GivePeace Privacy Policy
Version 3.0 — Effective July 30, 2026
This Privacy Policy explains how Give Peace Inc., a Delaware corporation ("Give Peace," "we," "us," or "our"), collects, uses, protects, and shares information when you use the GivePeace iOS app and the givepeace.co website (together, the "Service").
Privacy is not a compliance checkbox for us. You are recording words meant for the people you love most, sealed until after you pass away. We treat that trust as sacred, and this policy is written plainly — including being plain about death — so you know exactly what happens with your information, in life and after it.
When you create an account you will be asked to accept this policy; our servers record which version you accepted. This is Privacy Policy version 3.0, effective July 30, 2026. It replaces version 2.0. Questions any time: support@givepeace.co.
1. A Plain Summary
1.1 We collect what we need to run the Service: your profile, your relationships (trustees, recipients, friends), your messages and videos, your purchases, and signals that tell us whether you are still alive. We do not collect your precise location, your contacts, or anything biometric.
1.2 Your private videos are encrypted on our servers. Section 12 explains exactly how — including the honest part: Give Peace holds the encryption keys, because that is what lets us deliver your messages after you pass away. GivePeace is not end-to-end encrypted, and we will never pretend otherwise.
1.3 We do not sell personal information and we will not sell it — ever. We do not share it for advertising. There are no ad networks, ad trackers, or data brokers anywhere in GivePeace. We make money from the things we sell — never from selling your data or your attention. These are binding promises, not descriptions of current practice.
1.4 Your trustees never see who your recipients are or what your messages contain. Their role is death notification only.
1.5 When you add a trustee, recipient, or friend, you give us information about another person. Section 4 explains what we hold about them, how we contact them, and the rights they have — no account required.
1.6 We will email, text, and send push notifications asking you to confirm you are still alive when your proof-of-life process calls for it. While that switch is armed, you cannot fully turn those check-ins off — they are the safety mechanism that prevents your messages from releasing while you are alive. Pausing or disarming the switch turns them off.
1.7 You can get a copy of your data, correct it, and delete your account (30-day recoverable grace period, then permanent removal). Section 11 lists, item by item, the narrow things that survive deletion and why — including the archive that lets an armed message still reach your people if you pass away during that window.
1.8 We honor privacy rights for everyone, in every state, whether or not any particular law requires us to. Section 8 is the whole package.
2. Information We Collect
2.1 Account and profile. When you sign up we collect your name and display name, date of birth, and email address, plus your password (handled by Firebase Authentication — we never see or store your plaintext password). We also support Google and Apple sign-in; if you use them, we receive the basic identifiers those providers share, such as your name and email address. If you use Sign in with Apple's private email relay, we deliver mail to the relay address Apple gives us — and if that relay ever stops forwarding, our emails, including alive-check-ins, may not reach you.
2.2 Your date of birth is collected for one purpose: enforcing our age rules — 13+ to use the Service, 18+ to record or arm death-released messages, name trustees, or serve as a trustee. We do not use it for anything else, we do not collect precise location, and we do not collect government ID to verify age.
2.3 Phone number (optional). You can add a mobile number — U.S. and Canadian numbers — so we can reach you by text for check-ins and safety alerts. We verify the number by texting you a one-time code: the code is stored only as a one-way cryptographic hash (never in plain text), it expires after 15 minutes, and five failed attempts end the verification. Numbers are normalized to a standard international format. In the app, we display only the last four digits of the number on file.
2.4 Profile extras. You may add a profile photo, a coarse location (your city, region, and country — nothing finer), and up to ten "decade photos" — pictures from across your life, each with the age you were in the photo. All optional.
2.5 Your relationships. The trustees you invite, the recipients you choose, and the friends you add — including the names, email addresses, and phone numbers you enter for them. Because this is information about other people, it gets its own section: Section 4.
2.6 Your messages and videos. The private video messages you record, tombstone videos, prayers, and other things you create. Private videos are encrypted at rest (Section 12) and are not reviewed by our staff; sealed private messages are not reviewed by moderation and are accessed only where the law requires (Section 6.6).
2.7 Your plan ("will") state. Which messages are sealed, who they go to, whether your proof-of-life switch is armed or paused, and the state of any countdown. In the app we sometimes call this your "will" in the everyday, heartfelt sense; it is not a legal will.
2.8 Death-related information. Trustee death reports and confirmations, your responses (or non-responses) to "please confirm you're still alive" check-ins, death certificates uploaded by trustees for human review, and identity details recipients provide to claim a message.
2.9 Purchases. Token and wildflower order history, amounts, and Stripe transaction identifiers, plus the Stripe customer identifier linked to your account. Payments are processed by our payment processor, Stripe; we never receive or store your full card number.
