Privacy Policy
We store sensitive details of your life. You deserve to know what we collect, how we protect it, and what we will never do with it.
The plain-English version: we collect the information you give us to build your portfolio. We use it to run your account and, when configured conditions are met, help deliver the right parts of your plan to your designated people. We never sell your vault content. We do not give it to advertisers. The vault data your family may eventually need is protected and released only through the process you configure.
1. What we collect
Information you give us directly
When you create an account and complete the onboarding wizard, you may provide personal information including your name, date of birth, state of residence, citizenship status, contact details, family structure, health care preferences, asset and account inventory, digital account details, letters, and planning preferences. You may also upload documents such as wills, deeds, insurance policies, photographs, and other files to your vault.
The level of sensitivity varies by chapter. Early chapters collect basic identity and preference data. Later chapters can include financial accounts, legal documents, and recovery-location pointers. The wizard labels sensitive fields by tier so you can understand what will be released under each configured condition.
Payment information
Purchases and subscription management use Stripe-hosted Checkout and your customer portal. Payment details are entered directly on Stripe's hosted pages. AscenVent does not receive or store full card numbers or card security codes.
To operate and reconcile billing, AscenVent receives and stores relevant Stripe identifiers and billing records, such as customer, checkout, subscription, invoice, charge, refund, and dispute identifiers; status and timestamps; selected products and prices; tax-exclusive totals, taxes, discounts, amounts paid or refunded; and invoice or receipt links. Stripe may also process billing contact, address, tax-identification, device, and fraud-prevention information that you provide to its hosted pages.
Information we collect automatically
Hosting, database, email, and security systems may process standard request information such as IP address, browser or device details, timestamps, and application events needed to operate, secure, and troubleshoot the service. The current product does not use vault content for advertising.
2. How we use it
We use the information you provide to:
- Build and maintain your portfolio across the seven chapters.
- Save your progress, generate exports, and let you return to your account.
- Deliver configured information to designated people when release conditions are met.
- Send check-in reminders, review notifications, transactional emails, and account notices.
- Match you with local vendors when you request or opt in to an introduction.
- Respond to support requests and answer questions about your account.
- Operate, secure, and reconcile Stripe billing for complete authenticated accounts.
- Comply with legal obligations and protect the security of the platform.
We do not use your vault content to train AI models. We do not use your personal information for targeted advertising. We do not build behavioral profiles to sell to third parties.
3. How we store and protect it
AscenVent is built around a security-first posture. The current implementation includes application-layer AES-256-GCM encryption for saved wizard answers before they are written to the database, server only access to the encryption key, private owner-scoped document storage, Postgres row-level security, and TLS for production traffic. See the Security page for more detail.
Uploaded documents live in private storage scoped to your account. The platform stores pointers to many high-risk secrets rather than the raw secrets themselves. For example, AscenVent should know where your recovery material is kept, not the recovery seed or master password itself.
4. Who we share it with
We do not sell your personal information. We share it only in these situations.
Service providers
We use a small number of third-party vendors to run the platform, including cloud hosting, database and storage infrastructure, transactional email, and hosted billing surfaces. Current providers include Vercel, Supabase, Resend, and Stripe. They process information needed to provide those services under their applicable terms and privacy notices. Stripe processes payments as described in this policy.
Your designated people
The purpose of your vault is to release specific information to the people you designate under the plan, tier, response-window, evidence, staff-review, and co-sign rules described in the product. You control the beneficiary roster and configured release preferences while your account is active.
Vendor introductions
If you request an introduction to a vendor in our network, such as a funeral home, estate attorney, financial advisor, or grief counselor, we share only the context needed for that introduction, such as your name, contact information, zip code, and the type of help you requested. You initiate these introductions; we do not share your vault content with vendors automatically.
Legal requirements
We may disclose information if required by valid legal process, such as a court order or subpoena. Where legally permitted, we will notify you before complying. We will not disclose sensitive vault content in response to informal requests.
Business transfers
If AscenVent is acquired, merges with another company, or undergoes a similar business transfer, user data may be transferred as part of that transaction, subject to this policy and applicable law. We would provide notice when legally required.
5. The tiered release system and your data
AscenVent's tiered release model controls how your data is organized and released. Your exact configuration depends on your plan and the choices you make in the wizard.
| Tier | Typical contents | Release model |
|---|---|---|
| Tier 1 | Funeral wishes, service preferences, personal letters, contacts to notify, and immediate guidance. | A named person can request access, subject to your configured notice and veto window. |
| Tier 2 | Account inventory, professional contacts, insurance carrier names, and asset descriptions. | Requires supporting evidence and a 72-hour owner response window before release. |
| Tier 3 | Uploaded documents and recovery-location pointers for the most sensitive material. | Requires evidence, a seven-day owner response window, staff approval, and configured Premium co-sign thresholds. |
6. Your rights and choices
- Access. You can view the portfolio information available through your account.
- Export. You can generate a portfolio PDF export to keep, print, or store independently of AscenVent.
- Correction. You can edit fields in your portfolio while your account is active.
- Deletion. The current product does not expose a self-service account deletion control. You can request deletion of your data by .
- Vendor matching. Vendor introductions are opt-in. You can decline any introduction.
- Beneficiary management. You can add, remove, or change named people and access levels while your account is active.
California residents may have additional rights under California privacy law where those laws apply to AscenVent. These can include the right to know categories of personal information collected, request deletion, and opt out of sale or sharing. AscenVent does not sell personal information or share it for cross-context behavioral advertising. To make a privacy request, and note that it is a privacy request.
7. How long we keep it
We keep account and vault data while the account is active and as needed to operate the service. Deletion requests are handled through support and may be subject to backup, security, dispute, and legal retention requirements. The current product does not promise an automatic 30-day deletion workflow.
Signed Stripe webhook payloads are encrypted for reliable processing. After successful processing, their temporary encrypted contents are scheduled to be removed after 30 days while integrity hashes and normalized billing records remain. Retryable or unresolved records may be kept longer to complete recovery. Normalized financial records may be retained longer when needed for security, audit, dispute, tax, or legal obligations.
8. Children
AscenVent is designed for adults. We do not knowingly collect information from anyone under 18. If you believe we have inadvertently collected information from a minor, and we will investigate and respond as required.
The wizard may collect information about your children as dependents in your plan, such as their names, dates of birth, and care arrangements. This is collected from you, the account holder, and is used solely to populate your portfolio.
9. Changes to this policy
We will update this policy as the product and legal landscape evolve. The "Last updated" date at the top of this page reflects the most recent revision. We will provide additional notice when required by applicable law.
10. How to reach us
Questions about your privacy? . If you have a formal privacy rights request, say so in your message and we will route it appropriately.
