Privacy Policy
MyLifePapers is a household record keeper. Your records, documents, passwords, and notes are encrypted on your device with a passphrase that only you know. We cannot read them, and neither can any company that stores them for you.
If you choose to sync, the encrypted copies go either to a cloud account you already have (Google Drive, Dropbox, Microsoft OneDrive, or any folder your device already syncs, such as iCloud Drive) or to MyLifePapers Cloud. Either way the contents stay encrypted with a key we do not hold. Section 4 says exactly what the storage can and cannot see.
The AI in the app runs on your device. Nothing you type into it, and nothing you upload, is sent to us or to any AI company.
We collect what it takes to run the service: a verified email address when you register a purchase, a name and verified email address when you claim a gift, an internal household credential used by the app, and limited operational data when you publish a Trusted Access link. There are no analytics, trackers, or ads in the apps. Our website records which campaign brought you to it, without cookies and without your IP address.
If you want the long version, read on.
1. Who we are
This Privacy Policy describes how MyLifePapers LLC ("MyLifePapers," "we," "us," or "our") handles personal information collected through:
- the MyLifePapers desktop application for macOS and Windows,
- the MyLifePapers mobile applications for iOS and Android,
- the website at mylifepapers.com, including the Trusted Access viewer at access.mylifepapers.com, and
- any related services we offer (together, the "Service").
You can reach us at privacy@mylifepapers.com.
2. Information you give us
We collect personal information only when you give it to us. Specifically:
- When you buy on our website, you verify the email address that will own the purchase. Stripe separately collects the payment details and may collect a receipt or wallet email. Stripe tells us payment and customer references; we do not receive or store your card number.
- When you claim a gift, you give us your name and email address. We send a one-time code to confirm that you control the address, then register the gift to that verified email.
- When you buy inside the iPhone or iPad app, you first verify the email address that will own the purchase. Apple processes the payment under its own terms and gives us a transaction identifier, which we store so the same purchase cannot be redeemed twice.
- When you restore a purchase, you enter the registered email and a one-time code. We use that proof to restore the entitlement to the app; no customer-facing license key is involved.
- When you publish a Trusted Access link and choose to restrict it to named people, we store the email addresses you enter so the viewer can check that a visitor is one of them. When a visitor verifies, we store the address they typed and send a one-time code to it.
- When you contact support, we receive whatever you choose to send us: your email address, a description of your problem, and any attachments or screenshots you decide to include.
3. Information your device sends us automatically
Our applications make network requests to our servers and, if you chose one, to your cloud provider. These requests carry:
- an internal household credential, which the app presents to confirm that the household is active. The credential is stored by the app and is not a code you need to see, save, or type. This request carries no device name, device identifier, operating system, or app version;
- encrypted data when you sync or publish a Trusted Access link (we cannot read the contents);
- standard network metadata that every internet request carries, such as the request timestamp and the IP address it came from. We do not store IP addresses from the apps, with one exception: the access log of a Trusted Access link stores a shortened one-way hash of each visitor's IP address, described in Section 8.
The desktop application does not check for updates on its own and does not contact us for that purpose. We do not embed analytics SDKs, crash reporters, behavioral trackers, advertising trackers, or session-replay tools in our applications.
4. What reaches our servers, and what does not
When you use MyLifePapers Cloud, or a cloud account of your own, this is what the storage holds.
Encrypted, unreadable to us
- Every record, document, password, note, reminder, and attached file. Each is encrypted on your device with the household key before it leaves. Attached files are uploaded without their original file names and with a generic file type.
- The wrapped copies of your household key. Each is locked with a member's passphrase, or with the recovery code, and cannot be opened without it.
Visible to the storage
- The household's random identifier, which names the folder the encrypted objects sit in. It is not tied to a name or an email address.
- The size of each encrypted object and the time it was written, which any file storage records.
- The number of wrapped keys, which is the number of members in the household, plus each member's random id and their role (admin or member). Their names are sealed with the household key.
That is the whole list. We cannot read your records, documents, or passwords, and neither can the company whose storage holds them.
