Privacy notice

How RecordWarden handles your information.

This notice covers the marketing site, invitation requests, and the RecordWarden app. Last updated July 25, 2026.

In this notice, “RecordWarden,” “we,” “us,” and “our” refer to the operator of the website and app.

What this website collects

Cloudflare hosts this website and counts page views. We do not use advertising trackers, build cross-site profiles, or send names, email addresses, form entries, or invitation codes to analytics.

When you request an invitation

If you request an invitation, we store your email address, the page containing the form, and the time received. We do not save your IP address, browser information, or the web address that brought you here with the request.

Deleting an invitation request

Access-request entries remain until you ask us to delete them. Email support@recordwarden.com from the address you submitted. We verify control of the address before deleting the active entry. We record that the request was completed without retaining the deleted address. Cloudflare may keep deleted data temporarily in managed recovery copies until those copies expire under its retention policy. If we restore the database during that period, we replay the deletion before reopening the invitation list.

Account, sign-in, and household data

The app stores your email address, account status, household membership and role, invitations, and the dates associated with those records. It also stores the public credentials and security records needed for passkeys, email-code verification, active sessions, and abuse prevention. Rate-limit keys derived from email addresses and IP addresses are stored as keyed hashes rather than as the original values.

What the RecordWarden app stores

RecordWarden encrypts file contents in your browser before upload. The servers store encrypted document bytes and encrypted key envelopes. The server can also read the limited information needed to organize and retrieve records, such as the title, date, type, and the person, property, account, or year a record belongs to.

Technical details about application data

RecordWarden’s servers store encrypted document bytes and encrypted key envelopes, along with limited information needed to organize and retrieve records.

Information visible to RecordWarden’s servers can include:

  • record title, document date, and document type;
  • record-subject title and validated type-specific details;
  • lifecycle and expected-document state;
  • ciphertext size, integrity, algorithm, and envelope version information; and
  • typed fields required for the implemented organized views.

Plaintext OCR, full text, embeddings, arbitrary extraction dumps, folder paths, and user-managed tags are not stored by the server.

When you send feedback

When you use the in-app feedback form, RecordWarden sends the message you enter and your verified account email to support so we can reply. You can choose whether to add a marked-up screenshot of the current page; the form does not attach one automatically. Review the screenshot and remove or cover private information before sending it.

Feedback messages and screenshots are support communications, not documents stored in your household vault. They are not encrypted with your vault key. The RecordWarden app processes them in readable form for delivery, and the email delivery provider and people authorized to access the support mailbox can read them.

Feedback remains in the support mailbox and mail-delivery systems as needed to respond and operate support. To request deletion, email support@recordwarden.com from your verified account address. We may verify the request before deleting the support copy we control. Copies may remain temporarily in provider recovery systems or backups until they expire under the provider’s policies.

Deleting an account or household vault

The app lets an account holder delete an account and lets a household owner delete a vault. Those actions remove access to the affected records and cannot be undone in the product. Encrypted recovery copies are kept in a restricted recovery quarantine for at least 35 days and are scheduled for deletion after that. They are not available through the app while quarantined, but a RecordWarden operator can restore them as part of a service-recovery process.

Deleted account details and server-visible record information may remain in restricted, encrypted service backups until those backups expire under the configured retention schedule. Backups are used only for disaster recovery and are not available through the app.

If your subscription ends

If a subscription ends, you cannot add or change records. For the next 14 days, you can still open and export your files. Deletion then begins. Encrypted recovery copies are kept in a restricted recovery quarantine for at least 35 days and are scheduled for deletion after that. They are not available through the app while quarantined.

Physical originals

RecordWarden is designed to organize digital copies. Keep physical originals that have independent legal or practical value.

Questions

Email support@recordwarden.com with privacy questions or requests.