Privacy policy
AstruLegacy is designed to hold information that may be unusually sensitive. This page explains, in plain language, what the service stores and why.
Last updated: 13 August 2026. This policy should be reviewed for the countries in which AstruLegacy is offered before public launch.
1. Information you provide
AstruLegacy may store your name and email address, the legacy records you choose to enter, review settings, trusted-person relationships, and information needed to manage your account. The service may also store an email address and readiness score when a visitor deliberately opts in to marketing updates.
2. Why the information is used
Information is used to provide the organizer, calculate readiness and review status, operate trusted-person access, secure accounts, send requested service and security messages, administer subscriptions, provide backups, and respond to support or account requests.
3. Sensitive legacy information
Your legacy records can include financial, property, account, document, beneficiary, digital-estate and practical instruction information. AstruLegacy does not require you to store actual passwords and is not intended to replace a password manager. Store only information that is useful for your legacy plan.
4. Security and encryption
The active AstruLegacy data store and AstruLegacy backup snapshots are encrypted at rest. Account protection includes password hashing, optional authenticator-app two-factor authentication, recovery codes, session invalidation after important security changes, rate limiting on authentication endpoints, and restricted trusted-person release controls.
5. Trusted people
If you nominate a trusted person, AstruLegacy stores the contact and relationship details needed to send and manage the invitation. A trusted person does not receive your legacy information merely by accepting an invitation. Access must be released under the controls provided by the service.
6. Payments and service providers
Subscription checkout and payment processing may be handled by an external payment provider. AstruLegacy stores only the billing/subscription information needed to determine access and manage the customer relationship. Email delivery, hosting and other infrastructure may also involve service providers acting on AstruLegacy's behalf.
7. Marketing email
Marketing email is optional. If you opt in, AstruLegacy may retain your email address, signup source and readiness score where applicable. You can use the public unsubscribe page to switch marketing consent off. AstruLegacy may retain the preference record so the system knows not to include the address in the active marketing export. Service, security, access and billing-related messages are separate from marketing messages.
8. Backups and retention
Encrypted disaster-recovery backups may retain an older copy of information for the configured backup-retention period. Deleting an account removes it from the active data store, but older encrypted backups are allowed to age out according to normal retention rather than being silently rewritten.
9. Your choices
Signed-in users can review and update their legacy records, download a copy of their AstruLegacy data, change security settings, and request permanent deletion of the active account and its legacy records. Additional rights may apply under the law where you live.
10. Data that is deliberately excluded from exports
A personal data export does not disclose password hashes, password salts, authenticator secrets, recovery-code hashes, password-reset tokens, AstruLegacy encryption keys, webhook secrets or other credentials whose disclosure would weaken account or system security.
11. Contact
Configure Support:ContactEmail before launch so customers have a published privacy contact.