Your data, your call
We collect what we need, share as little as possible, and keep your data only as long as it serves you


What information do you actually need from me?
We ask for the minimum we need to draft a valid will and run your account. We don’t ask for things “in case we need them later”.
The will itself
Your name, beneficiaries, assets and wishes: the content of your will.
Identity verification
A document and a selfie, kept only as long as the law requires.
The video identity check, if you choose to record one
You can optionally record a short video identity check to show that the person holding an identity document is the person on it. That recording is a video of your face and your voice, so it is biometric “special category” data (Article 9 of the UK GDPR) and we treat it separately from the document photograph it accompanies. We ask for your explicit consent immediately before you record, and we record that you gave it: the agreement you gave when you uploaded the document does not cover being recorded, and we never assume it does. Our lawful basis is your explicit consent under Article 9(2)(a). The recording is stored privately on our own servers, and it never leaves our servers without your approval; no automated face matching is performed on it, it is never used to train any model, and a member of our team watches it and decides. We keep it for as long as the document it supports is evidence on your account and delete it with that document; you can delete it yourself at any time from your profile, which is also how you withdraw your agreement to it.
Executor and witness ID
You can optionally upload an identity document for an executor or witness, only with their agreement, never required, processed on our own servers.
Identity check for a witness signing electronically
If you are invited to witness a will that is signed electronically, we ask you to prove who you are before you can sign as a witness. We ask for your agreement before any check runs and record that you gave it against that will. You upload a photo of your passport, driving licence or national ID card, which is checked automatically on our own servers and never sent to an outside AI provider. Where the place the will is made asks for it, you also record a short video identity check, which carries exactly the same protections as the video identity check described above. We record only the outcome of the check against the signing, so it can be shown later who witnessed the will. If the check does not succeed you can try again or contact support. Your photo ID and any recording are kept in your own account and you can delete them there.
A signing ceremony, if you sign your will electronically
Where the law that applies to your will allows a will to be signed electronically and we offer that route for it, you can sign in a guided signing ceremony instead of on paper. Those are two different things, and we tell you which is which on the signing guide. We record the ceremony itself: which will it is for, the rules it was started under, who took part and in what part they played, when each person joined, signed or declined, and whether each witness was verified before they attested. The people involved are the witnesses and other parties you had already recorded, so a ceremony introduces no new names of its own; what it adds is their part in it and the outcome. A witness is invited by email at the address you gave for them, and we keep only a one-way hashed form of the invitation link, so we cannot reconstruct a working link from our records. Our lawful basis is performing the contract you bought and our legitimate interest in carrying out your instructions.
Attendance evidence, where a witness attends by audio-visual link
Some places allow a witness to attend the signing by an audio-visual link rather than in the room. Where a ceremony is witnessed that way, we record whether the link actually held: when the window opened and closed, whether it was interrupted, and how many times. A ceremony cannot be completed on a window that was left interrupted. Where a recording of that window is made, it is made through the same verification-media flow as the video identity check described above and carries exactly the same protections: it is biometric “special category” data (Article 9 of the UK GDPR), we ask for explicit consent before it is recorded and rely on that consent under Article 9(2)(a), it is stored privately on our own servers and it never leaves our servers without your approval, no automated face matching is performed on it, and it is never used to train any model. The recording and the record that the ceremony happened are held separately on purpose, so an erasure request can remove the video without erasing the evidence that the will was properly witnessed.
How long we keep the record of how your will was signed
When your will is signed with us we keep a record of how it was signed: the signing ceremony and its outcome, who witnessed it and when, each witness’s attestation, and, for each person who signed, the network address and browser their signature was made from. We keep this so that you, and later your executors, can show how the will was signed and witnessed if that is ever questioned. Unlike the security records about your sign-ins, which we delete after 12 months, this record is kept for as long as we hold the will and then for seven years after the will is revoked or replaced by a later will, after which it is deleted. The network address and browser details are stored in the same protected form as the rest of our audit records; keeping them longer changes how long they are held, not what is held. When your will is executed we also email you its seal: a SHA-256 fingerprint of the signed will and its execution details, with the date it was sealed and the will version. That email is your own copy; we cannot change it after it is sent. Our lawful basis is our legitimate interest, and yours and your estate’s, in being able to evidence how your will was executed.
