Privacy Policy
Last Updated: July 23, 2026
1. Introduction
Killswitch, operated by Elixir Mentor LLC ("we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our encrypted storage service.
By using Killswitch, you agree to the collection and use of information in accordance with this policy.
2. Encryption Architecture
Encrypted at Rest and in Transit
Killswitch encrypts your content and metadata:
- File contents, notes, and journals are encrypted at rest with AES-256
- Filenames, descriptions, and storage paths are also encrypted at rest in our database
- All connections use HTTPS/TLS encryption in transit
- Killswitch holds the encryption keys, which is what enables password reset, search, previews, delivery to your beneficiaries, and the optional AI connector
How We Access Your Content
Because we hold the encryption keys, our systems can technically decrypt your content. We access it only:
- Automatically, to provide the service you asked for (search, previews, delivering items to your designated recipients, features you invoke such as the AI connector)
- To investigate a specific abuse report or security incident
- If we are legally compelled to do so
We do not sell your data, use your content for advertising, train AI models on your content, or browse user content.
Change from Our Previous Zero-Knowledge Model
Killswitch previously used client-side zero-knowledge encryption, under which we could not read stored content or reset passwords. We transitioned to server-side encryption at rest in 2026 to make accounts recoverable and delivery to beneficiaries reliable. Content created under the old model remains unreadable to us until you upgrade it in the app.
Delegated Access for Sharing and Deadman Switches
When you share files or configure Deadman Switches, you delegate authority to us to provide access links on your behalf:
- Pre-generated access keys are stored encrypted on our servers until needed
- When you share a file, we provide secure access links to your designated recipients
- When a Deadman Switch triggers, we send access links to your beneficiaries
- All access links can be configured to expire and can be revoked
- This approach is used by 1Password, Bitwarden, and other password managers for emergency access
Sharing is always explicit: nothing is made available to anyone else unless you create a share or configure a Deadman Switch, every share can be revoked, and all share access is logged.
3. Information We Collect
3.1 Account Information
When you create an account, we collect:
- Email address - For account creation, login, and service communications
- Password hash - Securely hashed with bcrypt (we never store plain text passwords)
- Account creation date
- Subscription status - Free, starter, pro, etc.
3.2 Encrypted File Metadata
We store encrypted metadata about your files:
- Encrypted filename - Encrypted at rest in our database
- Encrypted description - Encrypted at rest in our database
- File size - For storage quota tracking
- Upload timestamp
- MIME type - For preview functionality
- Storage path - Encrypted at rest in our database
Note: Filenames, descriptions, and storage paths are encrypted at rest with an encryption key stored securely on our servers, separate from the database itself, as defense-in-depth against a database-only breach.
3.3 Usage Information
We automatically collect:
- Login attempts - For security monitoring and bot defense (via Paraxial)
- IP addresses - For rate limiting, abuse prevention, and security
- Browser type and version - For compatibility troubleshooting
- Session information - For maintaining your logged-in state
- Activity logs - Limited to account actions (login, file upload/download counts)
3.4 Payment Information
For paid subscriptions:
- Payment processor data - Handled by Stripe (see Section 6.4); we never store full card details
- Billing email - For receipts and billing notifications
- Subscription tier and status
- Transaction history - For billing records and tax compliance
We do NOT store credit card numbers or payment details on our servers. All payment processing is handled by PCI-compliant third-party processors.
