Legal

Privacy Policy

Last updated September 20, 2026. Vault content is encrypted on your device. Account, delivery and billing information have different processing needs, and optional AI composition requires your consent.

Summary

  • We process information required for authentication, billing, delivery and account operations.
  • Vault documents, journal content and stored Life Books are encrypted on your device. Optional Life Book composition sends selected written answers through our backend to Anthropic after your consent.
  • We do not sell your data. Google Analytics is optional and starts only after you accept analytics.
  • You can export your data and request account deletion. Eternal Vault retention is separate, as described below.

Data we collect

Account identifiers: email address, account creation timestamp, and an optional phone number you can add to your profile.

Billing metadata: subscription plan, billing address, payment processor transaction IDs. Actual payment card details are handled by our payment processor (Stripe) and never reach Henedo’s servers.

Ciphertext: the encrypted blobs of your vault contents, journal entries, contact bundles, signing keys, and Eternal Vault seals. We cannot decrypt these.

Operational metadata: timestamps, file sizes, MIME types (required for quota and content-type headers), session events (last login, heartbeat, DMS state transitions).

Delivery information: trusted-contact details, Ask recipient details and capsule delivery details are processed by the service to address and deliver messages. Sensitive fields are encrypted at rest with a server-managed key; this is different from the device-only keys protecting vault documents.

Optional Life Book composition: when you request AI composition and consent, selected written Life Story answers are sent in readable form through a Henedo Edge Function to Anthropic. The generated book returns to your browser and is encrypted there before storage. The generation handler does not persist the readable request or response. Revoking consent prevents future generations; it cannot undo processing already completed.

Optional web stories: after separate consent for each draft, submitted public links are sent to Jina Reader or Firecrawl to retrieve page text. Extracted text, text you paste, your profile name, and any context you add are processed in readable form by Henedo and Anthropic to prepare an editable draft. Page retrieval receives only the public links; pasted text, your profile name and your context are sent separately for drafting. We do not fetch or send your profile’s email address, phone number or other fields for drafting. Henedo does not persist this readable request or response. We request no caching or tracking from Jina Reader; provider retention follows the providers’ API data policies. Only material you review and save is encrypted on your device before storage, including its title and source links. Stories you select for your Life Book are included when you separately consent to book composition. Saved web stories follow your Life Story sharing settings.

Optional analytics: after acceptance, Google Analytics receives page-view and product-event information. See the Cookie Policy to change this preference.

Data we do not collect

  • Readable contents of encrypted vault documents, photos, videos and journal entries. The optional AI-processing exception for selected Life Story answers is described above.
  • File names or folder names (encrypted client-side with your Master Key).
  • Your readable Master Key or vault encryption passphrase. Account sign-in credentials are processed separately by the authentication provider.
  • Your readable recovery key as part of normal vault storage. Recovery and recipient-delivery flows handle their own explicitly requested key material.

Your rights (GDPR / CCPA)

You can request access to the account data we hold, export your vault, correct inaccuracies, request account deletion, and request restrictions on processing. A sealed Eternal Vault has a separate retention and delivery lifecycle.

Requests: privacy@henedo.com. We respond within 30 days (typically within 48 hours).

Subprocessors

We use the following subprocessors to deliver the service:

  • Supabase provides authentication, the database and backend functions. Vault document bodies reach storage as ciphertext; account and delivery services process their necessary operational information.
  • Stripe (payment processing), processes card data directly; Henedo never sees card numbers.
  • Cloudflare provides object storage and network protection; AWS Amplify hosts the frontend.
  • Anthropic processes selected written answers and web stories when you consent to Life Book composition, and source text when you separately request a web-story draft.
  • Jina Reader retrieves the public pages you submit when you consent to creating a web-story draft. Firecrawl may be used first when configured, with Jina Reader as the fallback.
  • Google Analytics processes optional analytics after your acceptance.
  • Transactional email delivery uses the email provider configured for the deployment. Contact us for the current provider details.

Retention

Account deletion has a seven-day cancellation period. Cleanup runs afterward and retries failed storage or database operations before finalizing. Billing records follow applicable retention requirements. Eternal Vaults have a separate purchased preservation term; the self-service account-deletion flow currently refuses deletion while a live Eternal Vault is present. Contact support to resolve that situation before proceeding.

Contact

Henedo Inc., privacy@henedo.com, For EU residents: EU representative address available on request.