2.10 Device and usage information. Device model, OS version, app version, language, push-notification tokens, and IP address — which also appears in our audit records and deletion records, so that security events and deletions can be investigated. Product analytics (PostHog) records pseudonymous usage events such as screens viewed and features used; it is configured not to attach your email address to analytics profiles, and you can opt out of product analytics at any time by emailing support@givepeace.co (subject "Privacy Request"). Crash and performance reports (Sentry) include device state and stack traces when the app fails; they are scrubbed of personal identifiers, and screenshots are stripped on sensitive screens.
2.11 People-search index. Limited public profile fields — your name, your profile photo, your follower count, and, once your family publishes a memorial, coarse memorial facts such as birth and death years — are indexed with our search provider, Typesense, so friends can find you in the app. When you delete your account, removal is propagated to that index.
2.12 Support correspondence. Emails you send to support@givepeace.co and our replies.
2.13 What we do not collect — and will not. No GPS or precise device location, ever — only the coarse city-level location you choose to add. No upload of your contacts. No advertising identifiers and no ad SDKs. No scanning or OCR of death certificates — review is human. And nothing biometric: we do not perform facial recognition, face matching, face-geometry scanning, or voiceprint analysis on any video, image, or audio, and we never create, derive, store, or transmit a biometric identifier or template from your videos, photos, or recordings. The optional Face ID lock on the app is Apple's, and it stays entirely on your device — no face data ever reaches us.
3. How We Use Your Information
3.1 To run the Service — create your account, store and encrypt your messages, maintain your relationships and plan state, show memorial pages, and operate the feed. (GDPR legal basis: performance of our contract with you.)
3.2 To determine death and deliver your messages — process trustee reports, run countdowns, send check-ins, review death certificates, verify recipients, and release messages to the people you chose. This is the core promise of the Service. (Legal basis: performance of our contract; for some post-death processing, our legitimate interest in honoring the instructions you set in life.)
3.3 To keep you safe from wrongful release — send safety-critical check-ins by push, email, and SMS; re-verify alive status before any release; audit the determination process. (Legal basis: performance of our contract.)
3.4 To process payments and deliver wildflower plantings. (Legal basis: contract; legal obligation for tax and accounting records.)
3.5 To secure the Service — detect fraud, abuse, false death reports, and unauthorized access; rate-limit suspicious activity; keep audit logs. (Legal basis: legitimate interests; legal obligation.)
3.6 To moderate public spaces — review reported posts, quarantine them pending review, and protect memorial spaces from abuse. Sealed private messages are never part of this (Section 6.6). (Legal basis: legitimate interests; contract.)
3.7 To improve the product — analyze pseudonymous usage analytics and crash reports. (Legal basis: legitimate interests; consent where required.)
3.8 To support you — answer your emails and resolve problems. (Legal basis: contract; legitimate interests.)
3.9 To comply with law — respond to lawful requests and keep legally required records. (Legal basis: legal obligation.)
3.10 Marketing, narrowly. If we send promotional email, every message includes an unsubscribe link, and unsubscribing never affects safety-critical check-ins (which are not marketing). Our emails come from addresses ending in @givepeace.co. We never text marketing (Section 7), and we never use your information for third-party advertising of any kind.
4. Information About People You Add: Trustees, Recipients, and Invitees
When you name a trustee, choose a recipient, or invite a friend, you give us personal information about someone who has not yet agreed to anything. We take that seriously, and this section is addressed to them as much as to you.
4.1 What we hold. For each person a member adds we hold: the name, email address, and/or phone number the member entered; the role they were added for (trustee, recipient, or friend); the state of any invitation (sent, accepted, declined, expired); and, for recipients, an internal reference linking them to a sealed message — never the message's words, which stay encrypted.
4.2 We will contact them before they have consented — here is how. The first time we reach someone, it is because a member asked us to: a trustee invitation, a friend invitation, or — after a death has been verified — a message telling a recipient that someone left them something. Every first message identifies GivePeace, explains why we are writing, links to this policy, and makes it easy to say no. We use these contact details only to deliver what the member set up — never for marketing, and never for anything else.
4.3 Invitations expire, and "no" is respected. Trustee and friend invitations expire after 30 days if not accepted, and their records are removed after 45 days. Declining is always available and can be reversed while the invitation lasts. Whether or not an email address or phone number already belongs to a GivePeace account, an invitation behaves identically — no one can use an invitation to discover whether you have an account.