5. What we do not collect
- The contents of your records, passwords, files, notes, or reminders. These are encrypted on your device with a key derived from a passphrase that only you know. We do not have, and cannot derive, your passphrase or the key it generates.
- Your passphrase or your recovery code. Neither leaves your device. We have no copy and no way to reset either for you. If you lose your passphrase, the recovery code you saved during setup lets you set a new one yourself, without us. If both are lost, no one, including us, can recover your data.
- Your questions to the AI, and its answers. The assistant runs on your device. Nothing you ask it, and nothing it answers, is sent to us or to anyone else.
- Which banks, insurers, or institutions you use. The logos the app shows are bundled inside the app. It never asks our servers for a logo, so we never learn which institutions appear in your records.
- The contents of files you sync through your own cloud account. Your encrypted records are stored in your account. We do not have credentials for that account and never see its contents.
- Your browsing history, location, microphone, or calendar. The apps do not request these permissions and do not access them.
- Your contacts, photos, or camera in the background. Some features need them only at the moment you use them, described in Section 6. We never upload your address book or photo library.
- Analytics or usage tracking. We do not measure which features you use, how often you open the app, or what records you create.
6. Device permissions and features
The mobile apps ask for these permissions, each at the moment you first use the feature, and use them only for that feature:
- Camera, to scan documents and QR codes.
- Photo library, to import a photo of a document, and to save a scan if you ask for that.
- Contacts, to pre-fill a person's name and details from a contact you pick. Nothing from your address book is stored or transmitted unless you save it into a record, and then it is encrypted like everything else.
- Face ID, Touch ID, or Android biometrics, to unlock the app. When you turn this on, the phone keeps a copy of your vault key in the operating system's secure keychain or keystore, protected by the device's own biometrics and passcode, so the app can open without your passphrase. Turning biometric unlock off removes it. The desktop app does not do this; it holds the key only in memory while unlocked.
- Notifications, for reminders you set. Reminders are scheduled on the device. We have no reminder server and send no reminder emails or push notifications.
Two features connect to other services only when you choose them:
- "Add to calendar." A reminder offers a button that opens Google Calendar or Outlook in your browser with the reminder's title, date, and description filled in. That information goes to Google or Microsoft only when you press the button, and only for that reminder.
- Password AutoFill. On iOS and Android you can let the system fill passwords from MyLifePapers into other apps and websites. The app keeps an encrypted copy of your password list where the operating system's AutoFill can reach it, unlocked by your biometrics. Nothing is sent to us.
7. Cloud sync and where your encrypted data goes
Sync is optional. If you turn it on, your data is encrypted on your device before it leaves, and only a device holding your passphrase can decrypt it. You choose one of these destinations:
MyLifePapers Cloud. Encrypted storage we run on Cloudflare. It is the destination that lets household members on different accounts share one household. Each household may store up to 5 GB there, and each file up to 50 MB.
Google Drive. We request only the drive.file scope, which lets MyLifePapers access only the files our application creates in your Drive. We do not request and we do not receive access to any other files.
Dropbox. We use Dropbox's App Folder mechanism, a folder created for our application inside your Dropbox at Apps/MyLifePapers. We can read and write only inside that folder.
Microsoft OneDrive. We use Microsoft's App Folder mechanism with the equivalent isolated scope, for personal Microsoft accounts. We can read and write only inside that folder.
A shared folder. Any folder your device already syncs, such as iCloud Drive, a NAS, or a network share. MyLifePapers writes the encrypted files to that folder and never connects to the service behind it; your operating system handles the transfer.
For Google Drive, Dropbox, and OneDrive you sign in at the provider, not with us. The sign-in tokens the provider issues are kept on your device only: inside the encrypted database on desktop, and in the app's private storage on your phone. We never receive them.
8. Trusted Access
Trusted Access lets you publish a read-only page of chosen records for someone you trust, for example an executor or a family member, at a link on access.mylifepapers.com.
- The page is encrypted on your device with an access code before it is uploaded. The code is shown to you to pass on however you like. It is not in the link, it never reaches our servers, and without it the stored page is unreadable to us.
