Privacy & Safety Protocol

Privacy Policy

Last Updated: June 10, 2026

Google Drive Storage

Your vault records and uploaded documents are organized inside your personal Google Drive.

No Persistent Copies

Our servers read your Google Drive data to serve your dashboard. We do not persistently store copies of your vault records.

Encrypted Routing Only

Our servers store only your account metadata, encrypted OAuth tokens, inactivity settings, and nominee contact details.

1. Introduction

Patrimony is a digital estate planning tool developed and operated independently. Our platform helps individuals organize important financial, legal, and personal records, and ensure those records can be accessed by trusted nominees if the account owner becomes unavailable.

2. Google API Services User Data Policy

Patrimony's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do not use your Google data for any purpose other than providing the Patrimony service you have requested
  • We do not use your Google data for advertising
  • We do not transfer, sell, or use Google user data to train AI or machine learning models
  • We do not allow humans to read your Google data except: (a) with your explicit consent, (b) where necessary for security or fraud prevention, or (c) where required by law

Google OAuth scopes we request:

  • Hidden Application Data — to create and manage a hidden, isolated spreadsheet in your Google Drive
  • Specific File Access — to upload and manage documents you explicitly store through Patrimoine
  • Basic Profile Info — to identify your account and personalize your dashboard

3. Data Storage and Ownership

Your data is in your Google Drive. We do not maintain a parallel copy of your vault contents on our servers.

When you connect your Google Account, we create:

  1. A hidden appDataFolder inside your Drive — containing your asset records spreadsheet.
  2. A dedicated drive.file folder — for documents you upload (PDFs, certificates, ID scans).

Both are in your Google Account. You can view and manage them directly via Google Drive Settings. Disconnecting Patrimony from your Google Account removes our access immediately.

4. Information We Collect and Store on Our Servers

We store the minimum required to operate the service:

  • Email address & Profile Data: For account identification and personalization.
  • Encrypted OAuth token: Your Google refresh token, securely encrypted, to authenticate Drive API calls for scheduled checks.
  • Inactivity threshold & Timestamps: To run the Dead Man's Switch scheduler.
  • Nominee details & Access tokens: To notify nominees and route portal access.
  • Login audit timestamps: For account security and audit trail.

We do not collect, store, or process: The contents of your vault records, the files you upload, data from your other Google services, or behavioral analytics.

5. How We Use Your Google Drive Data

When you load your dashboard, our server reads your Google Sheet and Drive folder to compile your vault records and display them in the UI. We temporarily process your Google Drive data in memory to render your dashboard. We do not persistently store those records after the request is completed.

6. Third-Party Personal Information — Nominee Data

When you add a nominee, you provide their name, email address, and relationship to you. This is third-party Personally Identifiable Information (PII). This information is used exclusively to contact nominees when your safety protocol triggers, stored encrypted, and never used for marketing.

7. Data Retention

Account metadata, encrypted tokens, inactivity settings, and nominee details are retained until account deletion. Login audit timestamps are retained for 12 months.

Account Deletion — Clean Break Protocol: When you delete your account, your Google OAuth token is revoked immediately, all Firestore data is permanently deleted, and your identity is removed. This process is irreversible.

8. Your Rights

Under the GDPR and the DPDP Act (2023), you have the right to Access, Rectification, Erasure, Withdraw Consent, and Data Portability. To exercise any right, contact support@patrimony.info.

9. Cookies and Session Management

We use secure session tokens in your browser to maintain your authenticated session. We do not use advertising or tracking cookies.

10. Children's Privacy

Patrimony is not intended for users under 18. We do not knowingly collect data from children.

10. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at:

Email: support@patrimony.info
Company: Patrimony, India