4.4 The trustee boundary. A trustee's only role is to tell us a person has passed away, and to confirm or contest what others have reported. A trustee is not a fiduciary, does not hold or inherit anything, and can never see who a person's recipients are, which messages exist, or what any message says.
4.5 Why we may hold a recipient's details for years. A sealed message can wait decades. We keep the contact details a member gave us for a recipient for as long as a message addressed to that recipient remains sealed, because those details are the only way to keep the member's promise. We never rent, sell, or share phone numbers, text-message opt-in records, or any other contact information — for any reason.
4.6 Your rights if someone added you — no account needed. If a member has entered your details, you can, without creating an account and without any verification code beyond what is reasonably needed to know we are talking to the right person: ask us what we hold about you; correct it; object to further contact; opt out of text messages (our SMS & Communications Terms explain how, including by reply); or ask us to delete your contact details. Email support@givepeace.co with the subject "Privacy Request." Be aware of the honest consequence: if we delete or stop using your contact details, a message a person recorded for you may never be able to reach you. We will tell you that plainly before we act, and then we will do what you ask.
4.7 Their own terms, their own choice. Trustees and recipients are never bound by a member's acceptance of anything. A trustee accepts the Trustee & Recipient Terms when accepting an invitation; a recipient sees them when claiming a message. Until then, the only relationship they have with us is the one this section describes.
5. What Happens With Your Information Around Death
This deserves its own section, written plainly. The full process lives in our Death Verification & Posthumous Release Policy; here is what it means for your information.
5.1 Before anything else: your death status is private. If a trustee reports that you have passed away, that report — and the countdown it starts — is visible only to you, your trustees, and us. Recipients are not told anything before release. Other users cannot look up whether you have passed away. Your memorial becomes visible to others only when your family chooses to make it visible — never automatically because a death was reported or confirmed. We will not let an app be how someone learns of a death before the family has shared the news.
5.2 During a countdown we process trustee reports and confirmations, your check-in responses, and any death certificate a trustee uploads. Certificates are reviewed by people, not software — we run no OCR or automated extraction on them — and the moment a certificate about you is uploaded, we notify you, before we have even reviewed it. One tap on "I'm alive" cancels the process at any stage.
5.3 At release, each sealed message is decrypted and delivered only to its chosen recipient, who may need to verify their identity to claim it. Released messages become available to those recipients to view and keep.
5.4 After release, memorial features you chose (tombstone video, memorial page) become visible per your settings and your family's choices, and others may add prayers and wildflowers to your memorial, subject to moderation.
5.5 Trustees stay blind. At no point — before, during, or after release — do trustees see who your recipients are or what any message contains. They see only the state of the process they are part of.
5.6 Your designations are recorded, and they control. Who receives your messages, and who serves as your trustee, is recorded through your Digital Legacy Designation Agreement — a separate agreement you accept in the app and can change at any time while you are alive. In most U.S. states, directions recorded in an online tool like this take priority over conflicting instructions found elsewhere. Nothing in this policy or our Terms of Service overrides a designation you recorded.
5.7 A deceased member's privacy continues. We protect a deceased member's information with the same care as a living member's — and we do not delete a deceased member's account, because preserving their words for the people they chose is the product working, not a policy gap (Section 11.6). Family members and estate representatives may contact support@givepeace.co; our Legal Process & Estate Requests Policy explains exactly how those requests work and how we verify who we are talking to.
5.8 Wrongful-report protection. Records of death reports, confirmations, check-ins, and releases are kept (Section 11) so the process can be audited and any wrongful report investigated.
6. Who We Share Information With
6.1 We do not sell personal information, and we will not — ever. Not to anyone, not for any price, and this includes what the law calls sensitive data. We do not share personal information for cross-context behavioral advertising, and we never have. We never sell or share the personal information of anyone under 18, and never use anyone's information — child or adult — for targeted advertising or profiling. These statements are unconditional and permanent: they are commitments, not descriptions of current practice, and they bind us and anyone who ever succeeds us (Sections 6.5 and 17).
6.2 Service providers (processors). We share information with providers who process it on our behalf, each under a contract that restricts its use of your information to providing its service to us and requires protection at least as strong as this policy. None of them may use your information for their own purposes, and we do not allow any of them to extract biometric identifiers or templates from your videos, photos, or recordings.
