Digital Inheritance: What Remains of a Person When the Password Runs Out
Tuesday. The Top Drawer of the Desk
He died on a Thursday. The funeral was on Monday. On Tuesday his daughter sits down to sort through the paperwork.
The top drawer holds exactly what it should: passport, insurance card, car keys, bank cards, a thin folder of contracts. Beside them, his phone.
What follows happens in steps. This is usually how it goes.
First. The phone is locked. Face unlock will not work again — that is not a metaphor, that is how the sensor is built. Nobody knows the passcode. After several wrong attempts the screen announces that the next try is available in an hour. Then in a day.
Second. She tries another route — through email, since every password reset leads there. The email password is unknown too. The "forgot password" link offers to send a code by SMS, to the number sitting inside the locked phone. The alternative is a code from an authenticator app. That app is installed on the same phone.
Third. The mobile carrier. Everything here is polite and by the book: death certificate, contract terminated, number returned to the carrier. From this moment on, that verification SMS will never arrive again.
Fourth. The bank. Accounts are frozen until the estate is settled — as they should be, the money is protected. Along with the card, the automatic payments stop clearing. Cloud storage, hosting, a music subscription, a domain renewal — all of it used to be debited invisibly, and now it invisibly stops being debited.
Fifth. A week later the daughter finds the official form for relatives — Google has one. She reads it carefully and runs into a single line: the company may close the account, and in certain cases hand over some of its contents, but it does not provide passwords or other login credentials. Not "will not" — does not, as a matter of policy.
Sixth. After that, nothing happens. The letters have not gone anywhere. The photographs are sitting on servers. The voice messages are intact. There is simply nobody left to open them.
There is no villain in this story. Nobody made a mistake, no employee behaved badly. Everything worked exactly as designed: the protection that guarded this man from strangers his whole life keeps working after his death. Now it works against his family.
This article is about what actually happens to a person's digital life once they are gone. No scare stories: only the rules already written into the agreements we all accepted without reading. And about what can be done in advance, while those rules still matter.
Chapter 1. What Actually Happens to an Account After Death
An account is not a thing. It is a permission
We say "my inbox," "my page," "my photos," and out of habit we assume we own them the way we own a cup or a car. In legal terms, that is not the case.
An account is a right to use a service, granted to you by a company under a contract. Not property — permission. And permission has an expiry.
The iCloud terms contain a section named exactly that: "No Right of Survivorship." Apple's wording is that, except as allowed under Digital Legacy and unless otherwise required by law, "your Account is non-transferable" and any rights to your Apple Account or its content "terminate upon your death" (iCloud Terms and Conditions, section D). The same clause carries the caveat — apart from the Digital Legacy mechanism, and apart from what the law requires. It also says that on receipt of a copy of a death certificate the account may be terminated and all content within it deleted.
This is not Apple being cruel. Nearly everyone has a similar clause: an account cannot be sold, gifted or bequeathed. Valve states plainly in the Steam Subscriber Agreement that it "does not recognize any transfers of Subscriptions (including transfers by operation of law) that are made outside of Steam." Transfers by operation of law is exactly what inheritance is.
The difference between a cup and an account becomes visible precisely once — when the heirs come for the account.
What is inherited and what is not
Take one legal system as an illustration. Under Russian law, an estate comprises things, other property and property rights. It does not include rights inseparably tied to the person, nor personal non-property rights and intangible benefits (Civil Code of the Russian Federation, art. 1112). Most civil-law countries draw a broadly similar line, though the wording and the exceptions differ.
What that means in practice:
- A phone and a laptop are things. They are inherited. Except you cannot switch them on without the passcode, and a passcode is not a thing.
- Money held in a service balance is a property right. It is inherited.
- A domain name is usually also a contractual right held against the registrar; a transfer is possible, but it is a separate procedure with paperwork.
- The right to log into an account is not a thing, not money, and not a property right in any clean sense. Here there is no single answer.
There is no single answer worldwide either. In 2018 the German Federal Court of Justice sided with the parents of a girl who had died: heirs get access to a social media account the same way they would get her paper letters and diaries (case III ZR 183/17, decided 12 July 2018, on the principle of universal succession under § 1922(1) BGB). In Russia, the Federal Notarial Chamber acknowledged as far back as 2021 that no established procedure for inheriting accounts exists, and singled out the main obstacle: user agreements frequently prohibit transferring access outright.
