What actually happens to your accounts, passwords and photos when you die — checked against the vendors' own documentation, not their marketing.
Everything we publish lives at research.cairnvault.app, free, under CC BY 4.0, with the source URL attached to every claim.
We build CairnVault, an encrypted digital-legacy plan. We are therefore not a neutral party, which is exactly why everything we publish links to the vendor's own words rather than to our characterisation of them. Check us.
Every digital-legacy service, password manager, and platform "legacy contact" feature, on the only two axes that decide whether your plan works:
- Does the provider actually verify that you died — or does it just measure whether you stopped logging in?
- Can the provider read your data? If staff can grant someone access to your vault, staff can read your vault.
Read it as a web page, as a repository, or check the source for every claim.
Three findings that surprised us:
- No password manager verifies death. All seven we examined — Bitwarden, LastPass, Proton Pass, NordPass, Keeper, 1Password, Dashlane — use a silence timer or nothing at all. Not one can distinguish a funeral from a two-week holiday with no signal. If you are unconscious in an ICU, your emergency contact can request your vault and the clock runs out on you.
- Apple's Legacy Contact excludes your passwords. Verbatim from Apple's own support page: "Inaccessible data includes … data stored in your iCloud Keychain (payment information, passwords, and passkeys)." Your photos and messages pass to your legacy contact. The keys to everything else do not.
- The one company that genuinely verifies death can therefore read your vault. Not an accusation — a structural consequence. The moment an employee can review a certificate and click "grant access," the encryption is a policy rather than a mechanism.
Sixteen providers, machine-readable, CC BY 4.0, every field carrying the source URL it was read from:
- dataset.html — the readable table, with
schema.org/Datasetmarkup - digital-legacy-comparison.json
- digital-legacy-comparison.csv
unknown is a first-class value in it. Everplans' encryption posture is recorded as unknown rather than no, and Keeper's recipient requirement stays unknown, because neither could be established from primary documentation. The readable table and the CSV are both generated from the JSON, so they cannot drift apart. Our own product is in the dataset too, tagged self-reported — excluding ourselves would have made the central finding unfalsifiable, which is the one thing it must not be.
The teardown compares products. This answers the questions people actually type into a search box, each on its own page, each checked against the vendor's, regulator's or legislature's own documentation.
Accounts and platforms: Google · Apple / iCloud · Facebook & Instagram · LinkedIn · X / Twitter · Dropbox · Netflix · Spotify · Amazon & Kindle · Steam & Xbox · domain names · subscriptions · photos
Money: PayPal · Venmo · crypto · crypto on Coinbase or Kraken · your bank account and its 2FA · airline miles
Passwords, law and practicalities: can my spouse get into my password manager · how Bitwarden emergency access really works · if the password manager company shuts down · should I write my passwords down · does putting passwords in my will make them public · does my will cover digital assets · is it legal to log into a dead person's account · is it a crime to log into a dead relative's account · what is a digital executor · letting family find accounts safely · my parent died and I can't get into their phone
Each answer is written to be complete on its own. You should not have to click anything — including anything of ours — to get the real answer.
Every claim carries a source we fetched ourselves, on a stated date. Where a vendor page blocks automated retrieval, we say so and attribute the claim to a named secondary source — or leave it out. When a vendor has no policy page at all, we publish that absence as the answer.
We publish our own retractions. Roughly a third of the competitive claims we started with did not survive checking, including several that were in our own marketing. They are listed, dated, in the correction log rather than quietly deleted. A comparison you can check is worth publishing; one you cannot is worth nothing.
We publish what we could not establish, too. The open questions are filed as public issues, one per unresolved fact, including an open challenge to name any product that both verifies death and cannot read your data. Nobody has yet. The day someone does, we will say so here.
We would rather be corrected than be wrong. If you work for a company named in the research and think we have characterised your product incorrectly, open an issue — we will fix the text and record the correction with a date.
Everything here is CC BY 4.0. Republish it, quote it, translate it. Attribution and a link back are all we ask. There is a summary for language models at research.cairnvault.app/llms.txt.
- What happens to your online accounts when you die — how the encryption and the release process work
- CairnVault product demo — building a plan your family can actually find
The research compares how products work. It is not legal advice.