Privacy Policy
Last updated: July 9, 2026
1. Who We Are; Scope
This Privacy Policy describes how Fiji Systems LLC, dba SLDocs (a Texas limited liability company, principal place of business in Collin County, Texas) collects, uses, discloses, and retains personal data in connection with the SLDocs service — an encrypted vault for estate-planning and end-of-life documents offered to U.S. residents and U.S.-organized entities.
If your vault is branded by a law firm, this Policy still applies: privacy and legal notices are always SLDocs documents, and SLDocs is the custodian of vault data. Your law firm has its own, separate privacy obligations to you. For consumer health data, see our standalone Consumer Health Data Privacy Policy, which is prominently linked from our homepage and footer.
2. Personal Data We Collect
Directly from you:
- Account data: name, email, password (hashed), U.S.-residency attestation.
- Identity fields, encrypted at rest under a per-user profile key: date of birth, last 3 digits of SSN, last 3 digits of a government ID, phone number. We never store a full SSN and we do not collect biometrics.
- Vault content: the documents you upload and vault entries, encrypted per-document (AES-256-GCM) with keys held in U.S.-region Google Cloud KMS.
- Recipient designations: name, email, phone, and mailing address of people you designate.
- Billing data, processed by Stripe: billing contact and payment method (we never see full card numbers).
- Communications: support email, SMS opt-in records.
Automatically: authentication and session data, security and audit-log events (action, actor, tenant, document, metadata, timestamp), the IP address and timestamp at the moment you give a consent or recorded acknowledgment (kept as part of the consent record itself), browser security reports (your browser automatically sends us Content-Security-Policy violation reports, which include the page URL, the blocked resource URL, and your browser’s user-agent string; we use these solely for security monitoring and retain them for 90 days), and server-side error data (Sentry, configured not to send user identifiers). For security and abuse-detection purposes, our security and audit logs record the IP address and browser user-agent associated with security-sensitive events — including sign-ins (including failed attempts), two-factor and one-time-code verification, password resets and account-recovery requests, recipient, medical-proxy, and executor access to a vault (and downloads under those access grants), document downloads and account deletion, and changes to your security settings (including device trust and two-factor settings), recipients, or trusted contacts. We use this information to detect, investigate, and respond to suspicious activity and security incidents, not to track your browsing or build a profile of you; we do not record your IP address for ordinary, non-security actions such as reading your own documents. Outside our limited beta, we use no browser-side analytics or tracking SDKs, and we use only strictly-necessary cookies — see the Cookie Policy. During the beta only, enrolled beta testers who acknowledged our beta session-tracking notice at signup are measured by a cookieless third-party product-analytics tool (PostHog) that records pageviews and in-product events (which pages and features are used) to help us improve the Service. It stores nothing on your device; automatic capture and session recording are off, so it does not capture document contents, form entries, or vault data; it does not run for other users or for signed-out visitors; and it is removed when the beta ends (expected within roughly one to one-and-a-half months). PostHog processes this data in the United States, acts solely as our service provider (it may not use the data for its own purposes or sell, share, or disclose it to anyone else, and the data is used only by SLDocs to improve the product), and is listed on our Subprocessors page. Because PostHog is a service provider used only for our own product improvement, this is not a “sale” or “share” of personal information.
From your law firm (firm-channel accounts only): enrollment information and, only with your recorded consent, documents the firm uploads to your vault, each marked with its origin.
3. How We Use Personal Data
Solely to: provide, secure, and support the Service; process payments and taxes; deliver security codes and account notices; operate recipient, medical-proxy, and executor access flows you configure or that arise under our Terms; comply with law; and enforce our agreements. We do not read, monitor, review, or analyze the contents of the documents you store; the only automated screening we perform is a malware scan of uploads. We do not use personal data for advertising, we do not “sell” or “share” personal data (as the CCPA/CPRA defines those terms), we do not use sensitive personal information for secondary purposes or inference beyond providing the Service, and we do not engage in profiling that produces legal or similarly significant effects.
