FOREVERVAULT — PRIVACY POLICY

Effective Date: December 1, 2025

Last Updated: September 7, 2026

This Privacy Policy ("Policy") describes how ForeverVault LLC, an Arizona limited liability company ("ForeverVault," "we," "our," or "us"), collects, uses, processes, and protects personal information when you access or use our websites, services, software, platforms, and applications (collectively, the "Service").

By using the Service, you agree to the practices described in this Policy.

If you do not agree, you must discontinue use of the Service.

1. WHO WE ARE

ForeverVault provides an encrypted document storage and sharing platform. Your content is encrypted in your browser before it is uploaded. Section 4 describes how encryption works, who can see your content, and the limited jobs the recovery key is used for.

ForeverVault LLC

Email: info@forevervault.com

Website: https://forevervault.com

Address: P.O. Box 170168, Miami Florida 33015

2. TYPES OF INFORMATION WE COLLECT

We collect the following information to provide and secure the Service:

2.1 Account Information

Name or username

Email address

Mobile phone number (for SMS verification)

Authentication data (passwords stored using one-way hashing)

Subscription details (plan type, payment status, billing history)

2.2 Encrypted User Content

Documents, files, metadata, and notes you upload or create

All User Content is encrypted in your browser before it is uploaded, and is stored and transmitted encrypted. The recovery key is used only in the five situations listed in Section 4.3, each of which is an action you have asked us to perform.

2.3 Device, Log, and Usage Data

IP address

Browser type and version

Device identifiers

Operating system

Dates/times of access

Pages viewed and actions taken

Error logs and diagnostic information

2.4 Cookies and Similar Technologies

We use essential and functional cookies for:

Login sessions

Account security

Preferences

Basic analytics

You may disable nonessential cookies. Essential cookies are required for account access.

2.5 Communications

Emails and messages you send to us

Notifications and alerts we send to you

SMS authentication messages (one-time passcodes, verification)

2.6 Legal and Administrative Information

If required for estate handling, account closure, or legal compliance, ForeverVault may collect:

Death certificates

Executor documentation

Identity verification for heirs or authorized representatives

3. HOW WE USE INFORMATION

We process personal information for the following purposes:

3.1 Service Operation

Creating and maintaining your account

Allowing uploads, storage, retrieval, and sharing of encrypted content. Immediate Share is available on all plans. Delayed Share, Legacy Share, and Trusted Contact designation require a paid plan.

Managing item and storage limits

Authenticating logins and actions

3.2 Security and Integrity

Multi-factor authentication (including SMS codes)

Fraud detection and prevention

Monitoring for suspicious activity

Protecting against unauthorized access

3.3 Account Notifications

Activation and security emails

Inactivity notifications and confirmations

Subscription and billing notices

Mandatory service and policy updates

3.4 Legacy and Estate-Related Actions

Initiating legacy workflows

Providing limited access to trusted contacts or heirs when authorized

Managing the 24-month estate access window after death

3.5 Compliance

Meeting legal obligations

Legal process as described in Section 6.2

Maintaining compliance records

ForeverVault does not sell personal information.

4. HOW YOUR CONTENT IS ENCRYPTED, AND WHEN WE CAN DECRYPT IT

This section describes how your content is protected and when the recovery key is used. Please read it rather than relying on a summary. The legal acknowledgment of the recovery-key architecture is in Section 3 of the Terms of Service.

4.1 Encryption

Your User Content is encrypted in your browser, before it is uploaded. It is stored encrypted, and it is transmitted encrypted. Your password is never sent to us and is not stored anywhere on our systems.

Each account has a master key, which is what your content is actually encrypted with. That master key is stored in two wrapped forms: one that can only be opened with your password, and one that can only be opened with a key held by ForeverVault in Amazon Web Services Key Management Service.

4.2 What the second copy is for

That second wrapped copy is the recovery key. It is what allows you to reset a forgotten password without losing everything, and what allows us to deliver your documents to the people you have nominated after your death, when you are no longer present to supply a password.

ForeverVault staff do not view, browse, or inspect your documents. No employee has a console for opening vaults. The people who can see your content are you, anyone you share with or nominate, and — only if the law requires it — a party named in a valid legal order.

4.3 The only situations in which the recovery key is used

Our systems are built so that the ForeverVault-held key can only be used for the following five purposes. Any other request is refused by the software itself, not merely by policy:

a. Password reset. When you have forgotten your password and complete our identity verification, so that your vault can be re-secured under your new password.

b. Legacy delivery. When the conditions you configured are met and we deliver your legacy portfolio to the recipients you nominated.

c. Share delivery. When you have shared an item and we make it readable to the recipient you chose, who does not hold your key.

d. Trusted contact release. When a trusted contact you designated completes the release process you configured.

e. Emergency message. Reading an encrypted contact detail you stored, so we can send an emergency message you configured.

