How we protect your information.

You are considering handing a stranger a map of your digital life. Before that conversation starts, here is exactly what you would share, what we are built never to receive, and why the difference is structural rather than a matter of trusting us.

What this page covers

Two things, and it is worth keeping them apart. The first is this website, which almost anything you do here leaves untouched. The second is an engagement, which happens in our client portal and involves real information about your accounts and household.

Most of what follows is about the second, because that is the part worth asking hard questions about.

What you share before anything begins

Only what you type into a contact form: your name, your email address, optionally a phone number, and whatever you choose to say. Nothing more, and nothing about your accounts or devices.

You do not need to arrive with an inventory, a list of logins, or any idea of where your gaps are. Producing that is the first part of the work, and it is ours to do. The privacy policy covers this website in detail.

What we never hold

One line runs through everything we do: we guide, you execute. Certain materials belong entirely to you, and our systems are not built to receive them. We do not hold:

  • Your account passwords
  • Recovery codes or backup codes for any service
  • Seed phrases or private keys for any wallet
  • One-time codes or authenticator secrets
  • Any credential that would let us reach your accounts

When a step requires entering a password or writing down a recovery code, our guides walk you through it, but you perform it and you keep the result. We never ask you to send these to us. If you ask us to hold them anyway, the answer is no, and we will help you choose a proper custodian instead: your own safe, your attorney, or a professional fiduciary.

This is the difference between a policy and a design. A promise not to look at something can be broken. Not having it is a different kind of assurance.

Why nobody ends up holding everything

The plan we build is deliberately split apart. The map of what exists holds pointers, not secrets: where a thing is kept, never what it is. The record of legal authority goes to your attorney or executor. The sealed recovery materials are segmented, so no single packet opens everything, and they sit with you or a custodian you choose.

We are the technical steward of that system and nothing more. No single document, and no single person, is the key to your entire digital life. That separation is the design, and it is what makes an arrangement safe to leave in place for years.

How this website is built

The site you are reading has no accounts, no sign-in, and no database. It stores nothing. A form submission is passed straight through to the client portal, which records it and notifies the advisor.

It loads one outside resource, the anti-spam widget on the two form pages. Its one typeface is served from our own servers rather than a third party. Keeping that list near zero is a deliberate choice: every additional script on a page is something else that could go wrong and something else that could watch you.

How the client portal is built

The portal runs on Supabase, which provides its database and identity infrastructure and holds SOC 2 Type II certification. A few specifics worth knowing:

  • Your password is never stored in readable form. Authentication is handled by Supabase Auth, and we cannot see your password in any form.
  • Records are isolated at the database level. Access rules make each client’s records reachable only by that client and their assigned advisor.
  • Everything is encrypted in transit and at rest, using TLS between your browser and our servers and AES-256 for stored data.
  • Access is limited and logged. Only the people who need your information to deliver your engagement can reach it.

Who can see your information

By default, you and your advisor. Nobody else, unless you decide otherwise.

People you authorize. You may grant limited access to a trusted contact, an estate attorney, an executor, or a fiduciary. Every grant is started by you, scoped to what you approve, and revocable at any time. The levels that touch sealed recovery material are deliberately procedural rather than digital: the portal shows the instructions, never the materials themselves.

No digital system is ever the only thing standing between someone and your recovery material. That is on purpose.

What we never do

We do not install software on your devices, hold standing access to your accounts, or leave a connection running when an engagement ends. We do not watch your accounts or alert you to anything, because we are an advisory and not a monitoring service. We never take an account over: changes are made with you, in systems you control.

Nothing you share is used for advertising, sold to anyone, given to data brokers, or used to train machine learning models.

Why this matters to us

We are asking you to write down how your digital life fits together. That record would be valuable to exactly the people it is designed to protect you from, which is why the boundaries above are built into the structure of the work rather than offered as assurances.

An advisory that quietly accumulated its clients’ credentials would become the single richest target among them. We would rather not be that, and you should not want us to be.

For the formal detail on what this website collects, see the privacy policy. The client portal keeps its own, covering the engagement itself: app.kearcontinuity.com/privacy.

Book a consultation