Unlock My Heart

Unlock My Heart — Privacy Policy

Effective July 7, 2026 · Version 1.0

This is a plain-language template prepared for review and finalization by a licensed attorney in [STATE]. It is not final legal advice, is not a substitute for counsel, and must be reviewed, adapted to UMH's actual data practices, and approved before it is published.

Unlock My Heart exists to hold something precious: the words, voices, and faces you want your loved ones to receive someday. Trust is not a small thing to ask for, so this Privacy Policy explains — in plain language — what information we collect, how we use it, who we share it with, how long we keep it, and the choices you have. We have tried to write it the way we would want it written for our own families: honestly, including the hard parts and the limits of what we can promise. If anything here is unclear, or you want to exercise a privacy right, reach us at [PRIVACY EMAIL].

1. Who We Are and What This Policy Covers

Unlock My Heart ("UMH," "we," "us," "our") is a U.S.-based digital legacy platform operated by [UMH LEGAL ENTITY]. We let a person (a "Creator") write and record heartfelt messages — text, uploaded video, and recorded audio — to be delivered to loved ones after the Creator dies or on future scheduled dates.

For privacy law, [UMH LEGAL ENTITY] is the "controller" (or "business") responsible for the personal information described here. [If UMH has an EU/UK establishment or representative, name it: EU/UK representative — [NAME/ADDRESS]. If a Data Protection Officer is appointed — [DPO CONTACT].]

This Policy applies to everyone who touches the Service:

It covers our website, app, and related services (together, the "Service").

What we are not: UMH is not a law firm and is not your fiduciary. We do not give legal, estate, tax, or financial advice. The Service is not a will, trust, codicil, or any legally binding testamentary instrument, and it does not replace one. This Policy is about your data; our Terms of Service cover the rest of that relationship.

2. The Short Version

If you read nothing else, read this:

This summary does not replace the full Policy below.

3. Information We Collect

Account information. When you create an account: your name, email address, password (stored only as a salted hash, never in plain text), and settings such as delivery preferences and scheduled dates.

Your messages and media. The heart of the Service: the letters you write and the video and audio you upload or record. Because you decide what to write, this content may include sensitive details — health, religious or philosophical beliefs, family relationships — and your voice and likeness (which some laws treat as biometric or "special category" data). You choose what to include; we store and deliver it as you direct and treat it as the most sensitive data we hold. We do not use it to train advertising or unrelated AI models.

People you name. To deliver your messages we collect information about the people you designate — Key Master and Key Recipients — such as names, email addresses, and the relationship or notes you provide. You are directing us to contact these people on your behalf; please provide their details only when it is reasonable for you to do so. At the point we contact them, we tell recipients how they came to receive a message and how to exercise their own privacy rights.

Your release passcode. You set a passcode and share it privately with your Key Master. We store only a one-way hash of it so we can confirm a release request — we cannot read it back, which also means we cannot recover or resend it if it is lost (see Sections 5 and 9).

Payment information. Payments are handled by Stripe, which collects and processes your card details directly under its own privacy policy. UMH receives only limited billing confirmation data (such as the last four digits, card type, expiration, and transaction status). UMH does not receive or store your full card number.

Professional Portal information. If you are an attorney or advisor: your professional identity, firm, license or vetting details, and the consent-scoped connections you establish with clients.

Technical and usage information. Like most online services, we automatically collect limited technical data — IP address, device and browser type, approximate location derived from IP, and basic usage and security logs — to operate and secure the Service. See Section 11.

Memorial-access requests. When someone uses the public "Find a loved one" search, we collect the request details and the identity/verification information our staff needs to confirm that person before granting any access.

Information from others. We may receive information about you from a Creator who names you, from a professional who invites you as a client, or from our service providers (for example, fraud or delivery signals).

4. How We Use Your Information

We use your information only for these purposes:

We do not use your letters, video, audio, or "essence" content to build advertising profiles or to train advertising or unrelated AI systems, and we do not sell your personal information.

We do not use your personal information to make legally or similarly significant decisions about you through solely automated means (no automated decision-making of that kind).

5. How Release Works — and Why It Matters for Your Privacy

Because the release process is unusual, we want to be very clear.

We do not verify death. UMH does not and cannot confirm whether a Creator has died. Instead, when you designate a Key Master and privately give them your passcode, you are giving UMH your affirmative consent and direction — a directive under RUFADAA (the Revised Uniform Fiduciary Access to Digital Assets Act) and the Stored Communications Act "lawful consent" framework — authorizing UMH to disclose your stored electronic communications and content to your Key Master and your designated recipients when a passcode-triggered release occurs. This consent and direction is the legal basis on which we disclose your content. You may change or revoke this direction at any time while you are able to, by updating your designations in your account.