- You can restrict the link to named email addresses. If you do, we store those addresses, and a visitor must confirm one of them with a one-time code we email to it. A confirmed visitor stays confirmed on that browser for seven days.
- Each link keeps an access log: the time of each attempt, whether it succeeded, the email address used if you set a restriction, and a shortened one-way hash of the visitor's IP address rather than the address itself. The log exists so you can see who opened the page. We keep it for as long as the link exists and for up to 90 days after the link expires or is deleted.
- You can give a link an expiry date, rotate its access code (the old code stops working at once), or delete it. Deleting removes the encrypted page immediately.
- The viewer page sets no cookies and runs no analytics.
9. Our website
Our website sets no cookies and runs no third-party analytics. Two things are worth knowing:
- Campaign attribution. If you arrive through a tagged link (for example from a social post), the page stores the campaign tags in your browser's local storage and sends them, with the address of the page that referred you, to our own server, which counts them. This carries no cookie, no IP address, and no browser identifier, and it does nothing on untagged visits. If you later buy, the same campaign tags are passed to Stripe as a reference on the purchase so we can see which campaigns lead to sales.
- Fonts. The site loads its typefaces from Google Fonts, so Google receives the standard request metadata (such as your IP address) that any font download carries.
Application installers and the overview video are served from our own servers.
10. How we use your information
We use the personal information we collect to:
- deliver the Service you purchased and let you restore that purchase with your verified email,
- confirm that your license is active when the application contacts our servers,
- let a Trusted Access visitor prove they are someone you named,
- send you operational messages about your purchase, your license, or a security issue that affects you,
- prevent fraud and abuse, and
- comply with our legal obligations.
We do not sell your personal information. We do not share it with advertisers. We do not use it, or anything you store, to train AI models.
11. Sharing your information with third parties
We share personal information only as described below.
Service providers
We use a small number of third-party services to run MyLifePapers. They are bound by contract to use the information we share with them only to provide their service to us.
- Cloudflare hosts our servers, MyLifePapers Cloud, and the Trusted Access pages. What it stores for you is encrypted before it leaves your device; Section 4 lists the little it can see.
- Stripe processes website purchases. Your name, email, and billing details are handled by Stripe under its own terms and privacy policy.
- Apple processes purchases made inside the iPhone and iPad app under its own terms.
- Resend delivers our transactional email: purchase confirmations and one-time codes for email verification, purchase restore, Cloud restore, and Trusted Access.
- Google Fonts serves the website's typefaces.
If you choose cloud sync with your own account, you also authorize one of the following at your own choice. We never receive your credentials for these services, and the data sent is encrypted before it leaves your device.
- Google LLC (Google Drive)
- Dropbox, Inc.
- Microsoft Corporation (OneDrive)
- the operator of whatever folder-syncing service you point a shared folder at, for example Apple Inc. for iCloud Drive
We do not share your personal information with marketing, analytics, or advertising providers. We will share the current list of providers on request: email privacy@mylifepapers.com.
Legal requests
We may disclose personal information if we are required to do so by a valid legal process, for example a court order or subpoena issued in a jurisdiction where we operate. We will challenge requests that we believe are improper, overly broad, or not supported by the law. Because we cannot decrypt your records, we cannot respond to demands for the contents of your data; we can only provide the limited account information described in Sections 2, 4, and 8.
Business changes
If MyLifePapers is involved in a merger, acquisition, financing, or sale of all or part of our business, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
12. Security
The most important protection of your data is on your device. Your passphrase is turned into a key with a memory-hard key derivation function, that key unlocks a random household key generated on your device, and the household key encrypts your whole local database and every copy that syncs. The household key never leaves your device in the clear. Our security page lists the algorithms and parameters.
We protect our own systems with industry-standard practices: encryption in transit between your device and our servers, encryption at rest on our storage, and access controls limiting which of our personnel can reach administrative systems. No security measure is perfect, but the design of MyLifePapers means that even a successful attack on our servers would not expose the contents of any household's records.