What your executors can see of the signing record after your death
Once a report of your death has been verified, an executor you named who has accepted the role can see the signing record of your will: the date it was signed, the names of the people who signed and witnessed it, the seal fingerprint with the result of checking it again, and whether it is the latest sealed version. They can download that record as a PDF. They never see your edit history, earlier versions of your will, anyone you removed from it, the network address or browser details of any signer, or who has opened your will. Each time an executor views or downloads the signing record we record it. Our lawful basis is our legitimate interest, and your estate’s, in your executors being able to show how your will was signed.
Where your signed original is kept, and how a professional’s engagement with you ends
If a professional prepares or reviews your will, they can record where the signed original is kept once it is signed: with their firm, with you, lodged with a will bank or deposit service, or somewhere else, with a short note such as a deed-store reference. You can see that record on your will, but only the professional can change it, and every change is logged. If the professional closes their engagement with you before your will is signed, we record when they closed it, the reason they chose from a short list (for example that they could not reach you, or that you signed elsewhere) and any note they add, and we email you to say it has closed and why. Their note is part of their own record of the matter and is not included in that email. A closed engagement can be reopened within 30 days. Our lawful basis is performing the contract for the service you asked the professional for and our legitimate interest in keeping an accurate record of that engagement. These records are kept with the engagement for as long as we keep its records.
A request to review a professional, only if they ask for one
A professional you have worked with can ask us to invite you to review their service once your matter with them is complete. We only do so if they have chosen to for your matter, and we send you a single email when you confirm the matter is complete; there are no reminders, and nothing is offered in return for a review. We use your name and email address for it and tell the professional only whether the invitation was sent; we never tell them why it was not, or whether you opened it. Leaving a review is optional. Every review is checked by our moderation team before it is published, and anyone can report a published review that breaks our rules. Our lawful basis is our and the professional’s legitimate interest in helping other people choose a professional on honest feedback. The invitation sits under “Suggestions and prompts”, which you can switch off from the link in the email or in your email preferences.
When a professional checks the scan of your signed will
If a professional is engaged on your will and you upload a scan of the signed copy, the professional checks that scan. Your will still counts as signed from the moment you upload it. We record whether they accepted the scan or asked for a new one, when they decided, who decided, which version of the scan they checked, the reason they chose from a short list (for example that a witness signature is missing or a page is hard to read) and any note they add. We email you their decision, and if they ask for a new scan we show their note on your will page and keep the earlier scan as a superseded version rather than deleting it. We send reminders if a scan waits too long for a check or for a new copy. The check is a record-keeping step by your professional, not a ruling on whether your will is legally valid. Our lawful basis is performing the contract for the service you asked the professional for and our legitimate interest in keeping an accurate record of how your will was signed. These records are kept with your executed will for as long as we keep it.
A record of the circumstances in which you gave your instructions
When you make a will with us we assemble a short record of the circumstances in which you gave your instructions, in the way a solicitor writes an attendance note at the time. It is built only from what you have already told us: when you gave your instructions, the confirmations you made about how the will is being made, what you recorded about your capacity to make it, the outcome of any identity check you completed, whether anyone helped you or was present, your own words for leaving somebody out, and the previous wills you told us about. It asks you nothing new and adds nothing of its own, and where you recorded something in your own words about your health it records only that you recorded it, never a copy of what you wrote. We seal it with a one-way checksum and link each record to the one before it, so it can be shown later that it has not been altered, and we keep the moment you gave your instructions separate from the moment the record was written so that the difference is visible rather than implied. It is held on our own servers alongside your will, and it is deleted with your will when you delete it. We also file a readable copy of it in your document vault, so you can open and download it at any time; that copy stays in your vault until you remove it yourself, in the same way as anything else you keep there. Our lawful basis is performing the contract you bought and our legitimate interest in being able to show that your will was properly made.
Account and payment
Email, password, and a payment method (handled by our payment processor).
Practice bank details on professionals’ invoices
If you are a professional, you can save payment instructions, such as your practice’s bank account details, and a short footer note to print on the invoices you issue to your clients. We store the payment instructions encrypted at rest on our own servers. When you send an invoice we copy them onto it, so the invoice your client holds keeps the details it was sent with even if you change them later. They are shown only to you, to members of your organisation who manage its billing, and to the client the invoice is addressed to. We never use them to make or take a payment ourselves. Our lawful basis is performing our contract with you and your legitimate interest in being paid. You can change or clear them at any time from your billing settings; invoices you have already sent keep the copy they carry for as long as we keep those invoices.