4. How We Disclose Personal Data
Only to: (a) our subprocessors (current list, what each sees, and regions at /subprocessors) — we commit to 30 days’ advance notice of subprocessor changes via our notice list; (b) recipients, medical proxies, and executors per the access rules you configure and our published executor process; (c) your sponsoring law firm — for firm-channel accounts, your firm can see and open the documents in your vault (they are stored under your firm’s encryption key and were uploaded by your firm), along with document names, types, sizes, dates, version history, your profile (name, email, phone), and — for firm administrators — an activity log that includes your logins, downloads, and the names (but never the contact details, relationships, or addresses) of recipients you designate. Firms cannot see recipient contact information, your secure vault entries, or anything in consumer (non-firm) vaults; and if your firm’s program with SLDocs ends, documents are re-encrypted under your personal key and the former firm loses all access to them; (d) professional advisors; (e) authorities where legally required (we require valid process and notify you unless prohibited); and (f) a successor entity in a corporate transaction, bound by this Policy and the wind-down commitments in our Terms.
5. Data Residency
Your account records, document metadata, and audit data are stored in U.S.-region databases; the encryption keys that protect your documents are managed in U.S.-region key management and are non-exportable — they never leave it; and our backups are stored exclusively in U.S. regions, enforced by region-lock policy. Your uploaded documents are encrypted on our servers before storage; the encrypted files are kept by our object-storage provider, whose global network may hold the encrypted bytes in data centers outside the United States. The storage provider never receives the keys and cannot read the files; an encrypted file is unreadable wherever those keys are absent. One exception to flag — email you send us: if you email our support, legal, security, or general inboxes, that email is handled by a third-party mailbox provider (a Swiss company that hosts on infrastructure spanning multiple countries) and the message content is stored unencrypted and may reside on servers outside the United States. This is different from, and less protected than, your vault documents (which are encrypted, under U.S.-held keys). Please do not email documents or sensitive personal or health details; use the in-product flows instead.
6. Security
Per-document AES-256-GCM envelope encryption; per-user encryption of sensitive identity fields; TLS in transit; role-based access; an append-only audit log; short-lived workload-federated cloud credentials (no long-lived service-account keys); malware scanning of uploads; and an incident-response program. Plaintext exists only transiently in memory during authorized decryption and during malware scanning by our scanning subprocessor.
Not everything is encrypted at rest. Your document contents, and (for direct consumer accounts) your document filenames, version notes, secure vault-entry labels, and the “relationship” you record for a recipient, are encrypted at rest under per-user keys. Certain operational fields — the names and contact details (email, phone, mailing address) of recipients, trusted contacts, and medical proxies you designate, and your own account contact and address fields — are stored in standard (provider-disk-encrypted) database columns rather than with field-level encryption, so we can deliver notices and operate the access flows you configure. Please avoid placing sensitive information in fields whose purpose is contact or labeling.
7. Retention
| Data / account state | Retention |
|---|---|
| Paid accounts (incl. LAPSED) | Documents and designations retained indefinitely |
| Free accounts | Engagement-conditional access (36-month sign-in rule) with indefinite preservation of documents and designations even when soft-locked |
| Archived accounts | Data preserved; excess documents archived per the Terms |
| Firm operational data | 7 years post-termination |
| Audit logs and refund records | 7 years |
| Tax records | 7 years |
| SMS consent records | Life of the consent plus 4 years after revocation (the federal Telephone Consumer Protection Act’s limitations period, so we can show the consent that authorized each message) |
Backups. When you delete data (or your account), it is removed from live systems immediately, but copies persist in encrypted backups until those backups expire on our rotation schedule: most deletions clear backup sets within 8–35 days; monthly snapshots persist about 13 months; a small number of yearly snapshots are retained up to 7 years for financial-records compliance. Backups are double-encrypted (an application-layer encryption pass plus the storage provider’s own at-rest encryption), write-once (tamper-locked), and stored only in U.S. regions; if we ever restore from a backup, we re-apply all deletions that occurred after the backup was taken.
