Privacy Policy

Last updated: June 25, 2026 · Version 1.1

This policy explains what EstateWatch collects, why, who processes it on our behalf, how long we keep it, and the choices you have. EstateWatch is a software platform for estate planning and estate administration. It is not a law firm and provides legal information, not legal advice; using it does not create an attorney–client relationship between you and EstateWatch (see our Terms of Service).

For law firms and attorneys. When your firm uses EstateWatch, your firm is our customer and you control the matter. Information your firm enters about its clients, their estate plans, and the estates it administers is your firm’s data: EstateWatch handles it only as a service provider acting on your firm’s instructions, to provide and support the platform. We do not use your clients’ information for our own purposes, we do not sell it, and we do not use it to train AI models for other customers or third parties. Your firm remains responsible, as the controller of that information, for its own confidentiality and professional-responsibility obligations to its clients. Section 2 explains this relationship in full.

1. Who this policy covers

EstateWatch serves two kinds of users, and this policy applies to both:

  • Law firms and their authorized users. An estate-planning or estate-administration firm subscribes to EstateWatch and its attorneys and staff use the platform to manage matters for the firm’s clients. The firm is our customer (the “account”), and its attorneys, paralegals, and other authorized team members are the individual users.
  • Individuals. A personal representative (executor), administrator, or other authorized individual may use EstateWatch directly to organize and administer a specific estate.

Throughout this policy, “you” refers to the user reading it. Where a section applies only to one audience, we say so.

2. Our role when a firm uses EstateWatch

When a law firm uses EstateWatch, two different categories of data are involved, and EstateWatch’s role differs for each:

  • The firm’s client and matter data. Information the firm enters about its clients, their estate plans, beneficiaries, fiduciaries, assets, and the estates it administers belongs to the firm. EstateWatch acts only as a service provider (processor) that stores and processes that data on the firm’s behalf and under the firm’s direction, solely to provide, secure, and support the platform and as permitted by the firm’s agreement with us. We do not sell it, do not use it for our own marketing, and do not use it to train AI models offered to other customers or third parties.
  • The firm’s own account data. For the firm’s administrative account information and its individual users’ account details (name, work email, role), EstateWatch is the controller, and the rest of this policy describes how we handle it.

Because the firm controls its matter data, the firm — not EstateWatch — decides who on its team may access each matter, and the firm is responsible for its own confidentiality, attorney–client privilege, and professional-responsibility obligations to its clients. EstateWatch designs the platform to support those obligations: access is role-based and limited to the firm’s authorized users, and sensitive identifiers are encrypted (see §4). Requests from a firm’s client to access, correct, or delete information held in the firm’s account are directed to and handled by the firm as the controller; we assist the firm in responding (see §8).

3. Information we collect

  • Account information. Your name, email address, role, and password (stored only as a salted hash by our authentication provider). For firm accounts, this includes the firm name and the details of each authorized user. Optionally a mailing address, used to pre-fill court forms you generate.
  • Estate, plan, and matter information. Details entered about a client, an estate plan, or an estate being administered — names, dates of birth and death, state of probate, beneficiaries and fiduciaries, assets, debts, share allocations, tasks, notes, and documents uploaded. Dates of birth and death are needed to compute filing deadlines and to populate probate court forms accurately. When a firm enters this data, it is the firm’s client and matter data described in §2.
  • Sensitive identifiers (Social Security numbers). Where a workflow genuinely requires it — for example, identifying parties in the attorney estate-planning module — a Social Security number is collected. These values are encrypted at rest (see §4). We deliberately do not store the decedent’s SSN: forms and letters that need it leave a blank to complete by hand, so it never enters our database.
  • Payment information. When you subscribe, payment is handled entirely by Stripe. We never see or store your full card number; we retain only the subscription status and identifiers Stripe returns.
  • Usage & diagnostics. Pseudonymous product-usage events and error reports (see §6 and §7). We do not sell your personal information.

4. How we protect it

Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider. In addition, the most sensitive fields — Social Security numbers and the editable content of generated legal letters — are individually encrypted in our application using AES-256-GCM before they are written to the database, through a single encryption choke point. Ciphertext is versioned (a v1: prefix) so the encryption key can be rotated without data loss. Access to a firm’s matter data is role-based and limited to the firm’s authorized users, and access to production systems is restricted to authorized personnel.

5. Service providers (processors)

We share data only with the vendors that operate the service, each acting on our behalf under confidentiality and data-protection obligations:

  • Supabase — database, authentication, and file storage.
  • Stripe, Inc. — payment processing and subscription billing.
  • Resend — transactional email delivery (invitations, reminders, notifications).
  • PostHog Inc. (United States) — pseudonymous product-usage analytics.
  • Sentry — application error and performance monitoring.
  • Plaid — bank-account connectivity. This integration is not enabled during the current pilot; it receives data only if and when you explicitly connect a financial account in a future release.

6. AI-assisted features

Where EstateWatch offers AI-assisted features to firm users, they function as decision-support for the licensed attorney — they organize information and surface facts with links to official sources; they do not provide legal advice to the firm’s clients, and the attorney remains the sole advisor exercising professional judgment. A firm’s client and matter data is not used to train AI models offered to other customers or third parties.

7. Cookies & tracking

We use the cookies strictly necessary to keep you signed in (session cookies set by our authentication provider). We also set a first-party attribution cookie (ew_attr) that records how you arrived at EstateWatch — for example, a partner referral link — so we can measure which partnerships are effective. Product-usage events are sent to PostHog Inc. (US) under a pseudonymous identifier, not your name. We do not use third-party advertising cookies.

8. Data retention

We retain account and matter data for as long as the account is active so the record stays available to you. For firm accounts, the firm controls its matter data and may export or delete it, and we retain it in accordance with the firm’s agreement and instructions. Estate administration records frequently must be preserved to support a final accounting; South Carolina Probate Court Rule 417 governs retention of court records, and you should keep your own administration records accordingly. When deletion is requested (see §9), we remove the data as described, subject to limited retention required for legal, tax, or fraud-prevention purposes (for example, Stripe’s and Sentry’s own retention of transaction and diagnostic records).

9. Your rights & choices

Depending on where you live, you may have rights to access, correct, or delete your personal information, and to know how it is used. California residents have these rights under the CCPA, including the right not to be discriminated against for exercising them. We do not sell personal information.

For a firm’s clients: because the firm controls the client and matter data it enters, requests about that data should be directed to the firm. If a firm’s client contacts us, we will refer the request to the firm and assist the firm in responding as the controller.

To exercise any of these rights for information EstateWatch controls, email [email protected]. We verify the identity of the requester and respond within the timeframe the law requires (for deletion requests under the CCPA, within 45 days). On a verified deletion request we delete the relevant estates and their associated records, remove stored files, delete the account, and submit deletion requests to our analytics provider.

10. Contact

Questions about this policy or your data may be directed to [email protected].