| Provider | What they do for us | What they process |
|---|---|---|
| Google Firebase (Authentication, Cloud Firestore, Cloud Messaging, Storage, Functions) | Sign-in, database, push notifications, file storage, and the server code that runs the Service | Account credentials, profile, relationships, plan state, push tokens |
| Google Sign-In | Optional sign-in | Name and email from your Google account |
| Apple | Sign in with Apple; Apple push notifications | Sign-in identifiers (including private relay email addresses); push delivery |
| Amazon Web Services — KMS | Hardware-backed management of encryption keys | Wrapped per-account encryption keys |
| Amazon Web Services — S3 and Glacier | Encrypted storage (U.S. regions); death certificates live in a separate private bucket | Encrypted videos, uploaded certificates |
| Amazon Web Services — SES | Email delivery | Email addresses and the notices we send |
| Amazon Web Services — SNS | Text-message delivery | Phone numbers and the texts we send |
| Amazon Web Services — MediaConvert | Video processing (transcoding) | Videos during processing; staging copies are deleted within 4 hours |
| Amazon Web Services — CloudFront | Fast, secure delivery of app media | Delivery logs (IP address, files requested) |
| Amazon Web Services — SSM | Server configuration management | Service configuration — no member profiles or messages |
| Stripe | Payment processing | Name, email, payment details (card numbers go to Stripe, never to us), Stripe customer ID |
| Sentry | Crash and performance reporting | Device info, app state, stack traces — scrubbed of personal identifiers; screenshots stripped on sensitive screens |
| PostHog | Product analytics (U.S. cloud, us.i.posthog.com) | Pseudonymous usage events and device info; no email attached to profiles |
| Typesense Cloud | People search | Public profile fields (name, profile photo, follower count, and published-memorial birth and death years); deletions are propagated to the index |
| Upstash (Redis) | Rate limiting to protect against abuse | Short-lived request counters tied to identifiers such as IP address or account ID |
| Expo (EAS) | App build and update infrastructure | App version and basic device information when the app checks for updates |
6.3 Recipients and other users. We share your information with others when you direct it: a released message goes to its recipient; an invitation goes to the trustee or friend you invited; your public memorial pages, profile name, and feed posts are visible to other users as those features describe.
6.4 Legal requirements. We may disclose information if required by law, subpoena, or court order, or where necessary to prevent imminent harm to someone's life or safety. Where the law allows, we notify you before disclosing your information, and we resist overbroad requests. Our Legal Process & Estate Requests Policy explains exactly how we handle legal demands and requests from families and estates. We do not voluntarily hand information to data brokers or advertisers — there is nothing to hand.
6.5 Corporate events — no bankruptcy loophole. We will not transfer your personal information, your messages, or your keys to any unaffiliated person or company — whether in a merger, acquisition, asset sale, reorganization, or bankruptcy — unless that party first assumes, in writing, the commitments of this policy and the wind-down commitments in our Terms of Service. There is no exception to this for financial distress or bankruptcy: a buyer who will not honor these commitments does not get the data. Section 17 describes what happens if we ever wind down.
6.6 Moderation and abuse review. Staff may view posts you made public (memorial pages, prayers, feed posts) when they are reported. Sealed private messages are not reviewed by moderation and are accessed only where the law requires; any such access is logged.
7. Communications — and the Check-Ins You Cannot Fully Opt Out Of
7.1 While your proof-of-life switch is armed, or while any death-report countdown is running, we will send you "please confirm you're still alive" check-ins and countdown notices by push notification, email, and SMS — including a final notice 48 hours before any release.
7.2 You cannot fully opt out of these while the switch is armed, because they are the mechanism that protects you from a wrongful release. If we let you silence them while the switch is armed, a silenced phone could mean your messages are released while you are still alive. That is not a trade we will make.
7.3 To stop these communications: pause or disarm your switch in the app, or delete your account. Pausing freezes everything — nothing can release while paused. Carrier message and data rates may apply to SMS.
7.4 Our text messages are transactional only — codes, life-check confirmations, safety alerts about your account, and message-delivery notices. We do not send marketing texts, and messages sent when someone passes away never contain anything promotional.
7.5 Everything else about texting — opting in, opting out, carriers, and frequency — lives in our SMS & Communications Terms.
8. Your Rights and Choices — for Everyone, in Every State
We honor the rights in this section for every person, in every U.S. state, regardless of where you live and regardless of whether any particular privacy statute applies to a company of our size. These are commitments we make to you, not claims about which laws bind us.
8.1 Access and copies. You can view your information in the app and request a complete copy of your data — including your own unreleased videos — as a downloadable ZIP archive, by emailing support@givepeace.co (subject "Privacy Request").
8.2 Correction. You can edit your profile in the app, or ask us to correct anything you cannot edit yourself. Date-of-birth corrections go through support and are logged, because our age rules depend on that field.
8.3 Deletion. You can delete your account in the app. Deletion starts a 30-day recoverable grace period, then becomes permanent. Section 11 owns the full story, including the short list of things that survive and why.