Logos, header images and signatures on professionals’ invoices
If you are a professional, you can upload a logo, a header image and an image of your signature to brand the invoices you issue, and choose an accent colour. We check each image for viruses, remove hidden details such as location and camera data before storing it, and keep it in private file storage that only the platform can read. A signature image can identify you, so upload one only if you want it printed on your invoices, and you can turn it off at any time. When you send an invoice we record the branding it was sent with, so the invoice your client holds, its PDF and the emails about it keep that branding even if you change it later. The images are shown only to you, to members of your organisation who manage its billing, and to the client the invoice is addressed to, including in the invoice emails we send them. Our lawful basis is performing our contract with you. You can replace or remove an image at any time from your billing settings; an image already on a sent invoice is kept for as long as we keep that invoice.
Documents you send in by email
You have one personalised inbound address for forwarding documents in, and you decide who may use it: only you, a short list of senders you name (your accountant or your solicitor, say), or anyone. You can switch inbound delivery off altogether, or rotate the address, at any time from your account, and mail that arrives after you switch off is rejected rather than stored. For every email that does arrive we keep a short delivery record (a one-way hash of the sender, its domain, and whether it succeeded or failed) so we can troubleshoot a delivery that doesn’t turn up. We keep a copy of the message itself, encrypted at rest, only while you have travel extraction switched on, because reading your travel dates out of an itinerary needs the text of the email; with travel extraction off, the attachments are filed in your vault and no copy of the message is kept. Reading it runs privately on our own servers, and it never leaves our servers without your approval.
Organ donation preferences
If you choose to record your organ and tissue donation wishes, that is health-related “special category” data (Article 9 of the UK GDPR). We only collect it because you chose to enter it, we process it on our own servers, and we only ever share it on your explicit instruction.
Healthcare decision documents
If you prepare a lasting power of attorney for health and welfare, or an advance decision to refuse treatment, the care preferences and treatment wishes you enter are health-related “special category” data (Article 9 of the UK GDPR). We collect only what the document needs (your decisions, not your full medical history) and we ask for your explicit consent to process that data when you create the document, before any section is saved. Our lawful basis is your explicit consent under Article 9(2)(a).
Will Location Registry: where your will is kept
If you use the Will Location Registry, we record where your will is stored and the people you choose to tell. We never store the contents of your will. The contact details you enter for a designated party or custodian are collected to notify them, on the basis of our legitimate interest in carrying out your instructions.
Files you upload, stored but not inspected
You can upload a document you already have, such as a will drawn up elsewhere, a lasting power of attorney or an advance decision, and record where the signed original is kept. Your vault takes almost any file type, not only documents, so what you keep there may equally be a scan, a photograph, a spreadsheet or a media file. We store the file and the details you enter about it. We do not read it for accuracy, check how it was signed, or confirm that it is valid. If you ask us to read a file to fill in details for you, that runs privately on our own servers, and it never leaves our servers without your approval for that specific document.
Where a health and welfare power of attorney or advance decision is kept
Recording where one of these is kept is itself health-related “special category” data (Article 9 of the UK GDPR), because these documents are about your health and are released at a point when your capacity is in question. Registering the location is your explicit consent under Article 9(2)(a) to release it to the people you designate, on the trigger you recorded. At the moment of release you may no longer be able to consent, so we rely on the vital-interests condition under Article 9(2)(c) instead, which is available only where you cannot consent. It is never available against your refusal, so switching disclosure off removes the basis entirely and we then refuse to release the location to anyone, including someone who has already been through a verified claim and already holds a link.
A registration you tell us about
Where a power of attorney or an advance decision has to be registered, you can tell us that you have registered it. We store the registration reference you enter, the date you say it was registered, when you told us, and, if you choose one, a link to a registered copy you already keep in your document vault. We do not check any of this against an official register, so wherever it is shown, including to anyone you share the document with, it is labelled as reported by you. We keep it for as long as we keep the document itself, and you can correct or remove it at any time.
