Skip to main content

Setting Up Your Legacy Vault (Owner Guide)

Qpher Legacy is a digital legacy vault: you choose documents, choose people, and set the rules under which those people can receive the documents after your death. Release is never automatic — a person you designated must open a claim, your rules must be satisfied, and you can veto at any time before release.

This is not a will

Qpher Legacy stores and releases documents. It does not make a document a legally valid testamentary instrument, and it is not legal advice. If a document matters to your estate, talk to an attorney — and tell them about your Qpher Legacy designation, because in most U.S. states a designation made through an online tool like this one can take priority over conflicting instructions in a will, trust, or power of attorney.

Step 1 — Build your Legacy Vault

  1. Open Qpher Legacy and sign in (the same account works in Qpher Vault — documents are shared between the two apps).
  2. Go to Legacy Vault and select the documents (or folders) to include. Your Legacy Vault is only the set you select — never your whole account by default.
  3. Documents are encrypted on your device before upload, and the names of Legacy Vault documents and folders are encrypted too — Qpher cannot read document contents or Legacy Vault file names.

If your selection may contain health-related documents (insurance policies, medical records), the app shows a separate consent screen first. Washington law asks for your explicit OK before we store data that may relate to your health, even in encrypted form. Declining still lets you use the product; see the Consumer Health Data Privacy Policy.

Step 2 — Designate heirs and confirmers

  • Heirs are the people who receive your documents when your policy completes. An heir does not need a Qpher account until it is time to receive.
  • Confirmers are people who must approve a claim before the waiting period starts. The setup wizard treats at least one confirmer as the default; you can skip this, but skipping requires an explicit risk acknowledgment and raises your minimum waiting period to 120 days.
  • A person can be both an heir and a confirmer, but no one can confirm their own claim.
  • If an heir is a minor, you must add a guardian contact — Qpher never contacts a known minor directly; everything routes to the guardian.

Confirming your designation is a separate agreement (the Legacy Designation Agreement), shown on its own screen with its own checkboxes. It records your consent for Qpher to disclose the selected documents to the people you list, if — and only if — your release policy completes. You can change or revoke the designation at any time while you are alive.

By default your heirs and confirmers are notified when you designate them ("no action is required from you"), so they know the vault exists. You may instead choose a sealed designation (no notice) — but then discovery is entirely up to you: if no one ever learns the vault exists, no one can ever claim it. A letter kept with your other important papers is a common choice.

Step 3 — Deliver claim codes offline

Each heir gets a claim code — a short code that acts as a fast lane when they claim. Qpher stores only a hash of the code and cannot recover it for anyone.

Deliver the code outside Qpher: tell the person directly, or write it in a letter kept with your important papers. Do not email it from the vault.

A lost code never locks an heir out permanently: a claim without the correct code still proceeds, but the waiting period is extended by 60 days and a manual review (including a death certificate) is required before release.

Step 4 — Set your release policy and arm it

  • Confirmations: choose how many of your confirmers must approve a claim.
  • Waiting period: choose the delay between an approved claim and release — 30 days by default, configurable from 14 to 180 days. With zero confirmers the minimum is 120 days.
  • Arm the policy. Arming (like disarming or editing contacts) requires step-up verification, and you are notified on every channel whenever the policy is armed or a contact is added — if you see a notice you do not recognize, act immediately.

While your policy is armed

  • You can veto at any time before release — one tap in the app cancels a claim and resets the policy. If you cannot sign in (lost device, hospital stay), contact support@qpher.ai: after identity verification, support can place a veto or hold on your behalf without app login.
  • A claim is loudly visible. When anyone opens a claim, you and all your other contacts are notified on every channel, repeatedly, for the entire waiting period.
  • Qpher never decides you have died. There are no check-ins and no inactivity timers; only a person can start a claim, and the system's job is to enforce your rules.
  • Your vault survives a lapsed subscription. While a policy is armed the account is protected from automatic deletion; if payment lapses the account becomes read-only but the veto and claim pipeline keep working.
  • Once a year the app asks you to review the policy — check that heirs' emails are current and the right documents are selected. The reminder changes nothing by itself.

Changing your mind

You can disarm the policy, edit the document set, or remove contacts at any time. Deleting your account while a policy is armed requires a typed confirmation acknowledging that deletion disarms and destroys the legacy; your heirs and confirmers are not notified of pre-death changes.