← back to Heirloom

Privacy Policy

Last updated: February 27, 2026

The short version

Heirloom holds intimate things — your voice, your stories, your photos, your last words to your family. We treat them accordingly. Your archive is yours. We do not sell it, train external models on it, or share it with anyone you have not personally named as an heir.

Who is responsible

Heirloom is a product of Unbound Infotech (the "Company", "we", "our"). For privacy questions, write to support@heirloom.app.

What we collect

  • Account info — email, name, profile photo from Google when you sign in.
  • Archive content — text entries, voice recordings, photos, social-media imports, and the answers you give to the AI biographer.
  • Derived data — long-term identity facts and episodic summaries the system extracts from your archive to help the Twin remember you.
  • Heirs and letters — the names, emails, and release conditions for the people you designate.
  • Companion telemetry — your local PC companion sends only a heartbeat and the commands you issue. It never streams the contents of your screen, microphone, or other applications.
  • Billing — Stripe handles your card; we receive only a checkout session id and your email address.

What we do NOT do

  • We do not sell your data.
  • We do not use your archive to train external models — not OpenAI, not Anthropic, not Google.
  • We do not allow any other Heirloom user to read your archive.
  • We do not surveil your microphone or your screen.

Third-party processors

To make the product work, certain pieces of your data are sent to specialized services. Each of them is contractually bound to process the data only on our behalf:
  • Anthropic (Claude) — the model that powers the Twin chat and the biographer. Your archive entries are sent at chat time.
  • ElevenLabs — your voice samples and generated TTS audio.
  • D-ID — text + your portrait photo URL when you render a talking-head video.
  • Stripe — payment processing.
  • Google — sign-in via OAuth (we receive only your email, name, and avatar).
  • MongoDB Atlas — encrypted storage for your archive.

Heirs and release

An heir gains read access to your archive only when you have explicitly released it — manually, on a date you set, on a future age, or after a period of inactivity that you chose. Until then no human at Unbound Infotech can read your archive in plaintext; we use it only to power the AI services you have signed up for.

Retention and deletion

You can delete your account and every artifact tied to it from the Settings page ("Delete my account"). The deletion is hard — your archive, your voice clone, your heirs, your letters, and your billing history are wiped within 7 days. We keep an anonymized audit log of the deletion event for 12 months for fraud and tax reasons.

Your rights (GDPR / CCPA)

You have the right to export your archive (write to support), to correct any inaccuracies (do it from the Library), and to delete everything (Settings → Danger Zone). EU residents may also lodge a complaint with their local data protection authority.

Children

Heirloom is not intended for users under 18 without a parent or guardian operating the account.

Changes

If we change this policy materially, we will send you an email and update the "Last updated" date above. Continued use after a change means you accept the new policy.

Made with Emergent