Privacy
You are handing this platform the details of an estate, which is not a small thing to hand anyone. This says what we hold, who else touches it, and what we will not do with it. It describes what the system actually does today rather than what we intend it to do eventually.
Effective 22 September 2026
What we hold
Your account details, being your name, email address and a hashed password. We never store your password itself.
The trusts and entities you administer here, including the trustee, beneficiary and asset details you record, the documents drafted or uploaded, and the notes and decisions attached to them.
The correspondence you produce, including letters, emails, faxes and their recipients, together with the delivery records that prove what was sent and when.
Your conversations with the agent, including the files you attach to them, because the record of how a position was reached is part of the administration record.
Filings you record, such as liens and Uniform Commercial Code filings, and the obligations and dates attached to them.
What is encrypted
Trustee details, beneficiary details, asset lists and the body of every stored document are encrypted at rest with a symmetric key held by the platform, so they are not readable in the database as ordinary text.
Other records, including trust names, jurisdictions, notes, addresses, filing details and correspondence logs, are stored without that additional layer. All data sits on managed infrastructure with access restricted to the operator.
Traffic between your browser and our servers is encrypted in transit.
Who else sees it
Running this service means handing parts of your information to the companies that perform the work. We share only what a given task requires.
Physical mail: recipient and sender names and addresses, and the letter itself including any exhibits, go to our print-and-post provider, because a letter cannot be posted otherwise. Faxes and remote notarisation work the same way, with the document and signer details passing to those providers.
Email: recipient addresses, subject lines and message bodies go to our email provider for delivery.
Payment: your email address and an account identifier go to our payment processor. Card details are entered directly with them and never reach our servers.
Drafting and research: what you type to the agent, the documents you attach, and the trust details relevant to the request are sent to third-party language model providers in order to produce the output you asked for. Their terms restrict the use of that content to serving the request. If you prefer, you can supply your own provider key or point the workspace at a model you run yourself, in which case that processing happens under your arrangement rather than ours.
We do not sell your information, and we do not share it for advertising.
Copies you should know about
By default, outbound correspondence sent on your behalf is copied to your own email address, so that your inbox holds the same record the platform does. You can change the address it copies, or turn the copy off, in settings.
When an account is created, we are notified of the name and email address so we know who has joined.
Where you send correspondence under a trust's own sending address, the trust's name is visible to the recipient.
What we do not do
We run no analytics, no advertising trackers and no third-party scripts. Nothing on this site reports your visit to anyone.
We set no cookies. Your session is held in your own browser's local storage and is cleared when you sign out.
We do not read your trust records, documents or conversations except where you ask us for support, or where we are compelled by lawful process.
Keeping and removing it
Records are kept for as long as your account exists, because administration depends on being able to produce what happened years afterwards. Archiving a document or a conversation hides it from your workspace while keeping it on the record.
Consent and audit records, being the evidence of who agreed to what and when, are kept permanently and are not altered.
If you want your account and its contents removed, write to us and we will do it by hand. We would rather tell you that plainly than claim an automated deletion we have not built.
Your choices
You can correct your account details, change or disable the copy of outbound correspondence, and supply your own model provider key, all from settings.
You can ask us what we hold about you, ask for a copy, or ask for it to be corrected or removed, by writing to the address below. Depending on where you live you may have a legal right to these things, and we will honour the request either way.
Where it lives
The application runs on managed hosting in the United States, with the database operated by our infrastructure provider. If you are outside the United States, using the service means your information is processed there.
Changes
If this policy changes in a way that affects what we collect or who we share it with, we will say so here and date it. Continuing to use the service after that means the revised policy applies.
Asking us anything
Write to fiduciary@irrevocable.io and a person will answer.