The safeguard. Release is not instant. When your Key Master signs in and enters the correct passcode, a 72-hour cooling-off window begins. During that window we email you a one-tap "I'm alive — cancel" link. If you cancel, nothing is delivered. If the window passes with no cancellation, your undated letters deliver and a memorial page opens automatically. (Date-scheduled letters follow their own timeline.)

Honest limits and risks you should understand:

6. When and With Whom We Share Information

We share information only in these situations:

With the recipients you choose. The core purpose of the Service. When a release completes, we deliver your letters and media to the Key Recipients you named and open a memorial page for them. Your Key Master receives the access needed to begin and manage release but does not receive your private letters unless separately named as a recipient.

With service providers (processors) who help us operate, including:

These providers may use your information only to perform services for us, under contract (including data-protection terms), and not for their own purposes. A current list of key subprocessors is available on request at [PRIVACY EMAIL].

With verified people who request memorial access. When someone uses "Find a loved one," UMH staff manually verify that person before granting any access. Memorial pages show only what the Creator intended to be public; private letters and "essence" content are never part of that public access.

With professionals — only within consent scope. Attorneys and advisors in the Professional Portal (18+ and vetted) can see only the non-letter data a client has specifically authorized. Your letters and "essence" content are never shared with professionals.

For legal reasons. We may disclose information if required by law, subpoena, or valid legal process, or where we reasonably believe it necessary to protect the rights, safety, and security of users, the public, or UMH. Where lawful and reasonable, we will try to give you notice.

On a Creator's death or an estate request. Beyond the release you directed, an executor, administrator, or court may have rights under RUFADAA or other law to request access to a deceased Creator's account. We evaluate such requests against your online-tool direction, this Policy, and applicable law.

In a business transfer. If UMH is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. We will require the successor to honor commitments at least as protective as this Policy, or we will notify you of your choices.

We do not sell your personal information and do not share it for cross-context behavioral advertising.

7. An Honest Word About Security

We take security seriously and we refuse to overpromise.

What we do. We encrypt your data in transit (TLS) and at rest, store content on reputable cloud infrastructure with access controls, hash passwords and passcodes, and limit internal access to personnel who need it to operate, secure, and deliver the Service.

What we do not claim. Your content is NOT end-to-end encrypted. UMH systems, authorized UMH personnel, and our infrastructure providers are technically capable of accessing stored content. We commit that UMH will not access the substance of your letters, video, or audio except as reasonably necessary to operate, secure, troubleshoot, or deliver the Service, or as legally required. We tell you this plainly rather than implying secrecy we do not provide.

Breach notice. No online service can guarantee perfect security. If a breach affecting your personal information occurs, we will notify affected users and regulators as and when applicable law requires.

Your part. Use a strong, unique password, keep your passcode private, keep your account email current, and choose your Key Master with care.

8. How Long We Keep Your Information (Retention)

Retention here is different from most services, on purpose.

Your content is meant to last. Because our promise is to deliver your messages someday — possibly many years from now — we keep your letters, media, and delivery instructions long-term for as long as your account is active and the delivery purpose remains, unless you delete them sooner. Deleting content early would break the very promise you trusted us with.

After delivery. Once a release completes, delivered content and the memorial page may remain available to your Key Recipients according to the settings and duration you or your plan specify.

Other categories. Account and billing records are kept for the life of the account and then for the period required by tax, accounting, and legal rules. Security and usage logs are kept for a limited period for security and troubleshooting. Memorial-access verification records are kept as needed to show we verified access properly.

If you close your account or delete content. We honor your deletion (see Section 13) and remove it from active systems, subject to the backup and legal limits below. Deleting your account means we can no longer deliver those messages — that is the trade-off, and the choice is yours.

Backups and legal holds. Residual copies may persist in secure backups for a limited period before overwrite, and we may retain certain records longer where required by law, to resolve disputes, or to enforce our Terms.

If the Service is discontinued. If we ever wind down the Service, we will make reasonable efforts to notify Creators in advance and to provide a way to export or retrieve content where feasible. We cannot guarantee indefinite operation (see Section 9).

9. What We Can and Cannot Promise About Delivery

This is a privacy-and-expectations honesty note, echoed in our Terms.

The Service is provided "as is." We work hard to deliver your messages faithfully, but we do not and cannot guarantee that delivery will happen at an exact moment, or at all. Delivery can be affected by things outside our control, including: a passcode that is lost or never shared; a Key Master who is unreachable, unwilling, or unable to act; out-of-date recipient contact information; a cancel email that reaches an unmonitored inbox; or discontinuation of the Service. Because we do not verify death, we also cannot guarantee that a release reflects an actual death, nor prevent a release triggered in error or by someone who wrongly holds both the passcode and Key Master access.