8.4 Portability. The export in Section 8.1 is provided in a portable, commonly used format.
8.5 Opt-outs that have nothing to bite. State laws give people the right to opt out of the sale of personal data, sharing for targeted advertising, and profiling with significant effects. We do none of these — for anyone, of any age — so there is nothing to opt out of. If we ever wanted to change that, we would have to change this policy first, with notice (Section 19), and Section 6.1's promises do not permit it.
8.6 Deactivation choice. If you deactivate, we ask whether to keep your switch armed (check-ins continue; if you pass away, your messages still go out) or pause it (nothing can release). Only you know which you want, so we ask instead of guessing.
8.7 Notifications and analytics. You can turn off non-safety notifications in the app or your device settings (safety-critical check-ins follow Section 7), and you can opt out of product analytics at any time by emailing support@givepeace.co (subject "Privacy Request").
8.8 No retaliation. We will never degrade your service, charge you more, or treat you worse for exercising any privacy right.
8.9 How requests work. Requests are free. We respond within 45 days; if a request is complex we may take one additional 45-day extension, and we will tell you if so. We verify identity in proportion to the sensitivity of the request — a request touching videos or death certificates requires stronger proof than a request about an email preference — because on this Service, handing data to the wrong person is the greater harm. You may use an authorized agent; we verify the agent's authority and your identity. If we decline a request, we tell you why, and you can appeal by replying — a human being, not a filter, takes the fresh look.
8.10 No account? Same rights. Trustees, recipients, and invitees can exercise every right in this section without creating an account (Section 4.6).
9. United States State Privacy Notices
9.1 Some state laws require specific disclosures. We make them here — and where a state grants rights, Section 8 already grants them to everyone, without threshold tests.
9.2 Categories we collect (described in Section 2): identifiers (name, email, phone, account IDs); customer records (date of birth, purchase records); commercial information (purchases); audio/visual information (your videos and photos); coarse geolocation (city-level only — never precise); internet or app activity (usage and device info); and inferences only as needed to operate safety features (such as inactivity signals). We collect them from you, your device, and the people who invite you. We use them as Section 3 describes and disclose them only as Section 6 describes. The categories of third parties who receive information are the service providers named in Section 6.2 and the people you yourself direct us to (Section 6.3).
9.3 Sensitive information, honestly sorted. Your account credentials and the contents of your private messages are sensitive personal information under state laws; we use them only to provide the Service you asked for — never to infer characteristics about you and never for advertising — so no "Limit Use of Sensitive Personal Information" control is needed. Your date of birth and coarse city-level location are not sensitive data under these laws, though we protect them carefully anyway. One thing deserves saying plainly: what you choose to post on public memorial spaces — a prayer, a tribute, a remembrance — can reveal things like religious belief, health history, or family relationships. Public posts are public; post what you want the world to see, and the choice to post is always yours and always affirmative.
9.4 No sale, no sharing — stated the strong way. We do not sell personal information and we will not sell it to any third party. We do not sell sensitive data. We do not share personal information for cross-context behavioral advertising. We never sell or share the personal information of anyone under 18, and never use it for targeted advertising or profiling. None of this has ever happened in the Service's history, and there is no "Do Not Sell or Share My Personal Information" link because there is nothing behind such a link — no sale or sharing exists to opt out of.
9.5 Tracking signals. Our responses to Global Privacy Control and Do Not Track are in Section 16 — the short version is that there is no tracking here for a signal to switch off, and we honor GPC on our website anyway.
9.6 California "Shine the Light." We do not disclose personal information to third parties for those parties' direct marketing purposes. There is nothing to request a list of.
9.7 Washington and Nevada consumer health data. Our standalone Consumer Health Data Privacy Policy — separately linked from givepeace.co — governs the narrow categories those laws define, such as responses to alive-check-ins and information on death certificates. It is its own document by design; this policy does not modify it.
9.8 Deceased persons. State privacy laws are written for the living. We nonetheless extend the protections of this policy to deceased members' information (Section 5.7), because our whole product is a promise to people who will not be here to enforce it.
10. European and U.K. Privacy Rights (GDPR)
10.1 GivePeace is operated from the United States and offered for use in the United States. If the GDPR or U.K. GDPR nonetheless applies to you, Give Peace Inc. is the data controller, and we honor it as follows.
10.2 Legal bases are noted clause-by-clause in Section 3: contract performance (the Service, death determination, delivery, payments), legitimate interests (security, moderation, analytics, post-death completion of your instructions), consent (optional marketing and analytics where required), and legal obligation (records, lawful requests).
