Skip to content

SLDocs Privacy Policy

Effective Date: September 10, 2026
Last Updated: September 10, 2026

1. Who We Are; Scope

This Privacy Policy describes how Fiji Systems LLC, dba SLDocs (a Texas limited liability company, principal place of business in Collin County, Texas) collects, uses, discloses, and retains personal data in connection with the SLDocs service — an encrypted vault for estate-planning and end-of-life documents offered to U.S. residents and U.S.-organized entities.

If your vault is branded by a law firm, this Policy still applies: privacy and legal notices are always SLDocs documents, and SLDocs is the custodian of vault data. Your law firm has its own, separate privacy obligations to you. For consumer health data, see our standalone Consumer Health Data Privacy Policy, which is prominently linked from our homepage and footer.

2. Personal Data We Collect

BETA PERIOD NOTICE. During the beta period only, and with your consent given at signup, we collect product usage data through PostHog for three purposes: analytics (understanding which features are used and where users encounter friction), debugging (diagnosing errors and reproducing reported problems), and product enhancement (improving flows before general release). This data includes pages and screens viewed, actions you take that we have specifically instrumented, device and browser metadata, and masked recordings of your interactions with the interface.

With your consent, PostHog records navigation and interaction during the beta on screens we specifically permit, including clicks, scrolling, page transitions, and ordinary interface selections. A new or unrecognized screen is not recorded unless we expressly add it. Medical and emergency-medical screens are never recorded. On recorded screens, everything you type and text derived from you or stored data are masked, except that a value identical to fixed interface text may appear as that interface text. Fixed interface text may remain readable. Sensitive controls and statuses are blocked.

PostHog acts solely as our service provider and may not use this data for its own purposes. We do not sell it and we do not share it for advertising.

At the end of the beta period we will stop this collection and delete the data. We are giving notice of that change now.

You may withdraw this consent at any time by emailing legal@sldocs.com. Withdrawing consent does not affect your account, your access to your documents, your participation in the beta, or any promotional pricing you received. On withdrawal we will disable further collection for your account and delete the analytics and session-replay data associated with it within 30 days.

Directly from you:

Automatically: authentication and session data, security and audit-log events (action, actor, tenant, document, metadata, timestamp), the IP address and timestamp at the moment you give a consent or recorded acknowledgment (kept as part of the consent record itself), browser security reports (your browser automatically sends us Content-Security-Policy violation reports, which include the page URL, the blocked resource URL, and your browser’s user-agent string; we use these solely for security monitoring and retain them for 90 days), and server-side error data (Sentry, configured not to send user identifiers). For security and abuse-detection purposes, our security and audit logs record the IP address and browser user-agent associated with security-sensitive events — including sign-ins (including failed attempts), two-factor and one-time-code verification, password resets and account-recovery requests, recipient, medical-proxy, and executor access to a vault (and downloads under those access grants), document downloads and account deletion, and changes to your security settings (including device trust and two-factor settings such as authenticator apps and security keys), recipients, or trusted contacts. We use this information to detect, investigate, and respond to suspicious activity and security incidents — including deriving anti-fraud risk signals at sign-up and sign-in — not to build a marketing or advertising profile of you; we do not record your IP address for ordinary, non-security actions such as reading your own documents. Except for the public /signup page measurement on SLDocs-owned domains described below, and the beta PostHog collection described above, we use no browser-side analytics or advertising SDKs within authenticated, authentication, recovery, token-bearing, confirmation, consent, legal, or other sensitive routes, and we use only strictly-necessary cookies there. Our public forms (such as sign-up and contact) run an invisible anti-automation check to block bots and abuse; it is a security measure that sets no cookie, performs no analytics, and is not used to track or profile you. If you choose to trust a browser so you can skip the second-factor step for a limited period, we keep a durable record of a coarse device descriptor (browser family, operating-system family, and device type — not a fingerprint) so you can review and revoke trusted browsers; signing in on a trusted browser during that period uses your password alone and is not a fresh two-factor sign-in, and security-sensitive actions still require a fresh factor. See the Cookie Policy.

Public marketing and sign-up analytics: On /, /about, /pricing, /firms, /firms/pilot, /contact, /security, and /free-tier-pledge, and on /signup only when it is served on SLDocs-owned domains, we use the standard Umami Cloud tracker to understand aggregate use of those pages, measure visits to the sign-up page over time, and evaluate and improve our public marketing. The tracker sends the page path, query parameters, and URL fragment, referrer, page title, browser, operating system, device type, screen size, and language to Umami Cloud. Umami uses the request IP address, user-agent string, and website ID to generate an anonymous session identifier and derives approximate location and device information; SLDocs does not configure a distinct ID. We do not send account identity, form contents, document or vault data, or custom properties. On the approved public marketing pages only, selecting a specifically instrumented sign-up call to action sends one custom event named “Signup button”; no other custom event name is permitted. The tracker does not write cookies or browser storage. It does not load on /signup when that page is served on a firm custom domain and cannot remain active when a visitor leaves an approved page or enters sign-up verification or checkout, an authenticated route, any other authentication route, a recovery, token-bearing, confirmation, consent, legal, or other non-marketing route. We do not use this information for advertising, cross-context behavioral advertising, or profiling.