Two limits are yours to manage: an unlocked device is an open vault, and on a phone with biometric unlock the vault key is held by the device's keychain, so the phone's own passcode and biometrics guard it.
If we ever discover a breach that affects your personal information, we will notify you without undue delay as required by applicable law.
13. How long we keep your information
We keep your information only for as long as we need it to run the Service.
- Purchase and claim information (registered email, claimant name, internal household identifier, and purchase references): for as long as your entitlement exists, plus a reasonable period afterward to maintain accurate business and tax records.
- Payment records: for the period required by tax and accounting law, typically seven years.
- Encrypted data in MyLifePapers Cloud: until you delete it in the app, disconnect the household from MyLifePapers Cloud, or ask us to delete it.
- Trusted Access pages: until the expiry you set, or until you delete the link. A link's record and access log are kept for up to 90 days after that.
- Pairing and invitation relays (the encrypted hand-off used to add a device or a member): deleted when picked up, and in any case after 15 minutes.
- One-time codes sent by email: deleted within a day.
- Website campaign counts: kept as counts; they contain no identifier.
- Support emails: up to two years from the last reply, then deleted.
14. Deleting your data
You are in control of your data. You can:
- Delete records, passwords, and files at any time inside the application. A deleted record goes to the trash, where it can be restored for 30 days and is then removed for good. Deleting propagates to every synced device and removes the encrypted copy from your sync destination.
- Stop syncing by disconnecting the provider in Settings. Future changes will stay on your device.
- Revoke our access to your cloud provider directly from that provider's settings page (Google Account → Security → Third-party access; Dropbox → Apps; Microsoft → My account → Privacy → Apps and services). You can do this at any time without telling us.
- Delete your Trusted Access links inside the application.
- Delete your license and remaining cloud data by following the steps at mylifepapers.com/delete-my-account. We delete the encrypted data we hold, the Trusted Access links and their logs, and the email address on the license within 7 days, and confirm by email. An anonymized purchase record stays for tax purposes. Backups may retain copies for up to 30 days before they are overwritten.
Data on your own devices is yours to delete by removing it in the app or uninstalling the app.
15. Children's privacy
MyLifePapers is not directed to children under the age of 16, and we do not knowingly collect personal information from children under 16. Records about a child kept by a parent or guardian inside their own household are encrypted like every other record and are not visible to us. If you believe a child under 16 has given us personal information directly, please contact us at privacy@mylifepapers.com and we will delete it promptly.
16. International transfers
MyLifePapers is operated from the United States. If you use the Service from outside the United States, your information will be transferred to, stored, and processed in the United States and in other countries where our service providers operate. We rely on appropriate legal mechanisms, including the European Commission's Standard Contractual Clauses where applicable, to protect your information when it crosses borders.
17. Your rights
Depending on where you live, you may have the following rights under applicable privacy law (including the General Data Protection Regulation in the European Economic Area and the United Kingdom, and the California Consumer Privacy Act):
- the right to know what personal information we hold about you,
- the right to access and receive a copy,
- the right to correct inaccurate information,
- the right to delete your information,
- the right to restrict or object to how we process it,
- the right to withdraw consent where we relied on it, and
- the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, email privacy@mylifepapers.com from the verified address registered to your purchase. We will respond within the timeframes required by applicable law, typically within 30 days. We do not discriminate against you for exercising these rights.
We do not sell or share personal information as those terms are defined under the CCPA, and we have no method to opt out of selling because we do not sell.
18. Changes to this policy
We may update this Privacy Policy from time to time. When we make a material change, we will post the new version on this page with a new effective date at least 14 days before it takes effect, and email the address tied to your license where we have one. Continued use of the Service after the effective date means you accept the updated policy.
19. How to contact us
- Email: privacy@mylifepapers.com
- Support: support@mylifepapers.com
- Security (vulnerability reports): support@mylifepapers.com
- Mailing address: MyLifePapers LLC, 5900 Balcones Drive STE 100, Austin, TX 78731, United States
We aim to respond to every request within 5 business days.