10.3 Your rights: access, rectification, erasure (Article 17 — honored even during any wind-down of the company), restriction, portability, objection (including to any processing based on legitimate interests), and withdrawal of consent at any time without affecting prior processing. Exercise them via support@givepeace.co. We do not make automated decisions producing legal effects about you without human involvement — death determination always includes human-reviewable safeguards, multiple human-response windows, and manual review of certificates.
10.4 Transfers. Your data is processed in the United States (Section 14). Where required, we rely on Standard Contractual Clauses and equivalent safeguards with our processors.
10.5 Complaints. You may lodge a complaint with your local supervisory authority, though we would welcome the chance to resolve your concern first at support@givepeace.co.
11. How Long We Keep Information — and What Survives Deletion
11.1 We keep information only as long as it serves you or the law requires. Where this product differs from others — keys that must outlive an account to deliver a deceased person's words — this section says so plainly, with numbers.
11.2 Retention schedule:
| Information | How long we keep it |
|---|---|
| Profile (name, date of birth, email, phone, photo, coarse location, decade photos) | While your account is active, plus the 30-day deletion grace period |
| Unreleased sealed messages (encrypted) | Until you delete them or your account deletion becomes permanent |
| Encryption keys | Life of the message; after account deletion, only the delivery archive in Section 11.4(a) remains |
| Relationships (trustees, recipients, friends) | While your account is active, plus the 30-day grace period |
| Trustee and friend invitations | The invitation expires after 30 days; its record is removed after 45 days |
| Phone-verification codes | 15 minutes, stored only as hashes; five failed attempts end the attempt |
| Message claim links | 30 days; a released message that goes unclaimed times out after 30 days |
| Death certificates pending corroboration | Moved to a restricted archive after 30 days; thereafter governed by the death-determination row |
| Video-processing staging copies (transcoding) | Deleted within 4 hours |
| Prayers on memorials | Hidden from public view after 24 hours; retained as part of the memorial record |
| Wildflower tributes | Shown on the memorial for 14 days; purchase records follow the payment row |
| Public memorial pages and tombstone videos | While the memorial remains published |
| Released messages | Held for their recipients for as long as those recipients keep them |
| Death-determination records (reports, confirmations, check-in logs, certificates, release logs) | 7 years after release or account closure, for auditability and wrongful-report investigation |
| Purchase and payment records | 7 years (tax and accounting law) |
| Audit records, including deletion records (these include IP addresses) | 7 years |
| Analytics events | 24 months |
| Crash reports | 90 days |
| Server and security logs | 12 months |
| Support correspondence | 3 years after the matter closes |
| Text-message consent and opt-out (suppression) records | Kept while we may text you, and after that — including after your account is deleted — for as long as we need them to honor a STOP request and to meet carrier and regulator obligations |
| Data of an account we terminated for a material breach | 30 days from our termination notice — the appeal window in Section 11.7 |
11.3 How deletion works. You delete your account in the app, and we confirm it is really you with a code sent to your email or verified phone. The first thing deletion does is pause your proof-of-life switch, so nothing can move toward release while deletion is pending. Then a 30-day grace period runs: your account is deactivated but recoverable — sign back in within 30 days and choose to restore, and everything is back. During the grace period we keep your original email address on file solely so recovery works. After 30 days, deletion becomes permanent: your profile, your plan ("will"), your token balance, your relationships, your sign-in records, your stored files, and your entries in our search index are permanently removed, and the removal is propagated to our search provider.
11.4 What survives deletion — the complete list. These, and only these, outlast a permanent deletion:
(a) The delivery archive. If you left messages armed for delivery and acknowledged during deletion that they should still deliver, we keep a minimal delivery archive — your account's encryption key and references to those armed messages — solely so they can still reach the people you chose if you pass away. (b) Released messages. Messages already delivered belong to their recipients' experience of the Service and are not clawed back by your deletion. (c) Audit records, including deletion records, with the IP addresses in them — kept per the schedule above so that deletions, releases, and security events can be investigated, including for your protection. (d) Payment and tax records the law requires us to keep. (e) Legal holds. Information subject to a litigation hold, a preservation request from law enforcement, or another legal preservation duty is kept for the duration of that duty, then handled per this section. (f) Copyright-dispute preservation. Material that is the subject of an active notice or counter-notice under our Copyright & DMCA Policy is preserved while that process runs. (g) Text-message consent and opt-out records. If you gave us a mobile number, we keep a record of your text-message consent and of any opt-out or suppression request — the number, and the fact and date of the consent or the opt-out — so that a STOP request is still honored after your account is gone, and because carriers and regulators can require us to produce it.
