Privacy policy

Updated 9 September 2026

Asset.Family holds what usually sits in a home safe: property documents, heirs' shares, instructions in case of illness. So we describe our handling of data in detail — including what we do not do.

The short version

  • We do not sell data and we do not pass it to advertisers or data brokers.
  • There is not a single third-party counter, tracker or advertising pixel on the site.
  • Everything in the registry is entered by you. We pull nothing from banks, public registries or any external source.
  • We do not use end-to-end encryption: records are stored in the database in readable form, otherwise the service could not calculate shares or assemble documents. That means we do have technical access to them.

What data we process

The data falls into three groups: what is needed to sign in, what you enter yourself, and what arises as the service runs.

  • Account: email address, an irreversible password hash, time zone, account status, creation and update dates.
  • Registry content: assets of every type and their parameters, liabilities, insurance policies, operations and expenses on assets, persons, ownership and inheritance shares.
  • Documents: the files you upload — scans of contracts, receipts, invoices, photographs, correspondence.
  • Legal documents: wills, financial powers of attorney, healthcare directives and the emergency envelope, together with their text.
  • Life chronicle: the events you chose to record — birth, education, marriages, children, relocations, citizenships and residence permits, passports.
  • Technical information: the identifier of the device you signed in from, the date of activity, the time zone and the country.

Special category data

Some information is given stronger protection by law. In Asset.Family that is the healthcare directive — your decisions on resuscitation, life support, pain relief and organ donation — and certain chronicle events: criminal convictions and their expungement, sanctions imposed, a change of religion.

We do not ask for this information and the service does not need it to work. It appears in the system only if you decided to enter it, and the basis for processing is your explicit consent expressed by that action. You can withdraw it by deleting the record.

Why we process it

  • To show you your registry, calculate sums and shares and lay out the distribution among heirs.
  • To assemble the will, the power of attorney, the healthcare directive and the emergency envelope from your own records and hand them back as PDFs.
  • So that you can sign in, and the service can tell your devices apart and end a session on a particular one.
  • To send the confirmation code at registration and the link when you reset your password.
  • To understand how many people use the service: we keep the date of activity, the time zone and the country — with no history of what you viewed or did inside your account.

How it is stored and what we do to protect it

The measures are described as they are implemented, without embellishment.

  • The connection to the service runs over HTTPS.
  • The password is not stored. The database holds an irreversible hash produced by Argon2: the password cannot be recovered from it, only replaced.
  • The session refresh token is likewise stored as a hash and bound to the device identifier.
  • Uploaded files sit in object storage and are served through a signed link with a limited lifetime, not from a permanent public address.
  • Registry records are stored in the database in readable form. The service has no client-side and no end-to-end encryption.

One thing follows from that last point: staff with administrative access can technically reach the contents of an account. Such access exists to operate and support the service, but we think it would be dishonest to claim it does not exist at all.

Who we share data with

We do not sell data, do not pass it to advertising networks or data brokers, and do not use it to train models. It is handled only by the providers without which the service would not run.

  • The hosting and infrastructure provider the service runs on.
  • The object storage that holds the files you upload.
  • The mail server that sends the confirmation code and password reset messages. Those carry the recipient's address and the text of the message.

We may disclose data on a lawful request from a competent authority. Since there is no end-to-end encryption, we also have no technical means of answering such a request with empty content.

How long we keep data

Registry records, uploaded documents and legal documents are kept for as long as your account exists. You can delete an individual record — an asset, a person, a chronicle event, the emergency envelope — at any time.

There is no self-service deletion of an entire account yet. We consider that a shortcoming and are not hiding it.

Your rights

If European data protection law applies to you, you have the right to obtain a copy of your data, correct inaccuracies, request erasure, restrict or object to processing, and withdraw consent to the processing of special category data.

Some of these rights are exercised manually today rather than by a button in the interface: there is no single-file export of all your data in the service yet.

Children

The service is intended for adults. We do not create accounts for children and do not knowingly collect their data. You may enter a child as a person or an heir — you enter that information as an adult user and you are responsible for it.

Changes to this policy

We change this document when the service changes. The date of the last change is shown at the top of this page. If a change materially affects your rights, we will tell you before it takes effect.