In the United States the picture is different in a way worth understanding, because it is the closest thing to a solution any legislature has produced. Most states have enacted RUFADAA — the Revised Uniform Fiduciary Access to Digital Assets Act — which gives executors, trustees and agents under a power of attorney a defined route to a deceased person's digital assets. More than forty states have adopted some version of it. Its logic is a ladder: an "online tool" provided by the service itself (Google's Inactive Account Manager, Apple's Legacy Contact, Facebook's legacy contact) sits at the top and overrides everything else; a will, trust or power of attorney comes second; the provider's terms of service come last. A separate and important limitation applies to the content of communications — under federal privacy law a provider generally may disclose the actual contents of emails and messages only where the user consented, which is one more reason those in-service settings matter more than most people assume.
In the United Kingdom there is no equivalent statute. Executors in England and Wales work from a patchwork: the platform's bereavement policy, the terms the deceased agreed to during their lifetime, and whatever credentials were left behind. Without an explicit authority in the will, an executor has no general legal right of access to online accounts. The Computer Misuse Act 1990 makes unauthorised access to a computer system an offence, which means a well-meaning relative logging in with a known password is, on a strict reading, doing something the criminal law does not permit. Parliament has been circling the problem — a Digital Devices (Access for Next of Kin) Bill and property-law reform on digital assets have both been under consideration — but as of the summer of 2026 the practical answer for a British family is still the same as everywhere else: what was set up in advance works, and what was not set up in advance turns into correspondence with a support desk.
We are not lawyers, and this is not advice. But the general picture is this: the law of digital inheritance is catching up with reality slowly, and the contract with the service is already in force today.
Why an envelope with passwords does not solve it
The most common piece of advice is to write your passwords on paper and put them in a safe or with a notary. It is sensible advice, and it solves the smaller part of the problem.
Legally. Handing over account credentials is prohibited by the terms of almost every service. Logging in with someone else's credentials formally remains logging in with someone else's credentials, even when it is a widow with a full legal claim to the estate and the best of intentions.
Technically. The password has long since stopped being the only key:
- Two-factor authentication. After the correct password, the service asks for a code. The code arrives by SMS to a number that no longer exists, or is generated by an app on a locked phone.
- Confirmation from a trusted device. Apple and Google both know how to ask you to "approve this sign-in from a device you already use." The only such device is that phone.
- Passkeys. Not a password but a cryptographic key bound to a device and to biometrics. It cannot be written into an envelope at all.
- Signing in from another country or a new computer. A sudden change of geography plus an unfamiliar device is the classic signature of a break-in. The service turns on extra checks at exactly the moment the family needs them least.
- Staleness. A password in an envelope is correct on the day it was written down. He changed it six months later, and the envelope became a piece of paper.
- Even the official mechanisms do not hand over passwords. Apple built the Legacy Contact, and even it does not receive Keychain data: passwords, payment information and passkeys go to nobody.
The large companies do have their own tools for this: Google, Apple, Microsoft, Meta. They work, but each has its own boundaries. We will go through them one at a time in the next chapter.
What a person loses by default
"By default" means: they did nothing special. Like most people.
| What exactly | What happens to it |
|---|---|
| Correspondence: email, messengers | The letters and messages are physically intact, but access is closed. Passwords are not handed out. Correspondence stored only on the device leaves with the device. |
| Photos and video in the cloud | They live as long as the account is active. Google deletes personal accounts that have not been signed into for two years, along with the contents of Gmail, Drive and Google Photos. |
| Purchased books, music, films | That was not a purchase, it was a licence. The licence is personal and non-transferable. |
| Games and game libraries | Steam does not recognise transfers of subscriptions made outside Steam. A library of hundreds of games stays bound to an account nobody is left to use. |
| Subscriptions and recurring charges | They keep charging as long as the card is alive. When the card is closed, services switch off one after another — often before the family even learns they existed. |
| Domains and websites | A domain survives on auto-renewal. The payment fails, the domain is released, and anybody can take it. The email on that domain dies with it. |
| Crypto wallets | Without the seed phrase, nobody can recover anything — including the wallet's developers. That is a property of the protocol, not a question for support. |
| The history of conversations with an AI assistant | The newest and the least protected of all. Among the leading AI services we could not find a trusted-contact feature or a published procedure for relatives. Only what the person exported while alive will survive. |
That last row deserves its own attention. People already talk to assistants about work, health, their children and their fears — for years, every day. It is the most honest diary that has ever existed: nobody writes it for an audience. And so far it has no heir.