3.5 Deadman Switch Information
When you create Deadman Switches:
- Beneficiary names and email addresses
- Check-in frequency and grace period settings
- Last check-in timestamp
- Switch status - Active, paused, triggered, expired
4. How We Use Your Information
We use collected information to:
- Provide the Service - Store encrypted files, manage account access, process Deadman Switches
- Security and fraud prevention - Monitor login attempts, detect abuse, block malicious IPs
- Service communications - Send check-in reminders, account notifications, service updates
- Billing and payments - Process subscriptions, send receipts, manage refunds
- Legal compliance - Comply with applicable laws and regulations
- Service improvement - Analyze usage patterns (aggregated, anonymized) to improve features
- Customer support - Respond to inquiries and troubleshoot issues
5. Information We DO NOT Collect or Use
We do NOT:
- Store your password in plain text (only a bcrypt hash)
- Sell or rent your personal information or content to anyone
- Use your content for advertising or marketing profiles
- Train AI models on your content
- Read or browse your content except as described in Section 2 (providing the service, investigating a specific abuse report, or legal compulsion)
6. Third-Party Services
We use the following third-party services that may collect data:
6.1 Digital Ocean Spaces (File Storage)
- Stores encrypted file data
- Located in the United States (SFO3 region, San Francisco)
- Files are stored as encrypted blobs
- Privacy Policy: https://www.digitalocean.com/legal/privacy-policy
6.2 Paraxial (Security Monitoring)
- Monitors security events, login attempts, and threats
- Collects IP addresses for bot defense and rate limiting
- Privacy Policy: https://www.paraxial.io/privacy
6.3 Postmark (Email Delivery)
- Sends account emails, check-in reminders, password resets, share notifications, and beneficiary delivery emails
- Receives recipient email addresses and message content necessary for delivery, and tracks delivery status
- Privacy Policy: https://postmarkapp.com/privacy-policy
6.4 Stripe (Payments)
- Handles subscription billing and payment processing
- Collects payment card information directly (full card details are never sent to or stored by Killswitch)
- Receives your email address and subscription plan for billing
- PCI-DSS compliant
- Privacy Policy: https://stripe.com/privacy
6.5 Twilio (SMS & Phone Verification)
- Delivers optional SMS alerts and two-factor authentication codes (US and Canadian phone numbers only)
- Receives your phone number and the content of service messages solely for delivery; verification codes are generated and checked by Twilio Verify
- Privacy Policy: https://www.twilio.com/en-us/legal/privacy
6.6 Plausible (Analytics)
- Privacy-focused, cookieless web analytics — measures page views and feature usage in aggregate
- Does not use cookies, does not collect personal data, and does not track you across other websites
- Never sees the contents of your stored files, notes, or journals
- Privacy Policy: https://plausible.io/privacy
6.7 Google Ads (Conversion Measurement)
- Used on our public marketing and checkout-confirmation pages only — never loaded inside the authenticated application
- Receives page-view and conversion signals, and sets advertising cookies
- Privacy Policy: https://policies.google.com/privacy
7. Data Sharing and Disclosure
We do NOT sell your personal information to third parties.
We may share information only in these circumstances:
- Service providers - Third parties who help us operate the Service (hosting, email, payments)
- Your designated recipients - When you share files or configure Deadman Switches, you authorize us to provide access links to your designated recipients and beneficiaries
- Legal requirements - If required by law, court order, or government request. We disclose only what we are legally compelled to disclose, and where lawful we will notify you of the request
- Safety and security - To prevent fraud, abuse, or harm to users or the public
- Business transfers - In the event of a merger, acquisition, or sale of assets
- With your consent - When you explicitly authorize sharing
Important: We never share your content with your recipients or beneficiaries except through the shares and Deadman Switches you yourself configured, and every such share is revocable by you.
8. Data Security
We implement industry-standard security measures:
- Encryption in transit - HTTPS/TLS for all connections
- Encryption at rest - Files encrypted with AES-256-GCM, metadata encrypted with AshCloak
- Secure password hashing - bcrypt with appropriate work factors
- IP blocking and rate limiting - Via Paraxial bot defense
- Security scanning - Automated scanning with Sobelow and Paraxial
- Content Security Policy - Nonce-based CSP to prevent XSS attacks
- CSRF protection - On all state-changing operations
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
9. Data Retention
We retain your information as follows:
- Account data - Retained while your account is active
- Encrypted files - Retained until you delete them or your account is closed
- Deleted files - Permanently deleted within 30 days (including from backups within 90 days)
- Activity logs - Retained for 90 days for security purposes
- Billing records - Retained for 7 years for tax and legal compliance
10. Your Privacy Rights
10.1 General Rights
You have the right to:
- Access - Request a copy of your personal data
- Correction - Update incorrect or incomplete data
- Deletion - Request deletion of your account and data
- Export - Download your encrypted files at any time
- Opt-out - Unsubscribe from marketing emails (service emails still required)
10.2 GDPR Rights (EU Residents)
If you are located in the European Union, you have additional rights:
- Data portability - Receive your data in a machine-readable format
- Restriction of processing - Limit how we use your data
- Object to processing - Object to certain data uses
- Withdraw consent - Revoke consent for data processing
- Lodge a complaint - File a complaint with your data protection authority
10.3 CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and share
- Request deletion of your personal information
- Opt-out of the sale of personal information (we do not sell data)
- Non-discrimination for exercising your rights
To exercise any of these rights, contact us at hello@killswitch.app.
