Privacy Policy

Last updated: July 17, 2026

1. Introduction

My Wishkeeper ("we," "our," or "us") operates the website wishkeeper-u5nf.polsia.app (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use My Wishkeeper to store and share end-of-life planning documents.

My Wishkeeper is a personal document vault for advance directives, medication lists, insurance cards, and similar planning records. We are not a covered entity or business associate under HIPAA, and we are not a clinical or medical record system. The data practices described below reflect that scope: we handle personal planning documents, not protected health information from a clinical provider.

2. Information We Collect

We collect information in three ways: (a) information you give us when you create an account or upload content, (b) information recorded automatically when others interact with the documents you've shared, and (c) information you submit through our public forms. The data we collect lives in the following stores:

Account data (users). When you sign up, we collect your name, email address, and a hashed password. We also store your subscription status (plan, subscription_status), billing reference (stripe_session_id), and timestamps for account creation and last update.

Sessions and password resets (sessions, password_reset_tokens). We issue an authenticated session token in a cookie when you sign in, and we store hashed one-time reset tokens if you use the password-reset flow. Reset tokens expire after one hour and are rate-limited to three per email per hour.

Uploaded document content (documents). We store the documents you choose to upload — advance directives, living wills, healthcare proxies, medications, emergency contacts, insurance cards, and government IDs — along with metadata you provide (titles, notes, document type, optional physical-copy location, official-form-appearance flag, and any special instructions you include for the Emergency Packet).

Contact and identification records (medications, emergency_contacts, insurance_cards, government_ids). We store structured records you enter for medications, emergency contacts, insurance card details (with optional uploaded image), and government-issued identity details (with optional uploaded image).

Emergency Packet configuration (emergency_packets). If you opt in to the Emergency Packet feature, we store per-user settings (date of birth, preferred hospital, and QR access settings) used to populate a printable emergency summary.

Sharing and QR access (share_links, qr_codes). We store share-link records (data scope, optional expiry, revocation state) and emergency QR codes (expiry, revocation state, scan counter) that you create.

QR scan audit log (qr_scan_logs). Each scan of an emergency QR code writes a row with the scan timestamp, the IP address of the scanner, and the user-agent string. Scan logs are retained for compliance and forensic purposes.

Payment status. When you subscribe, Stripe returns your subscription state to us; we store your plan, subscription status, and Stripe session identifier. Payment card data is handled entirely by Stripe — we never see or store your card number.

Facility inquiries (facility_leads). If you submit the interest form on /facilities, we collect your name, facility name, role, resident count, email address, phone number, and any message you provide.

Waitlist email capture (waitlist). If you submit your email on the homepage, we store that email with a source tag and timestamp.

Funnel analytics (analytics_events). We record server-side events for product analytics (for example, landing-page views, key feature usage). Event records contain an event type, optional metadata, and a timestamp. We do not include document content in these events.

3. How We Use Your Information

We use the information we collect for the following specific purposes, and only these:

4. Sharing and Disclosure

Sharing you control. You decide who can see your documents. Share links are scoped to the specific records you select and can carry an optional expiry; emergency QR codes are likewise scoped and may expire. Revoking a share link or QR code immediately blocks further access through that token, even if the recipient has the URL. We do not share your documents with anyone you have not explicitly authorized.

Service providers. We rely on a small set of third-party providers to operate the Service:

These providers receive only the data needed to perform their function and use it solely on our behalf.

Legal process. We may disclose information if required to do so by law, or in response to a valid court order, subpoena, or other legal process. Where lawfully permitted, we will make reasonable efforts to notify you before disclosing your information.

Change of control. If My Wishkeeper is acquired, merged, or sells substantially all of its assets, your information would transfer to the acquiring entity under the same privacy protections described in this Policy.

5. Data Storage and Security

We protect your information with layered controls. Uploads and downloads travel over TLS. Stored files sit with our cloud storage provider under their published security posture. Account passwords are stored as one-way cryptographic hashes; we never store your password in plaintext.

Sign-in sessions are issued as opaque tokens, stored in a cookie (session_token) and validated against the sessions table. Password reset tokens are single-use, hashed, expire after one hour, and are rate-limited to three per email per hour.

Share links and QR codes are scoped to the specific records you select and can be time-limited or revoked. Each QR scan is recorded in an audit log so that you — and the senior-care facilities using My Wishkeeper for compliance — can see who accessed what, and when.

No system is perfectly secure. We continuously review our security posture, restrict internal access to personal data on a need-to-know basis, and would notify affected users without undue delay in the event of a breach affecting their information.

6. Data Retention

Active accounts. Your documents, contact records, share links, and account data are retained for as long as your account is active. Closing your account or requesting deletion removes your documents and account data within thirty (30) days.

Audit logs. QR scan audit log rows may be retained longer than active-account records where they are needed to support facility compliance or to investigate suspected abuse. Audit log fields are limited to scan metadata (timestamp, IP, user agent) and are not linked to the underlying document content.

Aggregated analytics. Aggregated, non-identifying analytics events may be retained indefinitely.

7. Your Rights

If you are a U.S. resident, you have rights under applicable state privacy laws, including the California Consumer Privacy Act (CCPA / CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), and equivalent laws in other U.S. states where you reside. Regardless of where you live, or whether you live outside the United States, you can exercise these rights by emailing hello@wishkeeper.com; international users, including those in the European Economic Area, may use the same channel.

Your rights include:

To exercise any of these rights, email hello@wishkeeper.com. We will respond within the timeframes required by applicable law.

8. Cookies, Analytics, and Tracking

We use a small number of cookies and similar technologies:

My Wishkeeper does not use cross-site advertising cookies and does not allow third-party advertising networks to set cookies through our pages.

9. Children's Privacy

My Wishkeeper is intended for adults planning their own end-of-life documents or assisting an adult family member. The Service is not directed at children under 18, and we do not knowingly collect personal information from minors. If you believe a minor's information has been submitted to the Service, contact us at hello@wishkeeper.com and we will delete it.

10. Third-Party Services

We share data with the following third parties solely to provide the Service. Each provider has its own privacy terms, and My Wishkeeper is not responsible for their practices beyond the data-minimization commitments above.

11. International Transfers

My Wishkeeper is operated from the United States. Our cloud storage and payment providers may process data in regions outside your country of residence (including the United States and the European Union) under their published data-processing terms. By using the Service, you acknowledge that your data may be transferred to and processed in the United States.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If the changes are material, we will update the "Last updated" date at the top of this page and notify you by email or with a prominent notice in the product before the new terms take effect.

13. Contact

If you have questions about this Privacy Policy, or wish to exercise any of the rights described above, contact us at:

hello@wishkeeper.com
My Wishkeeper · South Florida · wishkeeper-u5nf.polsia.app