2
3 Comments

Building a "digital afterlife" checklist for families - no passwords stored

We are building HeirloomFile, a tool for the quiet disaster that follows a loud one: what happens to your accounts, documents, and wishes after you are gone.

The profile we design for is 35-55, financially settled, does the responsible thing and writes a will. But the will says almost nothing about the 40+ online accounts a person leaves behind: the email, the photo library, the mortgage portal, the pension account, the twelve subscriptions that keep renewing. Families end up reverse-engineering a whole life while grieving, and the biggest cost is time. Banks freeze accounts on notification, insurers wait for certificates, subscriptions keep billing.

The default answer in this space is a password vault with a deadman switch. We deliberately built the opposite.

The constraint that shaped everything: no passwords stored. A password is a key to everything, so keeping a copy anywhere means one breach away from exposing a life. Instead we store clues: "the bank is Community Trust, branch 221, account 44xxxx87." A reference, never a credential. Access protection comes from passphrase two-factor, plus a grace period that auto-unlocks a read-only handover for a trusted contact if you go silent across scheduled check-ins. It is a cadence, not a doomsday timer.

What the family receives is a quest list, not a data dump. Nine categories of accounts and estate items (bank, investments, insurance, home, vehicles, debts, subscriptions, digital accounts, valuables), each with the clue and the official process to claim it: what to do first, who to notify, which companies require letters testamentary, which offer a free locator (the NAIC policy locator is genuinely useful and free).

Why not "password manager for death"? Two reasons we keep coming back to. First, the failure we see most is discovery, not access: families do not need your passwords, they need to know where things are. Second, trust: nobody wants to hand a grieving relative a master key, and nobody can promise a vault full of live credentials stays safe for a decade.

Pricing is deliberately boring: free for 3 items, $27/year after that, one anchor price, no discount games.

We published two write-ups this week that walk through the reasoning (from interviews with people who handled a parent's estate, checked against CFPB and state rules): one on surviving spouse debt, one on why we store zero passwords. Links below. Feedback welcome, especially from anyone who has been through this and knows what we are missing.

Links: heirloomfile.com, /blog/do-i-have-to-pay-my-dead-spouse-debt, /blog/how-to-organize-passwords-for-family-after-death

on September 16, 2026
  1. 1

    The no-password constraint is a strong differentiator, but does the clue-based handover actually give families enough to recover the important accounts without needing more access?

    1. 1

      Good question - it's the one we stress-tested before shipping. The short answer: for the cases that actually hurt families, yes. But let me be specific.

      Discovery is the real failure. Most families don't fail at "we can't get in", they fail at "we didn't know the account existed". Clues solve that directly: bank name, branch, partial account number, policy carrier. With the clue list, the family starts claiming accounts the same day.

      Access doesn't need their password either, in the cases that matter. Google, Apple and Meta built their own legacy handover tools - they verify through the account holder's settings, which the clue list tells the family how to reach. Banks and insurers work off a death certificate plus account identifiers; the checklists in the product cover the official claim flow for each.

      The honest edge: some estate accounts only release to a court-appointed executor. We don't pretend a clue beats a judge. The checklist tells the family exactly which legal authority to obtain and when, before that institution will talk to them.

      Last part is the trade we made on purpose: vaults promise a master key to a decade of credentials; we promise a map of what exists and the official route to each door. The password is the one thing that made sharing unsafe, so we removed it and kept everything that makes the handover work.

      If you've handled an estate and found a hole in this, I'd genuinely like to hear it.

      1. 1

        Thanks JC — appreciate the detailed answer. I sent you a note by email recently as well, since the newer direction of BrandScope made me think the conversation was worth reopening. When you get a chance, would be good to continue it there.