Death and claim evidence
To unlock a sealed Registry Secure location, the person making a claim provides a death certificate, their own identity document, and a short verification video. We process this evidence (including the death record of the registered person) on our own servers, only to verify the claim. Our lawful basis is our and the claimant’s legitimate interest in seeing the will located and the estate administered, supported by the public interest in the proper administration of estates; where an identity document amounts to special-category data, we rely on the substantial-public-interest condition under the UK GDPR. Our team reviews it; a claim is never approved automatically.
Household and emergency information, only if you record it
You can optionally record practical household details for an emergency information pack: the recurring services and bills you pay (such as the provider, billing frequency and approximate amount) and household notes (such as pet care, medication reminders, home maintenance or utility access). We collect this only because you chose to enter it, and we process and store it on our own servers. It is never shown to anyone else unless you explicitly grant a trusted person access through the guardian sharing portal, and you can edit, exclude or delete any entry at any time. Our lawful basis is your consent, and carrying out your instructions.
Licence and permit details, only if you record them
If a possession you have listed can only be held under a licence, certificate or permit, such as a firearm held on a certificate, you can record what kind of permission it is, the body that issued it, the reference printed on it, when it expires and where the certificate is kept. The reference and the certificate location are encrypted, and the location follows the same visibility setting as the other access hints on that possession. We use it to tell your executors what exists and who to contact. We never contact a licensing authority, we do not apply for or renew anything for you, and we do not check that a permission is genuine or still in force. We collect this only because you chose to enter it, we process and store it on our own servers, and our lawful basis is your consent, and carrying out your instructions.
Pension and life cover details, only if you record them
Against a pension or retirement account you can record your member or scheme reference, the date you last reviewed your nomination with the scheme and the date it expires, if it has one. Against a life insurance policy you can record whether it is written in trust. The member reference is encrypted. We use these details to tell your executors what exists and who to contact. We never contact a pension scheme or insurer for you, we do not change a nomination or a trust, and we do not check that what you record is up to date. We collect this only because you chose to enter it, we process and store it on our own servers, and our lawful basis is your consent, and carrying out your instructions.
The country you sign in from, to show you relevant information
While you are signed in, we note the country your connection comes from: a two-letter country code supplied by our network provider, together with a one-way hashed form of your IP address used only to avoid recording the same day’s visit twice. We never store your actual IP address. We use this to surface the countries and guidance most relevant to where you are. It stays on our own servers, is never shared and is never used for advertising, and we keep it no longer than it remains useful for that purpose. Our lawful basis is our legitimate interest in tailoring the service to your location; you can object to it, or ask us to delete these records, at any time by contacting us.
Your approximate country, to tailor our public pages
When you visit our public pages, whether or not you have an account, our network provider tells our servers which country your connection appears to come from, as a two-letter country code worked out from your internet address. If you have chosen a country in the header country selector, we use that choice instead. We use the country only to tailor the page you are viewing: which features and prices we show, and a note when something is not yet offered in your country, with a list of the countries where it is. We work it out afresh for each page, and it is never stored against you, never added to your account or any profile, never shared and never used for advertising. If we cannot tell where you are, you see the standard version of the page. A page tailored to your country is never kept in a shared cache, so it is never shown to someone else. Our lawful basis is our legitimate interest in showing you information that applies where you are; you can always pick a different country in the header.
The devices you sign in from, to spot a sign-in that isn’t you
For each device you sign in from we keep a security record: the browser, operating system and device type, the IP address of that sign-in, and the location that address maps to. That location is a country, region and city, and also the approximate coordinates and time zone our geolocation database gives for the address. Those coordinates are approximate by design, accurate to a city rather than to a street, and they come from the IP address alone: we never ask your device for its location and we never use satellite positioning. We use this only to recognise your own devices and to flag a sign-in that does not look like you, such as one from a place you could not physically have reached since your last one. Unlike the country signal above, this record does hold the IP address itself, because a security record that cannot be matched to an address cannot tell one sign-in from another. It stays on our own servers, is never shared, is never used for advertising and never decides anything on its own. We delete the whole record once you have not used that device for 12 months, and everything in it, coordinates included, is erased when you anonymise or delete your account. Our lawful basis is our legitimate interest in keeping your account secure.
