Privacy Policy
Version 2 — last updated September 16, 2026.
This is the privacy policy of Brian Lee (sole proprietor), operating as Fecit, who runs the DearKith service.
DearKith is a private family legacy-message vault, operated by Brian Lee (sole proprietor). A vault owner records messages — text, voice, and photos — for the people they name, and DearKith stores those messages and delivers them under the conditions the owner sets. This policy says what information we handle, why, and what we will never do with it.
What we collect
- Account information: your email address and a password. Sign-in is handled by our authentication provider; we never see or store your password itself. You may add a contact phone number.
- People you add: the names, relationships, email addresses, and phone numbers of the recipients and trusted contacts a vault owner enters. Owners are responsible for having a personal or household relationship with the people they add.
- Vault content: the messages, recordings, photos, and documents an owner stores, and transcripts of voice recordings.
- Operational records: a log of account and vault actions (for security and accountability), and delivery records for messages we send.
How we use it
Only to operate the vault: storing your content, verifying identities by emailed link and, where an owner set one, a security question, delivering messages to the recipients an owner designates, and sending account-security notices. DearKith shows no advertising. We do not sell personal information.
Text messages
We do not send text messages. If an account holder records a phone number for someone, we store it as contact information for the account holder's own reference. We never text it, and we never share it with anyone for marketing.
Service providers
We use a small set of processors, each only to run the service: Supabase (authentication and database), Cloudflare (web hosting and media storage), Fly.io (application servers), Resend (email), and OpenAI (transcription of voice recordings). We share with them only what each needs to do its job.
Who can see vault content
The vault owner, and the recipients they designate — after identity verification, when a release happens under the owner's conditions. Trusted contacts an owner appoints can start the release process but do not gain access to message content by doing so. Where a recipient is a minor, access is held for them by the guardian arrangement their vault owner set up. We do not knowingly collect information directly from children; what an owner records about a minor recipient is entered and controlled by that adult.
Retention and deletion
Your content stays until you delete it. Account deletion starts a grace window during which you can change your mind; after it, your data is destroyed and stops being part of the live service. Owners can export a full copy of their vault at any time.
Our backups are the exception. DearKith keeps encrypted backups on write-once storage and does not remove them early, so a copy of deleted data stays in those backups for up to 240 days after it leaves the live service. The copy then expires on its own. We chose this deliberately: the product exists so that what you record outlives you, and a backup we can erase on request is not one we can count on the day we need it.
Security
Content is encrypted in transit, stored in access-controlled systems, reachable only through short-lived signed links, and guarded by an audit log. No system is perfectly secure; we design so that losing your memories is the failure we defend against hardest.
Changes and contact
If this policy changes, the date above changes with it, and material changes will be announced in the app. Questions or requests: support@dearkith.com.