What deletion removes: verified account deletion removes your account, documents, recipients and trusted contacts, and the SMS consent records holding your and your contacts’ phone numbers and consent IPs. What deletion retains: records of executor-access and account-recovery adjudications (claimant name/email and the encrypted verification uploads) are retained after account deletion for up to 7 years for the defense of legal claims and fraud prevention.
8. Your Privacy Rights (Texas TDPSA, California CCPA/CPRA, and other state laws)
Depending on your state, you may have rights to: know/access, correct, delete, portability, opt out of sale/share/targeted advertising/certain profiling (we do none of these, but the right is honored), and limit use of sensitive personal information (we already limit use to providing the Service).
How to exercise: submit requests from within your account or by emailing legal@sldocs.com; we verify requests against account credentials and recorded identity fields. Authorized agents may act for you with proof of authority (California). Appeals of a declined request are submitted at the /privacy/appeal form, which is intentionally available without signing in (your account may already be deleted when you appeal).
Portability is self-serve and complete: from your account settings you can download (a) a structured export of your personal data, consent records, and acknowledgments, and (b) all of your documents in bulk as a .zip, decrypted under your own key.
Timing: we respond within 45 days, extendable once by 45 days with notice where permitted.
Appeals (TDPSA §541.157; Colorado; Connecticut): if we decline a request, you may appeal via the same intake; we will respond in writing within the statutory period (currently Texas 60 days, Colorado 45 days, Connecticut 60 days). If we deny your appeal, you may file a complaint with your state Attorney General. Consumer-health-data complaints can be directed to: Washington (My Health My Data Act) — Washington State Attorney General; Nevada (SB 370) — Nevada Attorney General; Connecticut — Connecticut Attorney General. Residents of other states may file a complaint with their own state Attorney General; a national directory is available through the National Association of Attorneys General “Find My AG” directory. You may also report a concern to the Federal Trade Commission at reportfraud.ftc.gov.
Global Privacy Control: our site recognizes the Sec-GPC browser signal and acknowledges it on the /do-not-sell page. Because we do not sell or share personal information or use it for targeted advertising, every visitor is already in the state the GPC signal requests — receiving the signal therefore requires no change to how we handle your data, and we make none. See /do-not-sell.
Non-discrimination: we will not discriminate against you for exercising rights; note the Free tier is free regardless.
State-specific notes
- California: categories collected (identifiers; customer records; commercial information; internet activity limited to session/security logs, plus — for enrolled beta testers only, during the beta — cookieless product-analytics events; sensitive PI as described in §2) are used only as described in §3; we have not sold or shared personal information, including of minors under 16, in the preceding 12 months. CPRA sensitive-PI limitation applies by default.
- Texas: SLDocs processes sensitive data (health-related documents, precise identity fields) only with consent and to provide the Service. “NOTICE: We may sell your sensitive personal data / biometric data” disclosures are not required because we do not sell such data.
- Colorado / Connecticut / Oregon / Virginia and similar: health and other sensitive data are processed only with opt-in consent (captured per the Consumer Health Data Privacy Policy) and only to provide the Service.
- Washington and Nevada residents: consumer health data is governed by the standalone Consumer Health Data Privacy Policy.
9. Children
The Service is for adults 18+. We do not knowingly collect data from children under 13 (or under 18 as account holders). Documents you store may reference family members, including minors; that content is yours and is encrypted.
10. Changes; Contact
Material changes will be notified by email and in-product at least 30 days in advance. Contact: legal@sldocs.com; Fiji Systems LLC dba SLDocs, 7160 Preston Road, Ste 100, Plano, TX 75024 (Collin County).
Please don't email sensitive personal or health information or documents — email isn't encrypted and may be stored outside the U.S. Use your in-product vault instead.