Privacy Policy

Effective July 17, 2026

1. Who we are

Semparo is a product of Semparo LLC, a Texas limited liability company ("Semparo", "we", "us"). This policy explains what we collect, why we collect it, and what we can never see. Questions: contacts@semparo.com.

2. The short version

We collect the minimum needed to run a legacy vault: your account and contact details, the contact details of the people you designate, payment records, and basic service telemetry. Everything you place inside your vault is encrypted on your device before it reaches us, so we hold ciphertext only and cannot read it, sell it, or hand it to anyone in readable form. The operational details we do hold to run the service are encrypted at rest. We do not sell personal information, we do not share it for cross-context advertising, and we run no advertising and no third-party trackers.

3. The two kinds of data, and why the difference matters

Everything we handle falls into one of two buckets, and they are not the same:

At release, your vault content is decrypted for your chosen recipients inside hardware-isolated infrastructure, never for us.

4. What we collect

5. How we use it

We use your information to operate the vault and the release mechanism, to record your scheduled proof-of-presence and reach you when you stop responding, to take reasonable steps to confirm the identity of the people who confirm and receive a release, to send you service messages such as verification codes and alerts, to bill your subscription, to prevent fraud and abuse, and to meet legal obligations. Semparo does not determine or verify any fact about any person's status; the release mechanism responds to your signals and to declarations made by the people you designated. We send marketing email only if you asked for it.

6. Who we share it with

We use service providers that process data for us under contract:

If and when identity proofing is enabled for a release, an identity-verification provider may confirm that a person is who they claim to be; that provider is chosen to be provider-agnostic and is disclosed here when it goes live. We disclose information when the law genuinely requires it, but your vault content is ciphertext even to us, so a lawful demand can reach operational information only, never readable content. We never sell personal information and never share it for cross-context behavioral advertising.

Semparo operates from the United States. Your information is processed and stored in the U.S., and by using the service you consent to that.

7. How long we keep it

We keep your information for as long as your account is active, plus the retention window your payments have funded (up to 12 months after payments stop), because deleting a legacy vault too early could destroy an inheritance. After the window, data is archived and then deleted on a published schedule. Closing your account deletes your vault content. We keep a minimal audit record (that an account existed and what release actions occurred) for legal accountability; it contains no vault content.

8. Your rights and choices

You can read and correct your account details in the app, export a plain, readable copy of your data at any time, close your account, and email contacts@semparo.com to ask us to access, correct, or delete the personal information we hold about you. We respond within 45 days.

If you are a California resident, you have the right to know what personal information we collect and how we use it, to access and delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. You may make a request yourself in the app or by email, or through an authorized agent.

If you are in the European Economic Area or the United Kingdom, you have the rights of access, rectification, erasure, restriction, objection, and data portability. Our lawful bases are the performance of our contract with you (running the vault and the release mechanism), your consent (for the guides newsletter), and our legitimate interests (security and fraud prevention). You can withdraw consent and lodge a complaint with your local supervisory authority.

If someone designated you as a KeyKeeper or recipient, we hold your contact details on their behalf. You can ask us to correct those details, decline the role, or ask us to delete your contact information; if you do, we will tell the account owner so they can designate someone else.

9. Security

We protect your information with client-side encryption designed to resist both current and quantum-computing attacks, TLS in transit, encryption of operational data at rest, and strict internal rules that keep secrets and personal content out of our logs. We publish our security architecture for public review and run a vulnerability-disclosure process. No system is perfectly secure, which is exactly why Semparo is built so that a breach of us does not expose readable vault content. If a breach ever affects your personal information, we will notify you as the law requires.

10. Children

Semparo is for adults 18 and over. We do not knowingly collect information from children. A recipient who is a minor is reached through a lawful adult guardian.

11. Changes

We will post updates to this policy here. For material changes we will notify you and ask you to accept the new version.

12. Contact

Semparo LLC, Texas, USA. contacts@semparo.com.