Privacy
Privacy should be understandable, not just legal.
This describes what BeforeHand actually collects, protects, and shares in the product today — on the web and in the iOS app — down to the specific providers involved. It's a working draft, not a substitute for review by qualified counsel before this policy is relied on as binding.
Our commitment
BeforeHand is designed around deliberate access, data minimization, and clear control. We do not treat a family relationship as automatic permission to view another person's plan, and we do not use your plan's contents for advertising, profiling, or anything other than running the product you asked us to run.
Information you provide
When you create an account, we collect your name and email address. You can add a phone number, which we use only for the two-factor text codes and time-sensitive alerts described below — not for marketing.
Instead of a password, you can sign in with Google or with Sign in with Apple. Both give us only your name, email address, and (for Google) a profile photo — nothing else. If you choose Apple's “Hide My Email” option, we only ever see the private relay address Apple generates, never your real one. We never request or receive access to your Gmail, Drive, Google Calendar, Google Contacts, iCloud, or any other service tied to either account beyond confirming who you are.
Keeping your account secure
Every account is protected by two-factor authentication in addition to your password (or your sign-in with Google or Apple). The primary method is a time-based code from an authenticator app, generated and checked entirely on our own servers, with no third party involved. You can also request a one-time code by text message instead; that path is optional, sent through Twilio, and only used the moment you actually ask for a code.
Separately, when you choose to store something sensitive in your plan — an account password, an identification number, an access code — you set a security PIN of your own, distinct from your account password. We never store that PIN in a form anyone, including us, could read back: we keep only a salted, one-way hash of it, the same kind of check used to verify a password, not to recover one. Forgetting it means resetting it, not retrieving it.
Information you record in your plan
Your plan can include structured records (financial accounts, insurance policies, digital account logins, medical directives, personal property, and similar categories you choose to add), uploaded documents, and information about the people you connect to your plan — their name, relationship to you, and contact details. Fields you mark as sensitive, such as account passwords and identification numbers, are encrypted (AES-256-GCM) before they're written to our database, and uploaded documents are encrypted the same way before they're written to storage — not just access-controlled behind a login, but unreadable without the encryption key even if the underlying storage were somehow exposed. Sensitive fields also stay masked on screen behind the security PIN described above, separately from whatever access another person may have to view that part of your plan.
Adding people to your plan
When you add a trusted person or an Executor to your plan, we collect the name, relationship, and contact details you give us for them. If they don't already have a BeforeHand account, we email them to let them know they've been added and, if you've granted them any access, what that access is for. Inviting someone to a shared family subscription works the same way — we collect the name and email you give us for them and use it only to send that invitation and manage their seat on your subscription.
Who can see it, and when
Nothing you record is visible to anyone by default. Access only exists for the specific people you choose, scoped to exactly what you decide — a full plan, a single category, or a single item — and most access stays inactive until you explicitly publish it. Some access is conditional: it only activates once a life event you've defined (such as incapacity or death) is reported and verified through a review of real evidence, not a single click.
Once a death is verified specifically, we treat closing your accounts and settling your affairs as the priority: the Executor you've named and the family point of contact you've designated automatically gain full access to your plan's records and documents at that point, regardless of the narrower access they may have held while you were living. Everyone else you've connected to the plan can see high-level progress on that process without seeing your underlying records, unless they hold their own specific access to them.
Payments and subscriptions
If you subscribe, payment is handled entirely by Stripe; we never receive or store your card number, expiry date, or security code. What we keep on our side is a Stripe-issued customer reference so we can look up your subscription status — not your card details, which stay with Stripe under its own privacy and security practices.
How we communicate with you
We send email and, for time-sensitive items, text messages about account activity: access being granted, a life event being reported or verified, a two-factor code you requested by text, and updates once a plan enters the account-closure process described above. We use Mailgun to deliver email and Twilio to deliver text messages; neither is authorized to use your information for any purpose beyond sending the message we ask them to send. We don't currently send push notifications, and we don't use your information for advertising or any marketing outreach beyond what's described here.
Cookies, sessions, and tracking
The web app uses a single functional session cookie so you stay signed in — nothing more. It isn't used for advertising, cross-site tracking, or analytics, and we don't load any third-party advertising or analytics scripts on beforehandplan.com. The iOS app doesn't use cookies at all: it keeps your session as a token stored in the device's Keychain, encrypted by iOS itself and never held anywhere else on the device.
Where your information is stored
Your plan data and uploaded documents are stored using Supabase, our database and file-storage provider, with sensitive fields and documents encrypted before they ever reach storage, as described above. If you access BeforeHand from a location outside where our infrastructure is hosted, your information will be transferred to and processed in that location, under the same protections described in this policy.
How long we keep it
We keep your plan, your documents, and your contacts for as long as your account is open, so the product keeps working the way you'd expect. If you revoke someone's access or remove a record, it stops being visible immediately; we don't promise instant deletion from backups, which exist to protect against data loss and age out on their own schedule rather than being individually edited. If your plan enters the account-closure process described above, records related to that process are kept long enough to support the Executor and family point of contact through it, and afterward for as long as we reasonably need to in case a dispute or legal request requires us to show what happened. Billing records are kept for as long as tax and accounting rules require after payments are made through Stripe.
Your rights and choices
Wherever you're located, you can ask us to tell you what personal information we hold about you, correct anything that's wrong, or delete your account. Most of what we hold you can already see and edit directly inside the product — your profile, your plan records, your contacts, and who has access to what. To delete your account, use “Request account deletion” in the iOS app's Account screen, or email us at the address below; either way, we verify the request first, since deleting an account can affect other people's access, an in-progress account-closure process, or an active subscription, and we want to be sure it's really you and that you understand what it affects before we act on it. If you're in a region that grants you a formal right to data portability or to object to processing (for example under the GDPR or the CCPA), the request above covers that too — email us and tell us what you're asking for.
You can also, independent of any of that: revoke anyone's access to your plan at any time your plan isn't already in the account-closure process; stop receiving two-factor text codes by simply not requesting one (contact us to reset the authenticator-app method if you lose access to it); and unsubscribe from any non-essential email using the link in that email.
Children
BeforeHand is built for adults planning for themselves and the people they trust. It is not directed to, and we do not knowingly collect information from, anyone under 13. If we learn that a child's information was provided to us, we'll delete it.
Changes to this policy
If how we handle your information changes in a way that matters, we'll update this page and, for significant changes, tell you directly.
Contact us
Questions about this policy, your information, or an account deletion request: hello@beforehandplan.com.
Before this policy is final
This page reflects the product's actual current design and the providers listed above. It should still be reviewed by qualified counsel, updated with the company's legal name, registered address, and jurisdiction, and reconfirmed against the exact providers in use before it is relied on as a binding privacy policy.