11.5 If you pass away during the grace window. If you pass away during the 30-day grace period, the messages you left armed still deliver, through the delivery archive — and the rest of the deletion completes. Your words reach your people; everything else goes.
11.6 Deceased members' accounts are preserved. We decline requests to delete a deceased member's account. Delivering and preserving what they sealed is the promise they paid us to keep; our Legal Process & Estate Requests Policy explains the narrow paths families and estates can use.
11.7 If we terminate your account. If we terminate your account for a material breach of our Terms of Service, your sealed unreleased messages are not delivered, and your data is retained for 30 days from the date of our termination notice — the appeal window — so that an appeal can actually be decided on the record, and then deleted under this section.
11.8 Deleting one message. Deleting an individual unreleased message deletes its encrypted video and keys permanently. No one, including us, can recover it.
12. How We Protect Your Information
12.1 Your videos and messages are encrypted in transit and at rest. Each account has its own encryption key, protected by a hardware-backed key management service, and every video is sealed with authenticated AES-256 encryption derived from that key, with an additional layer of server-side encryption on our storage. Give Peace holds and controls these keys — that is what makes it possible for us to deliver your messages after you pass away. It also means Give Peace is technically able to access encrypted messages, and can be required to produce them in response to valid legal process. GivePeace is not end-to-end encrypted.
12.2 In concrete terms: keys are protected by AWS Key Management Service, and encrypted videos are stored in AWS S3 and Glacier in U.S. regions. All data moves over encrypted connections (TLS). Passwords are handled by Firebase Authentication; we never store them in plaintext. Database rules enforce that your private records are readable by you alone — other users see only the public profile you present. Internal access to production systems is restricted and logged.
12.3 Death certificates get extra care: they are stored in a separate private bucket, and access is limited to authorized Give Peace personnel through links that expire after 15 minutes, with every access logged. Review is human — no OCR, no automated extraction.
12.4 The death-determination process has its own safeguards: multi-trustee corroboration requirements, transactional alive-status re-checks at the moment of release, and audit logs of every step.
12.5 No system is perfectly secure, and we will not pretend otherwise. What we promise is serious engineering, honest disclosure (Section 13), and that security decisions always weight a wrongful release as the worst outcome.
13. If There Is a Breach
13.1 If a breach of security affects your personal information, we will notify you by email without unreasonable delay after we confirm it — and in any event within the time applicable law requires — and tell you plainly what happened, what information was involved, and what we are doing about it. We notify regulators within the timeframes the law sets, including, where the GDPR applies, the supervisory authority within 72 hours as that law requires. We will never quietly sit on a breach of your trust.
14. Where Your Information Lives
14.1 GivePeace is operated from the United States and offered for use in the United States, and your information is stored and processed in the United States, including AWS U.S. regions. If you use the Service from elsewhere, your information is transferred to the U.S., where privacy laws may differ from your country's. Where GDPR-style rules apply, the safeguards in Section 10.4 govern those transfers.
15. Children and Minors, by Age Band
15.1 How we know your age. Every sign-up path — email, Google, and Apple — collects your date of birth, and our servers enforce the age rules; the gates fail closed. The date-of-birth screen is neutral: you enter your real birth date freely, nothing is pre-filled, and nothing hints at a "right" answer. Corrections to a date of birth go through support and are logged. We do not collect government ID to verify age.
15.2 Under 13: not permitted. GivePeace is not directed to children under 13, and children under 13 may not create accounts. We do not knowingly collect personal information from a child under 13. If we learn an account belongs to one, we close the account and delete its information promptly — the 30-day grace period in Section 11 does not apply; the deletion is not recoverable. Parents and guardians who believe a child under 13 has an account: email support@givepeace.co and we will act promptly.
15.3 13 to 17: full protection, limited powers. Members aged 13–17 can use the Service but cannot record or arm death-released messages, name trustees, or serve as trustees — those require 18. For every member under 18, we process personal information only as strictly necessary to provide the Service and keep it safe. We never sell or share a minor's personal information, never use it for targeted advertising, and never profile a minor. There are no exceptions.
15.4 18 and over. Adults can use everything: record and arm messages, name trustees, serve as a trustee, and make purchases.
15.5 Receiving is never age-gated. A person under 18 — including a child under 13 — can always receive and view a message a loved one left for them. Grief does not check ID, and we will never lock a young person out of words recorded for them. For an under-13 recipient without an account, we process only what delivery requires: the contact detail the member gave us and the identity check the claim calls for — nothing more, and never for any other purpose.
15.6 Age signals from app stores. Where a state law requires app stores to share an age category with the apps you download, we use any such signal for exactly one purpose: applying the age rules in this section. We evaluate the signal, keep only the resulting age band, and do not retain the raw signal after the check. We never use age signals for marketing, advertising, or profiling, and we never share them.
