Privacy policy

Last updated 27 August 2026

What we collect

What appears publicly

Your page is reachable by anyone holding your code, without a password. It shows what you chose during setup: your name, birth year or full date of birth, sex if provided, what your document refuses, the statute, your nominated contact, and a link to your signed document. Nothing else about you appears there.

Your page is marked to keep search engines out and has no directory or index. Your code cannot be guessed at any practical scale. It is not, however, secret from anyone who can see the object you are wearing.

Who we identify

We record that an access happened. We do not know who did it — there is no login for readers, and we do not require anyone to identify themselves. We do not attempt to unmask readers, and we do not sell, rent, or share access records with advertisers or data brokers.

Text messages

Each contact you nominate receives one message asking them to confirm. We send alerts only to numbers that have replied YES. Anyone can reply STOP at any time and we stop immediately, for every record their number is attached to. Message and data rates may apply.

HIPAA

We are not a HIPAA covered entity or business associate. The information you give us is not protected health information in our hands. We describe our actual practices here rather than relying on that status.

Service providers

We use Cloudflare (hosting, storage), Stripe (payments — we never see your card number), Resend (email), and Telnyx (text messages). Each receives only what it needs to do its job.

Retention

On cancellation, your page keeps working until the end of the period you have paid for and then stops displaying your directive.

Your code stops resolving to your directive at that point. Anyone scanning it is told the record is not active. Nothing is deleted: your document, your consents and your access history are all still there, and renewing brings your page back exactly as it was.

You can download your document at any time while you are signed in, and you can ask us what we hold about you at any time.

Someone you name

You can name one person who may ask us for your record if you die. If you do, we hold their name, their email address, and whatever relationship you describe. You can change who it is, or remove them, at any time.

We email that person to tell them you have named them, what your record holds, and what to do if you die. That message goes out when you name them rather than when it is needed, because somebody told for the first time after a death has no way to ask you what you meant by any of it. They are also told if your subscription lapses, so they know your page has stopped showing your directive to anyone who scans your code.

They get no access to your account, and none to your record, while you are alive. There is no sign-in for them, no link, and nothing they can open. If you die, they write to us and we check them against what you recorded here and against evidence of your death before we release anything. That is a person's judgement rather than an automatic process, deliberately: the failure we are guarding against is handing your directive and your whole access history to the wrong claimant.

What we send them is your record: the directive you signed, and the log of who opened your page, when, and a fingerprint of what it said each time. It is there so an appropriate person can see what happened if your directives were ever disregarded.

If your record is deleted, for any reason, their details go with it.

Children

A record can be held for someone under 18. It is created and looked after by their parent or legal guardian from that adult's own account, and the child does not get a sign-in of their own. We do not collect anything from a child directly, and a child cannot open an account or create a record.

We ask the parent or guardian to consent before we collect anything, and we store the exact wording they agreed to along with the date. That consent covers the child's full name, date of birth and state, and it says plainly that this creates a page anyone can read at an address printed on a card or engraved on an item the child may wear. The page shows the child's name, what they refuse, who to contact, and either their year of birth or their full date of birth, whichever the parent chooses. It does not show their address, their medical history, or anything else.

Anyone named as an emergency contact for a child enters their own number and agrees to be texted themselves, exactly as they would for an adult. The parent cannot enter someone else's phone number.

The parent or legal guardian can delete the child's record, and everything in it, at any time from their account. That happens straight away rather than on a delay, and it removes the document, the page and every version of it we ever served, the access history, the consents and the confirmations. When the child turns 18 the record is theirs to take over.