We share this not to diminish our commitment, but so you can plan wisely — and so you understand why your choice of Key Master, the privacy of your passcode, and the accuracy of your recipient details matter so much.

10. Cookies and Similar Technologies

We use a small number of cookies and similar technologies to keep you signed in, remember your preferences, keep the Service secure, and understand basic, aggregate usage so we can improve.

We do not use cookies to build advertising profiles or to sell your data. You can control cookies through your browser settings; disabling essential cookies may prevent parts of the Service (like staying logged in) from working. Where required, we present a cookie choice on first visit. We honor recognized opt-out preference signals, including Global Privacy Control (GPC), as a valid opt-out for browsers where we receive them.

11. Age Requirements and Children

You must be 18 or older to create a UMH account. The Service is designed for adults making decisions about their own legacy, and we ask you to confirm your age at sign-up. Age self-attestation has limits, and we cannot guarantee it catches every underage user; if we learn an account holder is under 18, we will close it.

Minors as beneficiaries. A minor may be named as a Key Recipient. Where we know a recipient is a minor, delivery is designed to route through a verified adult rather than directly to the child.

COPPA. We do not knowingly collect personal information from children under 13, and the Service is not directed to them. If we learn we have collected such information without required parental consent, we will delete it promptly. If you believe a child under 13 has provided us information, contact us at [PRIVACY EMAIL].

12. Categories of Personal Information (Notice at Collection)

For transparency and for California residents, here are the categories of personal information we collect, why, and how we disclose them. We have collected these categories in the past 12 months:

Sensitive personal information. Your letters, voice, and likeness may reveal sensitive details (such as health, religious or philosophical beliefs, or family matters). We use and disclose sensitive personal information only to provide the Service you asked for (storage and delivery), to secure it, and as legally required — not to infer characteristics for any other purpose. Because we limit our use to these permitted purposes, there is no additional "limit the use of my sensitive personal information" step required, but you may still contact us with questions.

Sources of this information: you; people you name; professionals who invite clients; and our service providers.

We do not sell personal information and do not share it for cross-context behavioral advertising, and have not in the past 12 months. We offer no financial incentives in exchange for personal information.

13. Your Privacy Rights and Choices

You have meaningful control over your information.

Everyone can:

California residents (CCPA/CPRA). You have the right to know the categories and specific pieces of personal information we collect and how we use and disclose them; to access, correct, and delete your personal information; to limit certain uses of sensitive personal information (we already limit ours as described in Section 12); and to be free from discrimination for exercising these rights. We do not sell or "share" (for cross-context behavioral advertising) personal information, so there is nothing to opt out of on that front. You may use an authorized agent, and you may appeal a denial by contacting us.

Other U.S. state residents. If you live in a state with a comprehensive privacy law (for example Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect), you have similar rights to access, correct, delete, and obtain a portable copy of your data, to opt out of targeted advertising, sale, and certain profiling (which we do not do), and to appeal our decision on your request.

EEA/UK residents (GDPR/UK GDPR). Where these laws apply, you have the rights of access, rectification, erasure, restriction, objection, and data portability, the right to withdraw consent at any time (without affecting prior processing), and the right to lodge a complaint with your supervisory authority. Our legal bases are: performance of our contract with you (providing and delivering the Service); your consent (including your release direction under Section 5, and processing of special-category data such as voice/likeness and any sensitive content in your letters, based on your explicit consent); our legitimate interests in operating, securing, and improving the Service (balanced against your rights); and compliance with legal obligations.

How to exercise your rights. Manage most things directly in your account settings, or contact us at [PRIVACY EMAIL]. We may need to verify your identity before acting and will respond within the timeframes the law requires. If we cannot act on part of a request (for example, content we must retain to honor a delivery you still want, or records we must keep by law), we will tell you why.

International data transfers. We are based in and process data in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. Where required for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), a copy of which is available on request at [PRIVACY EMAIL].

14. Changes to This Policy

We may update this Privacy Policy as the Service evolves or the law changes. If we make material changes, we will notify you by email or through the Service before they take effect where required, and we will update the "Last updated" date below. Prior versions are available on request. Please review the Policy from time to time.

15. Contact Us

Questions, requests, or concerns about your privacy are always welcome.

Last updated: [DATE].

Reminder: This is a plain-language template prepared for review by a licensed attorney in [STATE] before it is published as final.

Terms of Service Privacy Policy contact@unlockmyheart.life