Privacy Policy
DRAFT — pending counsel review. Last updated May 2026.
Summary
The Executor Hub is a private workspace for estate executors. We collect only what is necessary to run the service. We do not sell, rent, or share your data with advertisers. We never use your estate content to train AI models.
Who we are
The Executor Hub is operated by [Operator] (“we”, “us”), a California-based company. For privacy questions, email privacy@theexecutorhub.com.
What we collect
- Account: your email address, full name (optional), and authentication tokens.
- Estate content: decedent name and dates, tasks, to-do items, notes, and family updates that you write.
- Family members: names and email addresses you invite as read-only viewers.
- Billing: Stripe handles your card details directly — we never see them. We store the Stripe customer/payment-intent identifier so we can match a payment to an estate.
- Operational logs: request metadata (timestamp, IP, user agent) for security and abuse monitoring.
How we use it
- To provide the service: store your estate, send invites, deliver updates.
- To process payments via Stripe.
- To answer support requests you initiate.
- To prevent abuse and meet legal obligations.
We do not use your data for advertising or for training third-party AI models. AI task help calls Anthropic with the catalogue task title and category name only — never your custom notes or family content.
Subprocessors
The vendors below process data on our behalf under DPAs:
- Supabase — database, authentication, file storage.
- Resend — transactional email (invites, family updates).
- Anthropic — AI task explanations (catalogue title + category name only).
- Stripe — payment processing.
- Netlify — application hosting.
Where your data lives
The Executor Hub is currently US-only. Data is stored in US regions. Visitors from the European Union and United Kingdom are blocked at the edge until we have built and certified a GDPR-compliant posture.
Retention
We retain your data while your account is active. You can delete an estate at any time, which removes its tasks, to-do, updates, and family records. Deleting your account removes all estates you own and your profile within 30 days, except for transaction records we are required to keep for tax and accounting purposes.
Your choices
- You can export your to-do list to PDF at any time.
- You can request a copy of, correction of, or deletion of your data by emailing the address above. We respond within 30 days.
- You can decline marketing email at sign-up; transactional email (invite acceptances, payment receipts, security notices) is necessary to operate the service and cannot be turned off.
Cookies
We use a single first-party cookie to keep you signed in. We do not use advertising cookies, third-party trackers, or session-replay tools.
Children
The service is not directed to anyone under 18 and we do not knowingly collect data from minors.
Security
Magic-link authentication, row-level security on every database table, signed Stripe webhooks, and HTTPS everywhere. No system is perfectly secure; we will notify affected users of any incident without undue delay.
Changes
When this policy changes, we will update the date above and notify active executors by email if the change is material.