Chapter 2. What the Companies Themselves Say
Every large company has written rules for the death of an account holder. They are not hidden: they sit in the public help pages and can be read in an evening. The strange part is elsewhere — almost none of them fire on their own. The tools exist, but by default they are switched off and have to be switched on by hand, during your lifetime.
Below is what the rules say as of August 2026.
Google: it asks in advance, but only if you show up
Google has the Inactive Account Manager. It works like this: you set a period of silence (from three to eighteen months), and if you have not used any Google service in that time, the account is considered inactive. Before that point Google will write to you several times and send an SMS — so that a holiday or a hospital stay does not get read as a death.
Then: up to ten trusted people. Each can be given something different — photos to one, Drive to another, mail to a third. Each receives an email with a download link, and the link is time-limited: by Google's own description, around three months.
The trusted person does not receive your account. They receive an archive — zip files containing what you allowed. Google does not hand the password to anybody, ever. Logging into your mail and replying to someone in your name will not be possible. This is an export, not an inheritance.
The tool works only with personal accounts: corporate and school accounts (Google Workspace) are outside its scope.
If you set nothing up, a different rule takes over. Google reserves the right to delete an account inactive for two years together with all of its contents — Gmail, Drive, Photos. The earliest deletion date under that policy was 1 December 2023. Almost any action counts as activity: reading an email, running a search, watching a video on YouTube. There are exceptions — the account is left alone if it carries an active subscription, a gift card balance, or previously purchased digital books and films.
Relatives without a configured tool are left with the request form. It offers three paths: close the account, request funds from it, or request its contents. Contents is the hardest road: Google requires a court order and reviews each case individually. And one detail that is easy to miss: if you choose "close the account" first, you cannot request the contents afterwards. The order in which requests are filed is not cosmetic — data first, funds second, closure last.
Apple: the Legacy Contact and its ceiling
From iOS 15.2 onward Apple offers a Legacy Contact. You pick a person, the device generates an access key, and that key has to be preserved: printed, filed with the papers, sent to the contact. After your death that person comes to Apple with two things: the key and a death certificate.
What opens: iCloud Photos, notes, mail, contacts, calendars, reminders, Messages in iCloud, iCloud Drive files, device backups. That is a great deal — essentially the contents of a life lived through a phone.
What does not open — and this is the more interesting part:
- purchased films, music and books;
- in-app purchases and subscriptions;
- payment information;
- the contents of Keychain — passwords, passkeys, Wi-Fi passwords.
The last item is worth rereading. Passwords are not inherited. And passwords are what open everything else: the bank, government services, email on another provider, the domain, the hosting. The Legacy Contact hands over the contents of iCloud and hands over none of the keys to the rest.
There is also a clock: by Apple's description, three years from the approval of the first legacy request, after which the account is permanently deleted. So it is a window in which to download everything, not an eternal vault.
Without a key issued in advance, what remains is the route through legal documents and, as a rule, a court order — or a request to delete the account.
Meta: the page stays, the messages do not
Facebook moves a deceased person's account into memorialised status: "Remembering" appears above the name. A friend, a follower or a relative with documents can request it.
In advance, you can appoint a legacy contact. They can pin a farewell post to the top of the page, accept new friend requests, change the profile and cover photos, manage the tributes section, and remove tags. If you specifically allowed it — download an archive of your posts, photos and profile information.
What they cannot do: log into the account and read private messages. Nobody gets into the Messenger conversations — years of talking with the people closest to you.
Instagram has no legacy contact at all. It has memorialisation: such an account cannot be logged into, cannot be changed, and posts stay visible to the same audience as before. Relatives with documents can request deletion — and that, in substance, is the only action available to them.
Company policy and national law sometimes diverge — that German decision of 2018 mentioned in the first chapter was handed down against precisely this kind of help-centre rule. So the conversation is not closed: somewhere a court may decide differently from what a service's terms say. But treating litigation as a plan is a poor idea: it means years, money and an unknown outcome.