From your law firm (firm-channel accounts only): enrollment information and, only with your recorded consent, documents the firm uploads to your vault, each marked with its origin.

3. How We Use Personal Data

Solely to: provide, secure, and support the Service; process payments and taxes; deliver security codes and account notices; operate the personal, Household, recipient, medical-proxy, and executor access flows you configure or that arise under our Terms; understand aggregate use of and improve the eight public marketing pages and SLDocs-owned-domain sign-up page identified in §2; comply with law; and enforce our agreements. We do not read, monitor, review, or analyze the contents of the documents you store; the only automated screening we perform is a malware scan of uploads. We do not use personal data for advertising, we do not “sell” or “share” personal data (as the CCPA/CPRA defines those terms), we do not use sensitive personal information for secondary purposes or inference beyond providing the Service, and we do not engage in profiling that produces legal or similarly significant effects.

4. How We Disclose Personal Data

Only to: (a) our subprocessors (current list, what each sees, and regions at /subprocessors) — we commit to 30 days’ advance notice of subprocessor changes via our notice list; (b) recipients, medical proxies, and executors per the access rules you configure and our published executor process; (c) all current and future authorized members of a Household when an authorized member places a document in that shared space; (d) your sponsoring law firm — for firm-channel accounts, your firm can see and open the documents in your vault (they are stored under your firm’s encryption key and were uploaded by your firm), along with document names, types, sizes, dates, version history, your profile (name, email, phone), and — for firm administrators — an activity log that includes your logins, downloads, and the names (but never the contact details, relationships, or addresses) of recipients you designate. Firms cannot see recipient contact information, your Key Information entries, Household documents, or anything in consumer (non-firm) vaults; and if your firm’s program with SLDocs ends, documents are re-encrypted under your personal key and the former firm loses all access to them; (e) professional advisors only when you initiate sharing of personal-vault documents — advisor sharing and personal support grants never reach Household documents; (f) authorities where legally required (we require valid process and notify you unless prohibited); (g) a successor entity in a corporate transaction, bound by this Policy and the wind-down commitments in our Terms; and (h) Umami Cloud, solely to process the public-marketing and sign-up analytics described in §2.

5. Data Residency

Your account records, document metadata, and audit data are stored in U.S.-region databases; the encryption keys that protect your documents are managed in U.S.-region key management and are non-exportable — they never leave it; and our backups are stored exclusively in U.S. regions, enforced by region-lock policy. Your uploaded documents are encrypted on our servers before storage; the encrypted files are kept by our object-storage provider, whose global network may hold the encrypted bytes in data centers outside the United States. The storage provider never receives the keys and cannot read the files; an encrypted file is unreadable wherever those keys are absent. One exception to flag — email you send us: if you email our support, legal, security, or general inboxes, that email is handled by a third-party mailbox provider and is hosted on servers in the United States. The message content is stored unencrypted at rest, so it is different from, and less protected than, your vault documents (which are encrypted under U.S.-held keys). Please do not email documents or sensitive personal or health details; use the in-product flows instead.

6. Security

Per-document AES-256-GCM envelope encryption (each document’s data-encryption key wrapped by a key-encryption key managed in U.S.-region Google Cloud KMS); field-level encryption of Key Information and sensitive identity fields; separate group-key encryption for Household documents and metadata; TLS in transit; role-based access; an append-only audit log; short-lived workload-federated cloud credentials (no long-lived service-account keys); malware scanning of uploads; and an incident-response program. Plaintext exists only transiently in memory during authorized decryption and during malware scanning by our scanning subprocessor.

Not everything is encrypted at rest. Your personal document contents, filenames, and version notes; your Key Information entry labels and fields; and the “relationship” you record for a recipient are encrypted at rest. For an active consumer account, the key-encryption keys that protect personal data are isolated to that account. A Household has its own separate group key and explicit membership; no member’s personal key controls the shared content. SLDocs manages and operates these keys in Google Cloud KMS; the Service is not zero-knowledge (see our Terms), and you do not separately hold or operate them. Certain operational fields — the names and contact details (email, phone, mailing address) of recipients, trusted contacts, and medical proxies you designate, and your own account contact and address fields — are stored in standard (provider-disk-encrypted) database columns rather than with field-level encryption, so we can deliver notices and operate the access flows you configure. Please avoid placing sensitive information in fields whose purpose is contact or labeling.

