How we protect your data
Before we begin working together, here is a plain-language explanation of exactly how we handle your information — what we collect, what we never hold, and how the platform is built to keep what you share with us secure.
What you share with us
In the course of our engagement, you will share information such as your name and contact details, the accounts and services you use, your household structure, and your preferences around how you manage your digital life. This information is used exclusively to build and deliver your continuity plan.
Nothing you share is used for marketing, analytics, or any purpose unrelated to your engagement with Kear Continuity Office.
What we never hold
A clear line runs through every part of how we work: we guide, you execute. There are certain materials that belong entirely to you and that we are designed to never receive, store, or access.
- Your account passwords
- Recovery codes or backup codes for any service
- Seed phrases or private keys for any crypto or hardware wallet
- MFA codes or authenticator secrets
- Any credentials that would allow us to access your accounts
When a task requires entering a password or saving a recovery code, our guides walk you through the step — but you perform it, and you retain the result. We never ask you to share these materials with us, and our system is not designed to receive them.
How the platform is built
The portal is built on Supabase, which provides identity management and database infrastructure with SOC 2 Type II certification. A few specifics worth knowing:
- Passwords are never stored in our system. Authentication is handled by Supabase Auth. We do not store or have access to your password in any form.
- Your data is isolated at the database level. Row-level security policies ensure that each client's records are only accessible to that client and their assigned advisor — not to other clients, and not to us except through the advisor relationship.
- All data is encrypted in transit. Every connection between your browser and our servers uses TLS encryption.
- Data is encrypted at rest. Supabase encrypts all stored data using AES-256.
Who can see your data
Default access. Your data is visible to you and to your assigned advisor. No one else has access unless you explicitly grant it.
Third parties you authorize. You may choose to grant limited access to trusted parties of your choosing — such as a Trusted Contact, estate attorney, executor, or fiduciary. These grants are initiated by you, scoped to the information you approve, and can be revoked at any time. We do not share your information with any third party without your explicit approval.
Analysis tools. To generate written summaries and analysis as part of your plan, engagement data is processed by automated analysis tools. Before this processing, personal identifiers are removed. The provider (Anthropic) operates under a zero-data-retention agreement: your data is not stored, logged, or used to improve any AI model.
We do not sell your data. We do not share it with third parties for any purpose beyond delivering your engagement. We do not use it for advertising or profiling.
Why this is fundamental to our business
Our entire value proposition depends on clients trusting us with sensitive information. That trust is not incidental to what we do — it is the foundation of it. A firm that sells, misuses, or fails to protect client data has no business offering continuity planning services. The incentive to protect your information is not just legal or ethical; it is existential.
We take this seriously because we have to, and because it is the right way to operate.
Your controls
You can request access to, correction of, or deletion of your data at any time. To make a request or ask any question about how your information is handled, contact us at privacy@kearcontinuity.com.
For the formal legal description of our data practices, see our Privacy Policy.