Privacy

What we collect, why we collect it, and what we never do with it.

Last updated: 2026-06-02. Compliant with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

Privacy policy

What we collect, why we collect it, and what we never do with it.

Last updated: 2026-06-02. Compliant with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

↓ Download as PDF

1. What we collect

  • Account: email, name, password hash (argon2id), 2FA secret (if enabled), Google OAuth ID (if used).
  • Will Registry: testator legal name, aliases, date signed, location of original, executor name & encrypted contact, registering lawyer / firm.
  • Treasure Map: asset descriptions stored in our database.
  • Sensitive secrets: PINs, recovery phrases, account numbers, document blobs — stored in FutureVault, never in our database.
  • Telemetry: server logs (IP, user-agent, timestamp), error reports.
  • Payments: handled by Stripe — we receive only the last 4 digits and brand of your card.

2. Why we collect it

To operate the service: register your will, persist your Treasure Map, verify executors, render the executor PDF, generate the Estate Plan™, calculate commissions for lawyers, route per-search results, and comply with applicable law.

3. Who we share it with

  • Sub-processors: FutureVault (encrypted storage), Resend (transactional email), Stripe (payments), OpenAI (optional realtime voice), Anthropic (AI assistant), our cloud hosting provider (Vercel) and database (Neon).
  • Your lawyer: only those Treasure Map items you explicitly toggle on for them.
  • Your executor: only after the executor unlock flow completes.
  • Sponsors: Barrett Tax Law and Donsky & Donsky receive your contact details only if you explicitly request a consultation.
  • Authorities: where compelled by valid legal process. We notify you where lawfully permitted.

4. International transfers

Our primary infrastructure is in Canada. Some sub-processors may store copies of metadata in the United States. We rely on contractual safeguards consistent with PIPEDA.

5. Retention

Active accounts: retained while active. Deleted accounts: erased within 30 days, except for audit records held under a minimum legal retention. Will Registry entries: retained while marked active or until you mark them superseded.

6. Your rights under PIPEDA

You may access your personal information, correct inaccuracies, withdraw consent where consent is the legal basis, and request deletion subject to legal retention. Contact privacy@lasttreasuremap.com.

7. Cookies and tracking

We use strictly-necessary cookies for authentication and CSRF protection, and a small set of first-party analytics cookies to understand how the service is used. We do not run third-party ad-network trackers.

8. Children

The service is not directed at people under 18. We do not knowingly collect data from minors.

9. Breach notification

If we detect a material data breach affecting your personal information, we notify you within 72 hours by email and, where required, notify the Office of the Privacy Commissioner.

10. Contact

For any privacy question, email privacy@lasttreasuremap.com.

Want a copy? Download this privacy policy as a PDF.

Privacy by default.
Your data is yours.
Security details