Legal

Privacy policy

Last updated 10 September 2026

1. Introduction and Scope

This Privacy Policy explains how Exit State Limited ("we", "us", "our", "the Company") collects, uses, stores, shares, and protects your personal data when you visit our website at exitstate.xyz ("the Site") and use our online will creation service ("the Service"). This policy applies to all Users of the Service, including visitors, registered Users, and individuals whose personal data is provided to us by Users (such as named beneficiaries, executors, and witnesses).

We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) as retained under the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018 (together, "Data Protection Law"). This policy should be read alongside our Terms of Service and Safety Policy.

Plain language summary: We collect the personal information you give us to build your Will. We encrypt it, store it securely in EU data centres, never sell it, and give you full control over it. You can access, correct, export, or delete your data at any time.

2. Data Controller

For the purposes of Data Protection Law, the data controller is:

Exit State Limited

Registered in England and Wales

Registered office: Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom

Data Protection Contact: privacy@exitstate.xyz

Postal address: Exit State Limited, Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom

If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise any of your data protection rights, please contact our data protection contact at privacy@exitstate.xyz.

3. Personal Data We Collect

3.1 Data you provide directly

When you register for and use the Service, we collect the following categories of personal data that you provide:

CategoryData ElementsPurpose
Identity dataFull legal name, date of birth, gender, place of birth, marital status, nationalityWill creation, legal compliance
Contact dataEmail address, postal address, telephone numberAccount management, communications, Will content
Financial dataAsset descriptions (properties, bank accounts, investments, vehicles, personal possessions, life insurance, pensions, business interests), estimated valuesAsset allocation in Will
Family dataNames, dates of birth, relationships, and contact details of family members, beneficiaries, executors, witnesses, and guardiansWill content, beneficiary designations, executor/witness coordination
End-of-life preferencesFuneral preferences (burial/cremation, ceremony, music, venue), organ donation status and restrictions, personal wishes and messagesFuneral planning, organ donor registration, personal messages feature
Digital legacy dataSocial media account identifiers, digital asset instructions, memorial page content, vault credentialsDigital legacy management, secure vault
Pet dataPet names, species, breeds, care instructions, guardian preferencesPet guardianship provisions

3.2 Data collected automatically

When you access the Service, we automatically collect certain technical and usage data:

  • Technical data: IP address, browser type and version, operating system, device type, screen resolution, time zone setting, and browser plug-in types.
  • Usage data: Pages visited, features used, session duration, clickstream data, referral source, and search terms used to find the Site.
  • Authentication data: Login method (email link or Google), authentication tokens, session identifiers, and login timestamps.

3.3 Payment data

Payment card details (card number, expiry date, CVV) are collected and processed exclusively by our payment processor, Stripe, Inc. We never receive, store, or have access to your full payment card details. We receive only: a transaction reference identifier, confirmation of payment status, the amount paid, and the last four digits of the card used (for your reference in account settings).

3.4 Special category data

Important notice regarding sensitive data: Some information you provide may constitute special category data under UK GDPR Article 9, including data revealing religious beliefs (e.g., funeral ceremony preferences) or health-related data (e.g., organ donation status, living will instructions). We process such data only on the basis of your explicit consent (Article 9(2)(a)) or where processing is necessary for the establishment, exercise, or defence of legal claims (Article 9(2)(f)). You may withdraw your consent to the processing of special category data at any time by contacting us at privacy@exitstate.xyz.

3.5 Third-party data

When you name beneficiaries, executors, witnesses, or guardians in your Will, you provide us with their personal data (typically their name, relationship to you, and contact details). By providing third-party personal data, you confirm that: (a) you have informed those individuals that their data has been shared with us; (b) you have directed them to this Privacy Policy; and (c) you have a lawful basis to share their data with us for this purpose.

4. Lawful Basis for Processing (UK GDPR Article 6)

We process your personal data only where we have a lawful basis to do so under UK GDPR Article 6(1). The table below sets out each processing activity, its purpose, and the applicable lawful basis:

Processing ActivityLawful Basis (Article 6(1))Detail
Creating, storing, and managing your Will and related documents(b) ContractNecessary for the performance of our contract with you
Account registration and authentication(b) ContractNecessary to provide you access to the Service
Processing one-time payments(b) ContractNecessary to fulfil your purchase of the unlock
Sending witness invitations and executor notifications at your direction(b) ContractNecessary to perform the witness/executor coordination features you have requested
Service-related communications (account updates, security alerts, policy changes)(f) Legitimate interestNecessary to keep you informed about your account and the Service. Interest: operational communication. Balancing: minimal privacy impact, essential information only.
Marketing communications and promotional emails(a) ConsentOnly with your explicit, freely given, opt-in consent. You can withdraw at any time.
Service improvement and analytics (using anonymised, aggregated data)(f) Legitimate interestInterest: improving the Service for all Users. Balancing: data is anonymised and aggregated; no individual can be identified.
Fraud prevention and security monitoring(f) Legitimate interestInterest: protecting the Service and Users from fraudulent activity. Balancing: limited to security-relevant data.
Tax record keeping and financial reporting(c) Legal obligationRequired under UK tax law and Companies Act 2006
Responding to law enforcement requests or court orders(c) Legal obligationRequired by applicable law
Processing special category data (religious preferences, health data, organ donation)(a) Consent + Art. 9(2)(a)Explicit consent. Withdrawable at any time without affecting the lawfulness of prior processing.
Death verification and post-death access for executors(f) Legitimate interest + (b) ContractNecessary to fulfil the purpose of the Service (post-death Will execution). Safeguarded by strict verification procedures.

5. Data Sharing and Recipients

5.1 Categories of recipients

We may share your personal data with the following categories of recipients:

  • Your designated contacts: Witnesses and executors you nominate will receive invitations and notifications containing limited information (your name, their designated role, and instructions for participation). This sharing is initiated by you and is necessary for the performance of the Service.
  • Beneficiaries: Individuals you name as beneficiaries may receive notification of their inclusion, at your direction.
  • Executors (post-death): After verified death, your nominated executors will receive access to your Will, vault contents, funeral preferences, and other end-of-life information you have stored through the Service, subject to our death verification process.

5.2 Data processors (UK GDPR Article 28)

We use the following third-party data processors to help deliver the Service. Each processor is bound by a Data Processing Agreement (DPA) that complies with UK GDPR Article 28 requirements:

ProcessorPurposeData ProcessedLocation
Supabase, Inc.Database, file storage and account authenticationAccount details, everything you write into your will, uploaded documents, the signed copy and any film of the signingIreland (AWS eu-west-1); company incorporated in the United States
Vercel, Inc.Website hosting, the server functions behind the app, and privacy-friendly traffic analyticsRequests to the site, IP address, and will data in transit through the server functions that generate documents and send invitationsEuropean (London/Frankfurt) edge regions; company incorporated in the United States
Stripe Payments Europe, Ltd. and Stripe, Inc.Taking paymentCard details (which reach Stripe, never us), billing name, email, amount, and the transaction reference we storeIreland and the United States; PCI DSS Level 1 certified
Resend (Plus Five Five, Inc.)Sending email — sign-in links, and the notices to the people you nameRecipient name and email address, and the content of the message sent to themEuropean Union sending region; company incorporated in the United States
Google LLC — Sign in with GoogleSigning you in, if you choose that option rather than an email linkYour Google account email address, name and profile picture. Nothing else, and nothing is read from your Google accountUnited States and global Google infrastructure
Google LLC — Places APISuggesting an address while you type oneThe partial address text you type into an address field. It is not linked to your account when we send itUnited States and global Google infrastructure
Google LLC — Gemini APITurning the answers you have given into the wording of a will documentThe will content you have entered, sent as a prompt at the moment you ask for a documentUnited States and global Google infrastructure

The table above is our current list of processors, and it is the list we keep up to date. Each of them is engaged under a written contract meeting the requirements of UK GDPR Article 28, which binds them to process personal data only on our documented instructions, to keep it confidential, to apply appropriate security measures, and to delete or return it at the end of the engagement. We remain responsible to you for what they do with it.

We may add or change processors as the Service changes. Where a change would materially affect how your personal data is processed, we will update this page and give notice by email at least 30 days before the new processing begins, so that you have the opportunity to object or to delete your account before it takes effect.

5.3 Legal and regulatory disclosures

We may disclose your personal data where required by law, regulation, legal process, or enforceable governmental request, including: (a) to comply with a court order, subpoena, or warrant; (b) to respond to a lawful request from a law enforcement agency; (c) to comply with regulatory requirements; or (d) to protect the rights, property, or safety of Exit State Limited, our Users, or the public.

5.4 No sale of personal data

We do not sell, rent, trade, or otherwise commercially exploit your personal data. We do not share your data with advertisers, data brokers, or marketing companies. Your Will Data is used exclusively for delivering the Service to you.

6. Sign in with Google, and Google User Data

Signing in with Google is optional. You can use the Service with an email sign-in link instead, and nothing in this section applies if you do.