11. International Data Transfers
Killswitch is based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States.
By using the Service, you consent to the transfer of your information to the United States and processing in accordance with this Privacy Policy.
12. Children's Privacy (COPPA)
Killswitch is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If we become aware that we have collected personal information from a child under 13, we will delete that information immediately. If you believe we have collected information from a child under 13, contact us at hello@killswitch.app.
13. Cookies and Tracking
We use minimal cookies and tracking:
- Session cookies - Essential for login and maintaining your session (required)
- CSRF tokens - Security tokens to prevent cross-site request forgery (required)
- Flash messages - Temporary messages for user feedback (required)
On our public marketing pages and checkout confirmation page, we use Google Ads conversion measurement, which sets Google advertising cookies. We do NOT load any advertising or analytics tags inside the authenticated application — your vault usage is never shared with advertisers. We do not sell your data.
14. SMS Text Messaging
14.1 SMS Alert Program
Killswitch offers optional SMS text message alerts to notify you of time-critical events related to your deadman switches. This service is entirely optional, requires your explicit opt-in consent, and is available only for United States and Canadian phone numbers; all alerts are always also delivered by email.
14.2 Types of SMS Messages
If you opt-in, you may receive SMS alerts for:
- Check-in reminders - Notifications when your deadman switch check-in is due or overdue
- Grace period warnings - Urgent alerts when your deadman switch has entered the grace period before triggering
- Trigger notifications - Critical alerts when your deadman switch has been triggered
- Security alerts - Optional notifications when your shared files are accessed (if enabled)
14.3 Message Frequency
Message frequency varies based on your deadman switch configuration and activity. Most users receive 1-5 messages per month. Messages are only sent when action is required (missed check-ins, grace periods, triggers).
14.4 Opt-In and Consent
You can opt-in to SMS alerts through:
- Your account Settings > Notifications page
- During deadman switch creation by providing a phone number and checking the SMS alerts checkbox
- Texting START, SUBSCRIBE, or ALERTS to our SMS number
By opting in, you provide express written consent to receive automated SMS alerts from Killswitch at the mobile number you provide. You confirm that you are the subscriber or customary user of the mobile number provided.
14.5 Opt-Out and Cancellation
You can opt-out of SMS alerts at any time by:
- Replying STOP to any SMS alert
- Disabling SMS notifications in your account Settings > Notifications
Your opt-out request will be processed within 24 hours (typically immediately). After opting out, you will no longer receive SMS alerts, but you will continue to receive email notifications.
14.6 Message and Data Rates
Message and data rates may apply based on your mobile carrier's plan. Killswitch does not charge for SMS alerts, but your mobile carrier may charge standard messaging rates. Check with your carrier for details.
14.7 SMS Help
For help with SMS alerts, text HELP to our SMS number or contact us at hello@killswitch.app.
14.8 Phone Number Privacy
Your mobile phone number:
- Is stored securely in our encrypted database
- Is used ONLY to send SMS alerts related to your deadman switches
- Is NEVER sold, rented, or shared with third parties for marketing
- May be shared with our SMS service provider (Twilio) solely for message delivery
- Can be removed from your account at any time in Settings
14.9 Beneficiary Notifications
When your deadman switch triggers, beneficiaries you designated may receive a one-time SMS notification with access instructions, even if they have not opted in to receive SMS from Killswitch. This is a single transactional message sent on your behalf to deliver critical information. Beneficiaries will not receive ongoing SMS messages from Killswitch.
14.10 Carrier Liability
Killswitch and mobile carriers are not liable for delayed or undelivered messages. SMS delivery depends on your carrier's network and may be affected by network outages, service interruptions, or device issues.
14.11 Supported Carriers
SMS alerts are available for all major U.S. carriers (AT&T, T-Mobile, Verizon, Sprint, etc.) and most regional carriers. International SMS support varies by country.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.
For material changes that reduce your rights, we will notify you by email or prominent notice on the Service at least 30 days before the changes take effect.
Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
16. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
Email: hello@killswitch.app
By using Killswitch, you acknowledge that you have read and understood this Privacy Policy.