Where an identity document was uploaded from, to spot a document that isn’t yours
When you upload an identity document we compare the country your connection comes from with the country of the residence you told us about. If the two are grossly far apart, further apart than a fixed distance we set in advance, we keep a short record of it: the two country codes, how far apart they are, and when. We keep no IP address and no coordinates in that record. It is used only as one input to our automated checks on the document, and it decides nothing on its own: it never blocks your upload, never puts your document in a queue for a person to look at, and never changes anything you see. We know travellers, people living abroad and anyone helping a relative upload a document will sometimes trigger it, which is exactly why nothing hangs on it. The record is deleted when you anonymise or delete your account. Our lawful basis is our legitimate interest in preventing identity fraud on the service.
Key contacts: details of other people you record
You can record the people your family would need to reach: a GP, a solicitor, an accountant, a vet, a property manager. Some you enter directly; others we assemble from contact details you already recorded against an asset, so they appear in one list without you typing them twice. These are another person’s details rather than your own, so we collect only what is needed to reach them (name, organisation, role, phone and email) and never anything about them beyond that. We process and store it on our own servers. It is never shown to anyone else unless you explicitly grant a trusted person access through the guardian sharing portal, and you can edit or delete any entry at any time. Our lawful basis is our legitimate interest in carrying out your instructions.
Importing a person from your phone’s address book
In our iPhone and Android apps you can fill in a person’s details from your address book instead of typing them. Your phone shows you its own contact picker and hands us only the single contact you choose, so we never ask for permission to read your contacts and we never see the rest of your address book. From that one contact we take only the fields the form needs: name, email address and postal address. Phone number and date of birth are not taken, and the details simply appear in the form for you to check and correct. Nothing reaches our servers until you press Save, and if you close the form instead, nothing is kept anywhere. Once saved, these are another person’s details and we treat them exactly as we treat any person you enter by hand. Our lawful basis is our legitimate interest in carrying out your instructions.
Residency check-ins: the country, never your coordinates
If you turn on location check-ins in our app, your phone works out which country you are in and sends us only that country, the date and how accurate the reading was. We never receive or store your coordinates, and our servers refuse a check-in that contains them. To name the country, your phone uses its built-in location lookup, which on some devices asks Apple or Google under their own privacy terms. Check-ins are off until you turn them on.
Photographs of your possessions, analysed on our own servers
You can photograph a valuable item so that we suggest its details for you. The photograph is analysed by an AI model on our own servers and is never shared with any outside AI service. It is kept in your vault like any file you upload, until you delete it, and suggested details you do not save are discarded after 24 hours.
Emergency access requests from your emergency contacts
If you switch on emergency access for an emergency contact who has accepted the role, that person can ask to see your will or the vault documents you chose. We record the request and when it was made, tell you straight away, and keep the record of whether you denied it or it was granted when the waiting period ended. If it is granted, we disclose only what you chose to that one person, read-only and for a limited time, and we record each time they view it. If a death report about you has been verified, an executor contact can skip the waiting period. All of this is processed and stored on our own servers. Our lawful basis is carrying out your instructions. We use the contact’s own name and contact details only to reach them about this arrangement.
Your emergency Wallet pass
The pass shows your name, up to three emergency contacts, whether you have an advance decision and a health and welfare power of attorney on file (yes or no only), and a QR code for your emergency information page. It contains no medical details. It is held on your device and by Apple or Google’s wallet service, under their own privacy terms. You can revoke it from your account at any time; Apple Wallet then removes it, and a pass saved to Google Wallet should be deleted there as well.
Passport chip verification by a professional
A professional checking a client’s identity can read the passport chip on the professional’s own phone: the personal details, the facial image where there is one, and the chip’s digital signature, never fingerprints or iris images. We check the signature on our own servers. The professional is the controller and we act as their processor; they rely on their legal duty to verify identity (UK GDPR Article 6(1)(c)), and the facial image, as special category data, on substantial public interest (Article 9(2)(g)). It is kept and deleted under the same rules as their other identity captures.
Dictation that stays on the device
When a professional dictates a visit note in our app, the phone’s own on-device recogniser turns speech into text and the audio never leaves the device. Where a device cannot do that, and on our website, the audio is transcribed by our own speech engine on our own servers and deleted as soon as it has been transcribed; only the text is kept.
Transcripts and captions for your video messages
If you ask for a transcript of a video message, it is produced by a speech engine on our own servers. The transcript and captions are stored with the video and deleted with it, and are shared with other people only if you choose to share the captions.

Your data, on your terms
Start your will today: private by design, with rights you can exercise without a support ticket.