6.1 What we receive from Google

If you choose to sign in with Google, Google tells us three things about the account you signed in with: the email address, the name on the account, and the profile picture URL if the account has one. We also receive a Google account identifier, which we use to recognise you as the same person the next time you sign in.

We request only the email, profile and openid scopes. These are the minimum scopes required to sign somebody in. We do not request, and therefore cannot access, any other part of your Google account: not Gmail, not Drive, not Calendar, not Contacts, not Photos, and not your Google search or location history.

6.2 How we use it

Google user data is used for one purpose only: creating and signing you into your Exit State account, and sending you service messages about your own will at that email address. Your name and profile picture are shown back to you in the app so you can see which account you are in. That is the whole of it.

  • We do not use Google user data for advertising, ad personalisation, or ad targeting.
  • We do not sell, rent or transfer Google user data to data brokers, information resellers, or any other party for those purposes.
  • We do not use Google user data to train, retrain, fine-tune or otherwise develop artificial intelligence or machine learning models, whether ours or anybody else's.
  • No human at Exit State reads your Google user data, except where you have specifically asked us to for support, where it is necessary for security purposes such as investigating abuse, or where the law requires it.

6.3 Google API Services User Data Policy

Exit State's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6.4 Storage, retention and removal

Google user data is stored alongside the rest of your account record, in the European Union region described in the transfers section below, and is kept for as long as your account exists. Deleting your account deletes it, on the timetable set out in the retention section.

You can disconnect Exit State from your Google account at any time at myaccount.google.com/connections. Doing so stops any future sign-in through Google; it does not by itself delete your Exit State account or the will you have written, which you can delete separately using the rights described below, or by writing to privacy@exitstate.xyz.

6.5 Other Google services we use

Two other Google services appear in the Service, and neither of them touches your Google account. The Places API receives the partial address text you type into an address field so it can suggest a full address; it is sent without your account identity attached. The Gemini API receives the will content you have written at the moment you ask for a document, so it can turn your answers into the wording of a will — this is described in the next section. Neither uses data from your Google account, and neither is affected by whether you signed in with Google.

7. Automated Processing and Artificial Intelligence

7.1 Where AI is used

When you ask the Service to produce your will document, the answers you have given are sent to Google's Gemini API, which returns the wording of the document. The same happens if you use the in-app assistant to ask a question. This is the only place artificial intelligence is used in the Service, and it only happens at the moment you ask for it.

7.2 What is sent, and what is not

What is sent is the will content itself: names, relationships, gifts, wishes, and the instructions you have written. What is not sent is your payment data, your account password, your uploaded documents, any film of your signing, or anything held in the encrypted vault, which we cannot read.

Your will is not used to train anybody's model. We use the paid Gemini API under Google's terms for paid services, under which prompts and responses are not used to train or improve Google's models. We do not train models of our own on your data, and we do not permit anyone else to.

7.3 No automated decisions about you

We do not carry out automated decision-making producing legal effects concerning you, or similarly significantly affecting you, within the meaning of UK GDPR Article 22. The AI drafts wording; it does not decide anything about you, does not score, profile or rank you, and does not determine whether you may use the Service or what you are charged.

7.4 The output is a draft until you sign it

Wording produced this way is a draft for you to read, correct and approve. It becomes your will only when you have read it and signed it in the presence of two witnesses, as section 9 of the Wills Act 1837 requires. Nothing in the Service is legal advice, and the responsibility for checking that the document says what you meant is yours. This is set out more fully in our Terms of Service and Disclaimer.

8. International Data Transfers

8.1 Primary data storage

Your Will Data — everything you write into the will, the documents you upload, the signed copy and any film of the signing — is held in our database and file storage at Supabase, in their Ireland region (Amazon Web Services eu-west-1). That is where it rests, and it is the only place a complete copy of it exists.

8.2 Transfers outside the UK/EEA

Several of our processors are incorporated in the United States, and some of them process data there: Supabase, Inc.; Vercel, Inc.; Stripe Payments Europe, Ltd. and Stripe, Inc.; Resend (Plus Five Five, Inc.); Google LLC — Sign in with Google; Google LLC — Places API; Google LLC — Gemini API. Where personal data is transferred outside the UK or European Economic Area to a country that has not received an adequacy decision from the UK Secretary of State, we ensure that appropriate safeguards are in place, specifically:

  • UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), as approved by the UK Information Commissioner's Office under section 119A of the Data Protection Act 2018.
  • EU-US Data Privacy Framework certification held by our US-based processors (where applicable and valid).
  • Supplementary measures including encryption of data in transit (TLS 1.3) and at rest (AES-256), access controls, and contractual obligations on sub-processors.