Microsoft and Amazon: on request and with documents
Microsoft has Digital Legacy in OneDrive. You invite a trusted person, a code is generated, and you pass it to them. When the time comes, they enter the code, wait 72 hours, and get access to your files and photos — read-only. The code does not change and does not expire. Only one trusted contact can be designated at a time, and the 72-hour delay exists so that a living account holder can cancel the request.
The limitation is right there in the name: this is OneDrive. Outlook mail, Xbox, purchases — all outside the mechanism. For those, relatives go through the Next of Kin process: a request to Microsoft's account records team, a death certificate, proof of relationship, sometimes a court order. The Microsoft account itself is treated as expired after two years of inactivity.
Amazon has no legacy contact. It has bereavement support: with an executor's documentation and a death certificate an account can be closed or information about it obtained. The Kindle library closes together with the account.
The one thing at Amazon that genuinely works only works while you are alive: Amazon Household and the shared Family Library — two adult accounts sharing purchased books. That is not inheritance, but it is a way to make sure the books still open for the second person afterwards.
Purchases: a file or a licence
This is where the gap between what people believe and what is written is widest.
The "Buy" button in a digital store almost nowhere means "receive a file." It means "receive a licence" — a right to read or watch, bound to your account. The Kindle Store terms say so directly: "Kindle Content is licensed, not sold, to you by the Content Provider" (Kindle Store Terms of Use).
The licence is non-transferable. Which means that, by the companies' own rules, it is not inherited: a library of three hundred books exists for exactly as long as the account exists.
Games are the same. In May 2024 Steam Support told a user that Steam accounts and games are not transferable, and that Support cannot give another person access to the account or merge its contents into another account.
The storefront can also simply close. On 18 July 2025 Microsoft stopped selling films and television shows in its store, with no advance announcement. Existing purchases were promised continued availability in the app; refunds were not offered. Which is to say a purchase lasts not as long as you need it, but as long as the company keeps the service running.
There is now a law about this: in California, AB 2426 has been in force since 1 January 2025 — stores are barred from using words like "buy" or "purchase" for digital goods whose access can be revoked, unless they clearly disclose that what is being sold is a licence.
The flip side matters just as much. Everything downloaded as an unprotected file — mp3, epub, your photographs, your documents — is an ordinary file on a disk. Those are inherited like a box of papers: whoever got the disk got the contents. The boundary of inheritance runs exactly here, between "I have the file" and "I have access."
Summary
| Company | What is inherited | What is lost | Must be set up in advance |
|---|---|---|---|
| An export of selected data: Gmail, Drive, Photos, YouTube, Calendar | The account itself and the password; without setup, only via a court order — and after two years of silence the account may be deleted | Yes — Inactive Account Manager, up to 10 trusted people | |
| Apple | iCloud data: photos, notes, mail, messages, files, backups | Purchased films, music and books; in-app purchases; payment information; every password in Keychain | Yes — Legacy Contact and a saved access key |
| A memorialised page; with permission, an archive of posts and photos | Logging in, and all private Messenger correspondence | Yes — legacy contact | |
| A memorialised profile, posts stay visible | Logging in, any changes, messages; relatives can only delete the profile | Nothing to set up — the tool does not exist | |
| Microsoft | OneDrive files and photos, read-only; everything else on request with documents | Mail, Xbox and purchases sit outside the mechanism; the account expires after two years of silence | Yes — OneDrive Digital Legacy |
| Amazon | Closing the account and obtaining information about it — with documents | The Kindle library, purchased video and music: the licence is non-transferable | Partly — the shared Family Library, and only during your lifetime |
| Steam and gaming platforms | By platform rules — nothing | The entire game library along with the account | Nothing to set up — transfer is prohibited |
What all of this adds up to
Here is what becomes visible once you read it all in one sitting.
First: where a tool exists, it is switched off. Google, Apple, Facebook, Microsoft — in every case you have to go in and turn it on. Nobody will turn it on for you, and none of them will remind you.
Second: almost everywhere what is inherited is a copy, not access. An archive is better than nothing, but it is a folder of files, not a living account.
Third: purchases are inherited almost nowhere, because what was bought was not an object but a permission. The permission ends with the account.