16. Cookies, SDKs, and Tracking Signals
16.1 There is no tracking here. No advertising SDKs, no advertising cookies, no cross-site or cross-app tracking, no data brokers, no fingerprinting. No third party collects information about your activity over time and across other websites or apps through our Service: PostHog and Sentry operate solely as our service providers, on our own app and site, for our own purposes.
16.2 The iOS app includes these SDKs: Firebase Authentication, Cloud Firestore, Firebase Cloud Messaging, and Firebase Storage, plus Google Sign-In (Google); Stripe (in-app wildflower payments); Sentry (crash and performance reporting, scrubbed as Section 2.10 describes); PostHog (analytics, pseudonymous, opt-out via support@givepeace.co); and Expo (app infrastructure and updates).
16.3 The givepeace.co website uses these cookies and tools:
| Cookie / tool | Provider | Purpose | Type / duration |
|---|---|---|---|
| Session cookie | Give Peace | Keeps a signed-in session working on pages we operate | Strictly necessary; expires within 24 hours |
| __stripe_mid / __stripe_sid | Stripe | Fraud prevention on Stripe's secure payment pages, set by Stripe when you make a purchase it processes for us | Strictly necessary; 1 year / 30 minutes |
| PostHog (ph_* keys, local storage) | PostHog | Usage analytics | Optional; consent-based where required; 12 months |
Where law requires, the website shows a consent banner for the optional analytics entry; declining it changes nothing about what you can do on the site.
16.4 Do Not Track. Some browsers send a "Do Not Track" signal. Because we do not track anyone across other sites or over time, there is no tracking for the signal to turn off: our practices are identical whether or not your browser sends DNT.
16.5 Global Privacy Control. We do not sell or share personal information, so opt-out preference signals such as GPC have no sale or sharing to stop — that is the reason, not an oversight. We honor GPC on givepeace.co anyway: a browser sending GPC is treated as opted out of the optional analytics above.
17. If Give Peace Inc. Ever Shuts Down
17.1 Our Terms of Service contain a binding wind-down commitment, summarized here because it is a privacy promise too: at least 90 days' email notice; your choice during that window to export your unreleased videos, continue scheduled delivery through a successor custodian (only if one exists, and only if you opt in), or have everything deleted immediately; completion of deliveries already in flight for members who have passed away; and — if there is no successor or you choose nothing — permanent destruction of all encrypted messages and keys as the default. Erasure rights, including GDPR Article 17, are honored throughout.
17.2 These commitments, and Section 6.5's rule that no unaffiliated party ever receives your information without assuming them in writing, bind any acquirer or successor — in any transaction, including bankruptcy. Your words will never be sold off or left behind as someone else's database.
18. Related Policies
This policy is part of a set. Where a topic has its own document, that document controls the detail:
- Terms of Service — the agreement that governs the Service, including purchases, refunds, disputes, and the wind-down commitment.
- Consumer Health Data Privacy Policy — the standalone policy for consumer health data under Washington and Nevada law, separately linked from givepeace.co.
- Digital Legacy Designation Agreement — the separate agreement, with its own acceptance, recording who receives your messages and who serves as your trustee.
- Death Verification & Posthumous Release Policy — the complete death-verification and release process.
- Trustee & Recipient Terms — the terms trustees and recipients accept for themselves.
- SMS & Communications Terms — how texting works, including opt-in and opt-out.
- Legal Process & Estate Requests Policy — how we handle subpoenas, law-enforcement demands, and requests from families and estates.
- Community Guidelines — the rules for public memorial spaces and the feed.
- Copyright & DMCA Policy — copyright notices, counter-notices, and preservation.
19. Changes to This Policy
19.1 We may update this policy as the Service and the law evolve; the version and effective date appear at the top, and we review this policy at least annually. For material changes we will give you at least 30 days' notice by email and in the app before they take effect, and our servers record the version you accept.
19.2 Version history. Version 3.0 — July 30, 2026 (this policy: named every service provider, published the full retention and deletion matrix, added the section for people our members add, and expanded the minors, state-rights, and tracking-signal disclosures). Version 2.0 — June 20, 2026. Prior versions are archived and available by emailing support@givepeace.co.
20. Contact Us
Give Peace Inc. support@givepeace.co (privacy requests: subject "Privacy Request" · legal notices: subject "Attn: Legal") givepeace.co
If anything here is unclear, ask us. On a product like this, you deserve straight answers about your privacy — in life, and after.
Privacy Policy v3.0 — Effective July 30, 2026