The short version: the list, not the keys.

Never stored

  • Passwords, PINs, recovery codes. Not in any field, on any screen. The Vault rejects anything that looks like one.
  • The Gmail access token. Used inside the one scan you started, then discarded.
  • Message bodies. The scan fetches only the sender and the date of each message.

Stored for you

Your identity (name, email, sign-in methods) is held by our sign-in provider and managed from Settings → Profile.

Shared with a practice

If you signed up from a practice’s leave-behind and left sharing on, the practice sees: whether you have run the audit and when, how many accounts it found and how many are critical, how many envelope sections are done, how many executors are named, and your plan. Never the accounts, the vault, the kit text or the executors’ details. Switch it off or remove the link under Settings → Your data.

Deleting

Settings → Your data → Delete everything removes every account, vault entry, executor, kit section and cleanup request. Your sign-in stays. Because the envelope is printed, deleting here changes nothing for your family.