And fourth, which is no longer about the rules. None of these tools preserves what you said. A Gmail archive is letters. An iCloud export is files and pictures. No company promises to preserve how you thought and how you talked. That is what comes next.
Chapter 3. Conversations With AI: The Newest and Most Fragile Part of an Estate
Over the past couple of years millions of people have acquired an archive that simply did not exist before. Not letters, not an album, not documents — hundreds of hours of conversation. About the diagnosis that is too frightening to say out loud at home. About the child who stopped picking up the phone. About the job you need to leave with nowhere to go. About money, about ageing, about guilt towards your parents.
People tell an assistant what they do not tell the living: it will not get tired, will not judge, and will not repeat it to the neighbour. The result is the frankest document about a person that they leave behind. And simultaneously the worst protected.
The difference from a messenger: there is no second copy here
Correspondence with a human lives in at least two places. You deleted it — the other side still has it. Your phone burned — everything is intact on theirs. When a person dies, their words remain with the people they spoke to: with a wife in WhatsApp, with a son in Telegram, with a sister in email. The family later collects those fragments and assembles a portrait out of them.
With an assistant there is no second party. Your interlocutor is not a person with a phone but a service, and for that service the exchange is not memory but operational data with a retention policy and an expiry date. It does not keep it "to remember you by." It keeps it exactly as long as its own rules say, and erases it on schedule without asking.
If you did not make a copy yourself, nobody has a copy. Not the family, not a friend, not a cloud.
What happens to the archive next
The sequence is roughly as follows (each service has its own rules and they change; this is the picture as of mid-2026):
| Event | What becomes of the conversations |
|---|---|
| You delete one chat | It disappears from your history immediately, and from the systems within about 30 days. OpenAI's help centre puts it as deleted chats being permanently deleted from its systems within 30 days |
| You delete the account | The same thing, but all of it, with no way back |
| You did nothing | Scheduled auto-deletion runs: in Gemini, history is erased after 18 months by default (configurable to 3 or 36 months, or off) |
| A conversation went to human review | At Google such chats are kept for up to three years and are not deleted along with your history — but you will not get them back either: they are disconnected from your account |
| You died | Nothing happens. The service does not know and carries on counting by its own clock |
That last row is the important one. None of the major chat assistants asks at sign-up who should receive your conversations. Google has a mechanism for this case — the Inactive Account Manager, covered in the previous chapter. But it has to be switched on in advance, by hand, and almost nobody does.
Assistants that live outside a mail giant do not even have that. The account is non-transferable, there is nowhere to name an heir, and there is no published "the owner has died" procedure. A legal right to digital property written into a will does not by itself open the door: access to an account and a right to it are different things. We are not lawyers and we do not give advice, but the fact is simple: the only thing that actually reaches the family is what you exported and placed somewhere they can reach while you were alive.
When it is not the account that closes, but the service
At least the account is yours. The service is not.
In the autumn of 2023 the Soulmate app shut down: the company was sold, the product wound up. It had thousands of people who had spent months talking to their character every day. After the announcement, genuine obituaries appeared on Reddit — people were saying goodbye.
Two years later the story repeated in a milder form. On 5 September 2025 the team behind the Dot app announced its closure, and on 5 October they switched the service off. They left the app running for a month so people could export their data — and the export button itself, judging by the release notes, was only added in August, weeks before the end.
From which comes a rule worth memorising: the window for rescuing an archive is opened by somebody else's company, lasts weeks, and falls at a moment when you have other things on your mind. An archive that exists only inside a service lives exactly as long as that service's business does.
Why "data export" often does not hand over the conversation
To be fair: at the major chat assistants the export is honest. With ChatGPT it is an archive containing conversations.json and a chat.html file with the turns, the roles and the timestamps; with Gemini it is JSON with your prompts and the responses. Full text, not a digest.
The problem is elsewhere — in four "buts."
First. Exporting requires a live sign-in: email, password, second factor. For a person who is no longer here, that is insurmountable — and that is precisely when the archive is needed.
Second. With voice assistants and chatbots embedded in other products, what you get is not a dialogue but a log: rows of "date — request — response," torn out of context. In Gemini the conversations actually sit in My Activity, next to search history — as a trace of activity rather than as correspondence. And if history saving was switched off, there is nothing to export at all: the conversations were never stored.
