from your master password on your own device. This key is never transmitted to our servers. While you are alive, Aftr cannot read your Vault or Life Story content.
This has an important consequence: if you forget your master password, your recovery phrase is the only way to restore access while you are alive. We do not hold a copy of your key, so we cannot reset it. Without your password or recovery phrase, your Vault content cannot be accessed while you are alive.
After your death, and only after a quorum of 3 of 5 of your chosen guardians independently confirms your passing and a 72-hour dispute window closes, the vault key can be reconstructed so your executor can access the estate. This release process is controlled entirely by your guardians. Aftr does not initiate it.
The Life Story feature uses OpenAI for voice transcription and AI story generation. By using these features, your voice recordings and transcript content leave our servers and are processed by OpenAI in the United States.
You can use written Life Story entries without any data being sent to OpenAI.
We use PostHog (US Cloud) for product analytics on our website and app. PostHog uses cookies and local storage to track sessions and page interactions. We also use PostHog feature flags to manage which features are visible to which users.
We use Sentry for error monitoring. Sentry may capture browser type, page URL, and error context.
We use Betterstack for uptime monitoring. Betterstack does not receive personal data.
If you submit your email address via the interest capture form, we will add it to our mailing list via Resend and send a short series of product update emails (currently three emails over approximately 14 days). Each email includes a one-click unsubscribe. You can unsubscribe at any time.
Transactional emails (account verification, guardian invitations, attestation notifications, password reset) cannot be unsubscribed from as they are essential to service delivery.
We use the personal information we collect to:
We do not sell personal information to third parties for their own marketing purposes.
Access restrictions: Aftr uses IP-derived location data (processed by Cloudflare) to block access from certain regions, including the European Union, United Kingdom, Switzerland, and countries subject to international sanctions. This processing is carried out for security and legal compliance purposes and does not result in personal information being stored about the visitor.
When 3 or more of your guardians attest to your death, the service enters a 72-hour dispute window. After this window, your designated executor receives a single-use access token by email. The executor does not need an Aftr account.
Access via the executor token is logged. The Bookshelf ON_DEATH auto-release feature is currently disabled and will not be activated without a further update to this policy.
The New Zealand Privacy Act 2020, which governs this service, protects the personal information of living individuals. It does not give the same rights over the information of someone who has died. Even so, we treat a deceased user’s information with care, because it is sensitive and because it belongs, in substance, to the family and estate they left it for.
When we confirm that a user has died, through our guardian attestation process, we release the information that user chose to leave to the executor they named. We do this because the user, while alive, set up Aftr and named that executor precisely so this release would happen.
We keep the released information only for a limited period after release, so the executor can access and act on it, and then we delete it.
If you are an executor, or you are administering the estate of someone who used Aftr, you can contact us at the address in the “Contact us” section about the information we hold or have released.
Aftr users can name other people as their guardians (who help confirm important events and recover access) or as their executor (who may receive the information the user chose to leave). When a user names you, they give us your name and email address so we can invite you and contact you when needed. We hold only your name and email for this purpose. We did not collect this information from you directly; the user who named you provided it.
You have rights over this information. You can ask us what we hold about you, ask us to correct it, and ask us to remove you so we no longer hold or contact you. To do any of these, contact us at the address in the “Contact us” section. Removing yourself as a guardian or executor may affect the account owner’s setup, and where appropriate we will let them know that you have asked to be removed.
Subscription lapse does not trigger deletion. Your data is preserved unless you explicitly delete your account. See the Terms of Service for the 30-day recovery window.
When you join as a Founding Member, your price is locked for the life of your plan. Founding Member status is non-transferable and attached to your account. No additional personal data is collected for this program beyond your subscription date.
You have the right to:
To exercise these rights, email us at [email protected]. We will respond within 45 days.
We collect the above categories for the purposes described in “How we use your data” above: service delivery, billing, security, and analytics.
No. Aftr does not sell personal information to third parties.
No. Aftr does not use advertising trackers or share personal information with any third party for cross-context behavioural advertising. We use PostHog for product analytics only.
Submit a request by emailing [email protected] with “California Privacy Request” in the subject line. For logged-in users, the data export and account deletion tools in your account settings are the most direct way to exercise your right to know and right to delete. We will respond within 45 days. We may extend this by an additional 45 days where reasonably necessary.
We will verify your identity before processing requests. Logged-in users can verify identity via their account. For non-account requests, we may ask you to confirm the email address associated with any inquiry we have from you.
Your encrypted vault is stored on AWS infrastructure in the region appropriate to your market. The contents of your vault are encrypted on your own device before they reach us, so what we hold is ciphertext we cannot read.
To run the service we use a small number of specialist providers, some of which are based in the United States. This means your account metadata, product analytics, error logs, the emails we send you, and any text you choose to send to our AI Life Story feature are processed by those overseas providers. We list them, and what each one receives, in the table above. Your encrypted vault itself is not sent to any of them.
By using Aftr, you acknowledge that your personal information may be transferred to and processed in countries outside your country of residence, including New Zealand and the United States.
Our security measures include AES-256-GCM encryption for vault content (key derived on your device, not held by Aftr), industry-standard adaptive password hashing, TLS in transit, passkey-first authentication (WebAuthn), and AWS encryption at rest. If we confirm a notifiable privacy breach, we will notify affected users by email as soon as practicable after we become aware of it.
If you are located in Australia, your privacy rights are also protected under the Australian Privacy Act 1988 and the Australian Privacy Principles. You may direct complaints to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the effective date above.