8.3 Transfer impact assessment

We have conducted a Transfer Impact Assessment (TIA) for each international transfer, evaluating the legal framework of the recipient country, the nature of the data transferred, and the effectiveness of the safeguards in place. Copies of our TIAs and applicable SCCs/IDTA are available upon request by contacting privacy@exitstate.xyz.

9. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The following retention periods apply:

Data CategoryRetention PeriodJustification
Will Data (active account)Duration of account + 7 yearsContractual obligation; legal document retention
Will Data (post-death verified)Up to 100 years from creationIndustry standard for testamentary documents; probate and estate administration requirements
Account/identity dataDuration of account + 7 yearsLimitation Act 1980 (6-year limitation period + 1 year buffer)
Transaction/payment records7 years from transaction dateHMRC requirements; Companies Act 2006 s.386
Technical/usage logs90 daysSecurity monitoring and debugging
Authentication logs12 monthsSecurity auditing, fraud prevention
Marketing consent recordsDuration of consent + 3 yearsEvidence of consent compliance
Data subject request records3 years from request completionRegulatory accountability (Article 5(2))

Upon account deletion request, we will delete or anonymise all personal data that we are not legally required to retain within 30 days. Data subject to legal retention obligations will be securely archived with restricted access and deleted upon expiry of the applicable retention period.

10. Your Data Subject Rights (UK GDPR Articles 15-22)

Under UK GDPR, you have the following rights in relation to your personal data. We are committed to facilitating the exercise of these rights promptly and free of charge.

Right of access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data together with information about the purposes of processing, categories of data, recipients, retention periods, the source of the data (if not collected from you), and the existence of automated decision-making.

Right to rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete personal data completed. You can update most of your data directly through the Service, or contact us for assistance.

Right to erasure / "right to be forgotten" (Article 17)

You have the right to request deletion of your personal data where: (a) it is no longer necessary for the purposes for which it was collected; (b) you withdraw consent and there is no other lawful basis; (c) you object to processing and there are no overriding legitimate grounds; (d) the data has been unlawfully processed; or (e) erasure is required by law. This right is subject to exceptions, including where retention is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

Right to restriction of processing (Article 18)

You have the right to request restriction of processing where: (a) you contest the accuracy of the data (restriction applies for the period needed to verify accuracy); (b) processing is unlawful and you oppose erasure; (c) we no longer need the data but you require it for legal claims; or (d) you have objected to processing pending verification of our legitimate grounds.

Right to data portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON or CSV), and to transmit that data to another controller without hindrance, where processing is based on consent or contract and is carried out by automated means. You can download your Will as a PDF at any time through the Service.

Right to object (Article 21)

You have the right to object to processing based on legitimate interests (Article 6(1)(f)) at any time. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims. You have an absolute right to object to processing for direct marketing purposes.

Right not to be subject to automated decision-making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently use automated decision-making or profiling that falls within the scope of Article 22.

Right to withdraw consent

Where we process your data on the basis of consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

10.1 How to exercise your rights

To exercise any of the above rights, please contact us at:

Email: privacy@exitstate.xyz

Subject line: "Data Subject Request — [Your Right]"

Post: Data Protection Contact, Exit State Limited, Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom

10.2 Response timeline

We will acknowledge your request within 5 business days and provide a substantive response within one calendar month of receipt. If your request is complex or we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it within the initial one-month period, as permitted by UK GDPR Article 12(3).

10.3 Identity verification

To protect your personal data, we may need to verify your identity before processing your request. We will ask you to confirm your identity through your registered email address or, where necessary, by providing additional identifying information. We will never ask for your payment card details as part of identity verification.

10.4 Fees

We will not charge a fee for exercising your data subject rights unless your request is manifestly unfounded or excessive (particularly if repetitive), in which case we may charge a reasonable fee based on administrative costs or refuse to act on the request, as permitted by UK GDPR Article 12(5).

11. Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with UK GDPR Article 32. For detailed information about our security practices, please refer to our . Key measures include:

  • Encryption at rest: AES-256 encryption for all stored data
  • Encryption in transit: TLS 1.3 for all data transmission
  • Password security: bcrypt hashing with appropriate work factor
  • Vault encryption: RSA public-key cryptography for end-to-end encrypted vault
  • Access controls: Role-based access controls, principle of least privilege
  • Infrastructure: Supabase (SOC 2 Type II certified) for the database and file storage, and Vercel (SOC 2 Type II certified) for hosting and server functions
  • Payment security: Stripe PCI DSS Level 1 compliance — no card data touches our servers

12. Data Breach Notification

12.1 Notification to the ICO

In the event of a personal data breach as defined by UK GDPR Article 4(12), we will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33). Our notification will include: the nature of the breach; categories and approximate number of data subjects affected; the likely consequences; and the measures taken or proposed to address the breach.

12.2 Notification to data subjects

Where a breach is likely to result in a high risk to your rights and freedoms, we will communicate the breach to you without undue delay (Article 34), describing in clear and plain language: the nature of the breach; the name and contact details of our data protection contact; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. We will use direct communication (email to your registered address) unless this would involve disproportionate effort, in which case we will use public communication or a similar measure.

12.3 Breach response procedures

We maintain a documented data breach response plan that includes: immediate containment and assessment; risk evaluation; ICO notification where required; affected data subject notification where required; remediation; root cause analysis; and lessons learned. All breaches, including those not reportable to the ICO, are recorded in our internal breach register in accordance with Article 33(5).

13. Records of Processing Activities (UK GDPR Article 30)

We maintain records of processing activities as required by UK GDPR Article 30. These records include: the name and contact details of the controller; the purposes of processing; a description of the categories of data subjects and categories of personal data; the categories of recipients; details of transfers to third countries or international organisations and the safeguards in place; envisaged time limits for erasure; and a general description of technical and organisational security measures. These records are available to the ICO upon request.

14. Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) in accordance with UK GDPR Article 35 before undertaking any processing that is likely to result in a high risk to the rights and freedoms of individuals. Given the sensitive nature of Will Data and end-of-life information, we have conducted DPIAs for: (a) the core Will creation and storage service; (b) the secure vault feature; (c) the death verification and post-death access process; and (d) international data transfers to US-based processors. Summaries of our DPIAs are available upon request.

15. Cookies and Tracking Technologies

15.1 Essential cookies

We use only strictly necessary cookies that are essential for the Service to function. These include:

  • Authentication cookies: To maintain your logged-in session (set by Supabase Auth).
  • Session cookies: To remember your session state across page loads.
  • Security cookies: To prevent cross-site request forgery (CSRF) and other security threats.

15.2 What we do not use

We do not use: advertising cookies; third-party tracking cookies; analytics cookies that identify individual users; social media tracking pixels; or fingerprinting technologies. We do not participate in advertising networks or real-time bidding systems.

We do measure traffic, using Vercel Web Analytics. It sets no cookies and builds no profile: it records the page visited, the referring site, and coarse device and country information, and it derives a visitor count from a hash that is discarded daily and cannot be traced back to a person or reconciled with your account. This is why the Service has no cookie banner — there is nothing to ask you to consent to.

15.3 Lawful basis for cookies

Strictly necessary cookies are exempt from the consent requirement under Regulation 6(4) of the Privacy and Electronic Communications Regulations 2003 (PECR). As we do not use any non-essential cookies, no cookie consent banner is required.

16. Children's Privacy

The Service is not intended for, and we do not knowingly collect personal data from, anyone under the age of 18. You must be at least 18 years old to create a valid Will under English law. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that data as soon as reasonably practicable. If you believe that a child has provided us with personal data, please contact us immediately at privacy@exitstate.xyz.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will: (a) update the "Last updated" date at the top of this page; (b) notify you by email to the address associated with your account at least 30 days before the changes take effect; and (c) where required by law, seek your consent to any material changes in how we process your personal data. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acknowledgement of the updated policy.

18. Complaints and Supervisory Authority

18.1 Complaints to us

If you have any concerns about how we handle your personal data, we encourage you to contact us first at privacy@exitstate.xyz. We take all complaints seriously and will investigate and respond within 30 days. Our internal complaints procedure includes acknowledgement, investigation, resolution, and follow-up stages.

18.2 Right to complain to the ICO

If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane

Wilmslow, Cheshire SK9 5AF

United Kingdom

Helpline: 0303 123 1113

Live chat: ico.org.uk/global/contact-us/live-chat

Website: www.ico.org.uk

Report a concern: ico.org.uk/make-a-complaint

We would appreciate the opportunity to address your concern before you contact the ICO, but you are entitled to lodge a complaint with the ICO at any time without first contacting us.

This Privacy Policy was last updated on 13 March 2026 and is effective as of that date. It was prepared in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and guidance published by the Information Commissioner's Office.