Third. Part of the archive does not physically exist. Apple states that Siri requests are associated with a random, device-generated identifier that rotates multiple times per hour and is not tied to your Apple Account, and that audio is not retained by default. There is nothing to hand to the heirs — not out of spite, but because the link between those records and you was never created.
Fourth. Format. conversations.json is a tree with branches for edits and regenerations — a machine file. In twenty years your grandchild will need not only the file but a program that can open it. An archive you cannot read with your eyes is half an archive.
The assistant's "memory" is a note, not an archive
The feature that various products call memory deserves separate treatment — and should not be confused with storing correspondence. It is built roughly the same way everywhere.
The assistant does not remember your conversations. It keeps a short note about you: name is such-and-such, two children, writes Python, likes short answers, does not eat meat. The volume is on the order of a page or two of text; users measuring it report something like fifteen hundred words, and no official figure has been published. When the note fills up, a "memory full" message appears, and new entries start pushing out old ones.
This is not done out of stinginess but out of how the models are built. Before every answer, everything the model must take into account is fed to it again — and that window has a size limit. Every extra character in it costs money and adds latency. Passing thousands of pages of your history into it on every turn is impossible technically and economically alike. So the history is compressed down to facts.
The difference is fundamental. The note stores information about you: age, profession, preferences. The archive stores your words: how you argued with yourself at three in the morning, where you stumbled, what you advised your daughter, what words you used to justify yourself. In twenty years, information about a person is worth almost nothing — everyone knows it anyway. The words are worth everything.
Why this matters more than photographs
A photograph shows how a person looked and where they stood. It does not show how they thought.
A conversation does. In an archive of correspondence you can see how a person made decisions, what they feared, what made them laugh, what they repeated year after year, how their view of the same thing changed. A grandchild reading such an archive will not see an official portrait — they will hear a living person, often not at their best, and that is the entire point.
An archive like that does not appear on its own. It is not inherited by default, it is not released on production of a death certificate, and it will not survive a service closing down. It survives only where somebody decided in advance to preserve it: a copy outside the service, in a readable form, encrypted, with the people close to you knowing where it is and how to open it.
That decision is made once — and, like everything in this subject, always in advance.
Chapter 4. How Inheritable Memory Is Built in CODE Eternal
So far we have been talking about how things work by default: access is tied to a living person, the password dies with them, and the correspondence stays with a company to which you are nobody.
Now for a construction built for the opposite. We will go through it as a mechanism: what happens to your words after you write them, where they are kept, who can read them, and what of it reaches your children. With the caveats and the downsides — every design has them, and glossing over them would be dishonest.
The whole conversation is preserved, not a digest
An ordinary assistant remembers a window: the last few thousand words. Everything past the edge of the window it either compresses into a short summary or forgets. After a year of talking, what remains of the conversations is a note: "user asked about renovations, lives in Minsk, has a daughter."
We do it differently. Every pair of turns — yours and AIfa's reply — is appended to an archive with a timestamp. Nothing is trimmed and nothing is paraphrased.
When the current block grows to a limit of roughly 68 kilobytes of text (several hundred turns), what has accumulated is sealed into a separate immutable chunk, and a fresh live block begins. Chunks are numbered in sequence. The full correspondence is a chain of sealed chunks plus the current block.
The difference between "trim" and "seal" is the whole point. In the first case the old material disappears to make room for the new. In the second the old material is frozen whole and stays available: in ten years your child will be able to read not a digest but the conversation itself — with its date, your words and your intonations.
One engineering detail that cost us a separate investigation. If a previous record turns out to be unreadable for any reason, the system does not write new data over the top of it; it returns an honest error instead. It used to be the other way round: one failed decryption would silently replace a person's entire archive with their last sentence. Losing one turn is survivable. Losing the history is not.
The memory key is a fingerprint of an email address
A person is identified in memory not by name and not by a database row number, but by a fingerprint of their email address: the output of a sha256 function. The address cannot be reconstructed from the fingerprint, but the same address always yields the same fingerprint.
From which follows something visible in daily use: the conversation is one and the same across all of the project's sites. The memory store is shared, and every record is tagged with the site where it was made. You started on one and continued on another, and AIfa remembers what was being discussed and can point back to it: "we already went over this on aifa.works."