7. Retention

Data / account stateRetention
Paid accounts (incl. LAPSED)Documents and designations retained indefinitely
Free accountsEngagement-conditional access (36-month sign-in rule) with indefinite preservation of documents and designations even when soft-locked
Archived accountsData preserved; excess documents archived per the Terms
Firm operational data7 years post-termination
Audit logs and refund records7 years
Tax records7 years
SMS consent recordsLife of the consent plus 4 years after revocation (the federal Telephone Consumer Protection Act’s limitations period, so we can show the consent that authorized each message)

Backups. When you delete data (or your account), it is removed from live systems immediately, but copies persist in encrypted backups until those backups expire on our rotation schedule: most deletions clear backup sets within 8–35 days; monthly snapshots persist about 13 months; a small number of yearly snapshots are retained up to 7 years for financial-records compliance. Backups are double-encrypted (an application-layer encryption pass plus the storage provider’s own at-rest encryption), write-once (tamper-locked), and stored only in U.S. regions; if we ever restore from a backup, we re-apply all deletions that occurred after the backup was taken.

What deletion removes: verified account deletion removes your account, personal documents, Key Information, recipients and trusted contacts, Household membership and the Household access it conferred, and the SMS consent records holding your and your contacts’ phone numbers and consent IPs. Documents deliberately placed in Household remain under shared Household custody after ordinary member/account erasure; the erased member loses access and identifying attribution is removed or pseudonymized. A verified privacy or consumer-health deletion request specifically covering shared data remains separately reviewable under the Consumer Health Data Privacy Policy. Separately, while Household is active, any current authorized Household member or custodian may permanently delete any Household document for all members, regardless of who uploaded it; the uploader has no exclusive deletion right after sharing it. The Service requires confirmation, records the deletion, and sends current Household members a non-sensitive notice. Ordinary member-initiated deletion is unavailable in read-only or frozen states. What deletion retains: records of executor-access and account-recovery adjudications (claimant name/email and the encrypted verification uploads) are retained after account deletion for up to 7 years for the defense of legal claims and fraud prevention.

Do-not-contact records. If you, or someone else such as a designated recipient or trusted contact, ask not to be contacted — or if an address stops accepting our email — we keep a minimal do-not-contact record (the email address, the reason it was suppressed, an optional internal note, and dates) so that we continue to honor the request. Because this record is the instruction not to contact you, we retain it indefinitely and only for that purpose; deleting it would remove the opt-out itself and could cause a later message to reach you again. This record is not linked to any account and is kept even after account deletion — it is the minimum needed to respect the request, which anti-spam rules (including the federal CAN-SPAM Act) permit retaining for this purpose.

8. Your Privacy Rights (Texas TDPSA, California CCPA/CPRA, and other state laws)

Depending on your state, you may have rights to: know/access, correct, delete, portability, opt out of sale/share/targeted advertising/certain profiling (we do none of these, but the right is honored), and limit use of sensitive personal information (we already limit use to providing the Service).

How to exercise: submit requests from within your account or by emailing legal@sldocs.com; we verify requests against account credentials and recorded identity fields. Authorized agents may act for you with proof of authority (California). Appeals of a declined request are submitted at the /privacy/appeal form, which is intentionally available without signing in (your account may already be deleted when you appeal).

Portability is self-serve and complete for your personal account: from your account settings you can download (a) a structured export of your personal data, consent records, acknowledgments, and references to Household memberships/documents, and (b) all documents in your personal vault in bulk as a .zip, decrypted for you on our servers using the keys that protect your account. Household document copies are exported through the Household while you remain authorized; they are not silently duplicated into an individual member’s personal-data export.

Timing: we respond within 45 days, extendable once by 45 days with notice where permitted.

Appeals (TDPSA §541.157; Colorado; Connecticut): if we decline a request, you may appeal via the same intake; we will respond in writing within the statutory period (currently Texas 60 days, Colorado 45 days, Connecticut 60 days). If we deny your appeal, you may file a complaint with your state Attorney General. Consumer-health-data complaints can be directed to: Washington (My Health My Data Act) — Washington State Attorney General; Nevada (SB 370) — Nevada Attorney General; Connecticut Connecticut Attorney General. Residents of other states may file a complaint with their own state Attorney General; a national directory is available through the National Association of Attorneys General “Find My AG” directory. You may also report a concern to the Federal Trade Commission at reportfraud.ftc.gov.

Global Privacy Control: our site recognizes the Sec-GPC browser signal and acknowledges it on the /do-not-sell page. Because we do not sell or share personal information or use it for targeted advertising, every visitor is already in the state the GPC signal requests — receiving the signal therefore requires no change to how we handle your data, and we make none. See /do-not-sell.

Non-discrimination: we will not discriminate against you for exercising rights; note the Free tier is free regardless.

State-specific notes

9. Children

The Service is for adults 18+. We do not knowingly collect data from children under 13 (or under 18 as account holders). Documents you store may reference family members, including minors; that content is yours and is encrypted.

10. Changes; Contact

Material changes will be notified by email and in-product at least 30 days in advance. Contact: legal@sldocs.com; Fiji Systems LLC dba SLDocs, 7160 Preston Road, Ste 100, Plano, TX 75024 (Collin County).

Please don't email sensitive personal or health information or documents — email isn't a secure channel and messages are stored unencrypted at rest. Use your in-product vault instead.