Every one of these is an action you asked us to be able to perform. We do not access User Content outside them. No ForeverVault employee has a facility for browsing or reading your documents, every use of the key is recorded in an audit log we retain, and use of the key requires live credentials that can be revoked.

4.4 Your responsibilities

We cannot verify the accuracy, validity, or legal sufficiency of anything you upload.

You remain responsible for safeguarding your credentials, for keeping your nominated contacts current, and for understanding that the people you nominate will be able to read what you have designated for them.

5. NO STORAGE OF SENSITIVE CRYPTOGRAPHIC SECRETS

ForeverVault does not permit or support storage of private cryptographic keys, seed phrases, or mnemonic codes for third-party wallets or accounts.

Encrypted passwords you choose to keep in the Digital Wallet are stored on your behalf and are not used by ForeverVault for any other purpose.

Users bear all responsibility for compliance with this requirement.

6. HOW WE SHARE INFORMATION

We do not sell your information.

We may share limited personal data only in the following circumstances:

6.1 Service Providers

We use trusted third-party companies to provide:

Hosting (AWS)

Email delivery

SMS transmission

Error logging

Payment processing (Stripe)

These providers act only on our instructions and under contractual confidentiality obligations.

6.2 Legal Process

ForeverVault will disclose User Content only when required by applicable law or by legal process that ForeverVault reasonably determines to be valid, binding, and enforceable.

To the extent permitted by law, ForeverVault will notify you before disclosing your User Content so that you may seek appropriate legal relief. If ForeverVault is legally prohibited from providing prior notice, ForeverVault may provide notice after the prohibition expires, unless otherwise prohibited by law.

ForeverVault reserves the right, but does not undertake an obligation, to challenge or seek to narrow any request that it reasonably believes is unlawful, defective, or excessive. Any legally compelled disclosure will, where reasonably practicable, be limited to the User Content specifically required by the applicable legal process.

Except as authorized by you, required by applicable law, or expressly described in the Terms of Service or this Policy, ForeverVault will not disclose decrypted User Content to third parties.

6.3 With Your Direction

When you:

Share content

Add trusted contacts

Approve legacy actions

Designate an executor or heir

6.4 Estate Requests

Upon verified death and proper documentation, we may disclose limited information to authorized heirs or representatives as described in the Terms of Service.

7. INTERNATIONAL TRANSFERS

ForeverVault stores all data exclusively within the United States using AWS infrastructure.

We do not transfer User Content or personal data outside the U.S.

8. DATA RETENTION

We retain personal information only as necessary to:

Maintain your account

Provide the Service

Comply with legal obligations

Resolve disputes

Enforce our Terms

8.1 Account Deletion

When you delete your account:

Encrypted User Content is permanently deleted

Backup copies are purged according to our retention schedule

Some transactional or security logs may remain where legally required

8.2 Inactive Accounts

In accordance with user-selected inactivity settings, ForeverVault may:

Mark accounts as inactive

Notify trusted contacts

Restrict account activity

Close accounts after extended inactivity (e.g., 24 months)

8.3 Accounts of Deceased Users

As per the Terms of Service:

Accounts remain accessible to authorized heirs for up to 24 months

Thereafter, the account and all encrypted content are permanently deleted

9. SECURITY

We implement administrative, technical, and organizational safeguards, including:

Client-side encryption

TLS encryption in transit

Strong credential hashing

Access controls

System monitoring

AWS infrastructure protections

No system is 100% secure. Users must maintain secure devices and passwords.

10. YOUR RIGHTS

Depending on your jurisdiction, you may request:

Access to personal information

Correction or updates

Deletion of personal data

Restriction of processing

Portability of non-encrypted data

Withdrawal of consent for certain processing

Requests: info@forevervault.com

We can delete your User Content and export it to you. We do not, however, decrypt and inspect User Content in order to answer content-level questions about it, such as identifying every document that mentions a particular person; the key is restricted to the five purposes in Section 4.3 and searching your documents on request is not one of them.

11. CHILDREN'S PRIVACY

The Service is not directed to children under sixteen (16).

If you believe a child has provided personal information, contact us, and we will take appropriate action.

12. CHANGES TO THIS POLICY

We may update this Policy from time to time.

Changes will be posted with a new "Last Updated" date.

Material changes may be communicated via email or in-service notifications.

Your continued use of the Service constitutes acceptance of the updated Policy.

13. CONTACT US

For questions regarding this Policy:

ForeverVault LLC

Email: info@forevervault.com

Address: P.O. Box 170168, Miami Florida 33015