The second consequence matters more: inheritance is bound not to a device, not to a browser and not to an app that may disappear, but to an email address — the same one people usually put on their documents.
The three levels of PADAM memory
Memory is divided into three layers. Each solves its own problem, and together they deliver both a fast answer and long-term storage — qualities that do not coexist in a single store.
| Level | What it holds | Where | Why |
|---|---|---|---|
| Operational | the current session, the latest turns | Redis / Vercel KV | an answer without delay |
| Semantic | a meaning index of all messages | pgvector in Postgres (Neon) | finding the right thing among thousands of turns |
| Eternal | the full correspondence in encrypted form, plus the digital passport | Arweave, with a record on the blockchain | storage that does not depend on us |
The middle level is worth explaining. Every message is turned into a vector — a set of numbers describing the meaning of what was said. Search runs on meaning rather than on words: ask "what did I say about my father's house" and it will find a conversation in which the word "house" never appeared, but "the dacha outside Minsk" did.
That layer is an index, not a source of truth. It can be lost in its entirety and rebuilt from the archive. The source of truth is the correspondence archive itself.
Encryption: everyone has their own key
The design is simple and worth understanding:
- every person has their own random 32-byte key, and the correspondence is encrypted with AES-256-GCM;
- the key itself is not stored in the clear but wrapped by a master key that lives only in the server's protected environment: it is not in the browser, not in the source code, and not in the backups that leave our perimeter;
- what goes to the blockchain is already-encrypted text. Alongside it, only technical tags: record type, an "encrypted" marker, and the owner's fingerprint. Neither the email address nor the name is on-chain.
Without the key a record is a meaningless string of characters. It can be downloaded, but not read.
And immediately about what is not here. This is not a scheme in which only you hold the key and nobody else. The server can decrypt your correspondence — otherwise AIfa would not remember it and an heir could not receive it. The choice was between "nobody but you can read it, and there is also nothing to pass on" and "the memory works and can be passed on." We chose the second and we say so plainly, rather than hiding it behind the word "encryption."
Arweave: pay once, stored for centuries
Ordinary cloud storage is built like a rental: you pay monthly and the files stay, you stop paying and the files are deleted. Heirs will not pay, because they do not know what they are paying for.
Arweave is built differently. Uploading is paid for once. The payment is split: part goes to those storing the data now, and the larger part into a common endowment out of which storage is paid for in the years that follow. The network's model is calculated two hundred years ahead and rests on the fact that storage keeps getting cheaper year on year: over the past half-century the cost of storage has fallen by an average of roughly 38% a year.
Two hundred years is not a promise made by our company. It is the model of the network itself, and it operates whether we exist or not.
The second property: a record cannot be changed and cannot be deleted. Not by you, not by us, not on demand, not by accident. Our own user agreement puts it without decoration: "Blockchain transactions are irreversible."
That property has a flip side, and it is not a small one. Article 17 of the GDPR gives a person the right to demand erasure of their data — and a record on a blockchain cannot be erased. The contradiction is real, regulators have taken it seriously, and a detailed look at their position is in the chapter on the legal side. Our answer is short: only ciphertext goes on-chain, the key is stored separately and never goes on-chain, and destroying the key renders the record permanently unreadable. That is the only form of "deletion" physically available here.
But to say the record will disappear would be untrue. It stays in the network. An individual gateway may stop serving it — every gateway keeps its own lists of what it displays — but the data does not vanish from the network. Eternal storage and the right to erase your trace are things that never fully reconcile. We chose the side of preservation, and a person should know that before they start writing.
The digital passport
The correspondence is encrypted and not meant for outside eyes. But a personality also has a public part — what a person is willing to show about themselves.
The digital passport is a separate record on Arweave: name, pseudonym, a short text about yourself, a manifesto, links, an avatar. There is no email address in it — only its fingerprint in the subject field. The document number is derived from the same fingerprint.
Three properties make this more than a profile page:
- The record is created once. A repeat attempt returns the same one — a passport is not minted twice.
- It exists independently of our sites. The link points at a network gateway, not at our server. Were the project to close tomorrow, the record would remain available at the same link.
- It can simply be handed over. A link and nothing more; the person looking at it needs no registration.
