Legal
Privacy Policy
Last updated: June 1, 2026
AevumSecure is a digital legacy vault. You store sensitive things in it (passwords, recovery codes, documents, photos, videos, letters) so that the right people receive them if something happens to you. That only works if you can trust us with very little, so we designed the product to see as little of your data as possible, and this policy to be honest about what we do see.
The short version: your vault contents are encrypted with keys derived from your passkey or password, we collect a small amount of account information to run the service, we do not sell your data, and you can ask us to delete everything.
01Who we are
AevumSecure is available to people anywhere in the world. We act as the data controller for the account information described in this policy. For privacy questions or requests, contact us at hello@aevumsecure.com.
02What we collect
We collect two very different kinds of data, and we treat them very differently.
Account data (we can read this). Information we need to operate your account and contact you:
- Your name and email address.
- Your phone number, if you choose to add one (used for SMS reminders).
- Optional profile details such as a postal address or national ID reference, only if you use the legal-handshake feature that connects your vault to a lawyer or executor.
- Authentication records: passkey public keys, two-factor settings, session metadata, and security logs (for example sign-in timestamps and IP addresses).
- Check-in activity: when you last confirmed you are okay, which reminders we sent, and the state of any release process.
Vault contents (encrypted). Everything you put inside the vault: passwords, 2FA recovery codes, documents, photos, videos, and letters. These are encrypted with keys derived from your passkey or password before they are stored. Beneficiary contact details you enter are also stored encrypted. We store and move the encrypted data, but the content is locked to keys that come from your credentials.
We use dual-custody encryption. This means the encryption keys are derived from your credentials and wrapped using managed key infrastructure, so that controlled processes such as account recovery and the legacy release flow can work. We do not claim absolute zero-knowledge: a small set of tightly controlled server-side operations participate in key handling. We never use your vault contents for anything other than storing them and releasing them to the people you chose.
03How we use your data
- To create and secure your account, including passkey and two-factor sign-in.
- To store, sync, and release your encrypted vault items according to your plan.
- To run the check-in system: sending reminders by email and, if you opted in, by SMS, and starting the verification and cooling-off process when you stop responding.
- To notify your chosen beneficiaries and executor when a release happens.
- To respond to support requests and keep the service safe from abuse.
We do not sell your personal data, we do not use it for advertising, and we do not use the contents of your vault to train AI models.
04Service providers we rely on
We use a small number of vetted infrastructure, security, communications, and AI service providers to run AevumSecure. We choose industry-standard services, restrict access by role, and configure each provider to process only what its role requires:
- Storage and key management: managed cloud infrastructure stores encrypted files and encrypted vault records, and wraps encryption keys with controlled access and audit logging.
- Database, cache, and job scheduling: managed data and queue services support account metadata, encrypted records, rate limits, check-in reminders, and release timers.
- Email and SMS delivery: notification providers deliver account emails, check-in reminders, release notices, and optional SMS messages when you opt in.
- Authentication and session security: industry-standard authentication tooling supports passkeys, two-factor authentication, and sessions inside our controlled infrastructure.
- Homepage AI chat: if you type into the public concierge, that message is sent to an AI service provider to generate a reply. Do not paste vault secrets into the homepage chat.
Because some providers may operate outside Ghana and outside the European Economic Area, your data may be transferred internationally. Where that happens, we rely on contractual, technical, and organizational safeguards appropriate to the service being provided.
05Beneficiaries and executors
When you add a beneficiary or executor, you give us their name and contact details so we can reach them when it matters. We store that contact information encrypted, we contact them only for invitations, verification, and release events that you configured, and we never market to them. A beneficiary only ever sees the specific items you assigned to them, and only after the release process (including verification and the cooling-off period) has completed.
06How long we keep data
- While your account is active: we keep your account data and encrypted vault contents so the service can do its job.
- After a release: beneficiaries have a 90-day access window to retrieve the items assigned to them. After that window closes, we perform cryptographic cleanup: the keys needed to decrypt the released material are destroyed, which renders the underlying data unreadable.
- If you delete your account: we delete your account data and destroy the encryption keys for your vault. Some minimal records (for example billing or security logs) may be retained for a limited period where the law requires it.
07Your rights
We aim to comply with the EU General Data Protection Regulation (GDPR) and Ghana's Data Protection Act, 2012 (Act 843). Wherever you live, we extend these rights to you:
- Access: ask for a copy of the personal data we hold about you.
- Rectification: correct inaccurate account information.
- Erasure: ask us to delete your account and data.
- Portability: receive your account data in a machine-readable format. Your vault contents are already exportable by you, since only your credentials can unlock them.
- Objection and restriction: object to or limit certain processing, such as optional SMS reminders.
To exercise any of these rights, email hello@aevumsecure.com. We will verify your identity before acting on a request, because the alternative would be a security hole.
08Security
Security is the product. Vault items are encrypted with keys derived from your credentials, media files are encrypted on your device before upload, keys are wrapped with managed key infrastructure, sessions are short-lived, and sign-in supports passkeys and two-factor authentication. Releases require verification and a cooling-off period before anything is shared. No system is perfectly secure, and we will notify you and the relevant authorities of any breach as required by law.
09Children
AevumSecure is not intended for children under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
10Changes to this policy
If we make material changes to this policy, we will notify you by email before the changes take effect and update the date at the top of this page. Continued use of the service after the changes take effect means you accept the updated policy.