The flip side is the same as for everything in the eternal part: whatever went into the passport stays there forever. Which is why only what a person consciously chose to make public goes in.
What an heir actually receives
Precision is needed here, because the subject invites pretty language.
An heir receives records: the full text of the correspondence in chronological order, links to the Arweave records that can be verified independently of us, and the digital passport. That is memory and documents — what the person wrote, and how they themselves chose to remain visible.
An heir does not receive a talking copy of the deceased. We preserve memory and records, not a personality as a physical fact. Anything that can be built on this archive is a conversation resting on a person's real words, not a continuation of them.
Passing access to an heir is provided for on the Family Archive ($100 per month) and Digital DNA ($1,000 one-off per device and $200 per month thereafter) tiers. And to be honest about the boundary: there is no separate ready-made "heir" role with a button in the dashboard today — access is passed through the passport link and the account, not with a single click. On the Spark tier ($15 per month) the correspondence is likewise preserved in full and likewise encrypted, but there is no configured access transfer there, and saying otherwise would be a lie.
And a caveat without which the chapter would be incomplete: we are not lawyers, and what is described is a technical mechanism, not a will. The order of succession to property and digital rights is determined by the law of your country and is executed by a notary or solicitor. Our mechanism gives an heir access to the archive; it does not replace the document by which third parties will recognise that access.
The difference is worth understanding in advance — and the next chapter is about exactly that.
Chapter 5. The Legal Side: What Can Be Done Today
A caveat first, and it is not a formality: this is not legal advice. Succession law differs from country to country, and on digital assets the practice has not settled even within individual countries. Everything below is a starting point for a conversation with a notary or a solicitor, not a substitute for one.
The fork: property on one side, the account on the other
In the first chapter we already named one rule — art. 1112 of the Russian Civil Code: an estate comprises things, other property, property rights and obligations; rights inseparably tied to the person of the deceased do not pass. There is no separate rule about accounts, and the Federal Notarial Chamber openly acknowledges that the inheritance of digital assets is unregulated and that the question is generally resolved through the courts. Treat that as one legal system's snapshot, not as a universal rule — but the shape of the problem is the same everywhere.
From that comes a fork worth keeping in mind.
- Inherited: money in accounts, domain names, rights in the texts, photographs and music you created and the income from them — that is property and property rights.
- Usually not transferred: the account itself. An account is a contract with a service, and the terms of that contract most often prohibit transfer to another person. In the iCloud terms Apple says of the account directly that it is "non-transferable," and that rights in it terminate on the owner's death. Exactly one exception is carved out: a Legacy Contact named in advance.
Practice varies a great deal. In the United States, RUFADAA is in force — a uniform act on fiduciary access to digital assets, adopted by most states, with more than forty having enacted some version of it. The detail that matters most for us is its order of priority: a setting made inside the service itself (an "online tool") outranks an instruction in a will. In other words, a checkbox in Google's settings outweighs a document sitting with your attorney. Second in line comes the will, trust or power of attorney; only if neither exists do the provider's terms of service decide the question.
Two further American details are worth carrying with you. First, RUFADAA distinguishes between a catalogue of communications — who wrote to whom and when — and the content of communications. A fiduciary can generally obtain the catalogue on the usual documentation, while the content of emails and messages requires either the deceased's consent expressed through an online tool or in an estate document, or a court order — a distinction that traces back to federal privacy law from the 1980s that was never written with inheritance in mind. Second, RUFADAA is an access statute, not an ownership statute: it lets a fiduciary in, but it does not convert a licence into property. Your executor may lawfully reach the Kindle library and still be unable to move it to anybody.
Britain sits at the opposite end. There is no dedicated statute at all, and executors work from the platform's bereavement policy plus whatever the deceased left behind. An executor of an English estate has no general right of access to online accounts, and the Computer Misuse Act 1990 makes unauthorised access an offence — which means the ubiquitous family workaround of "we know the password, we will just log in" sits on the wrong side of the criminal law even when everyone involved is acting in good faith and inherits everything anyway. In practice British solicitors advise the same three things: name the digital estate in the will, appoint someone specifically for it, and use the platforms' own tools, because those are the only instruments that work without anybody's permission.
There is one more British wrinkle worth knowing. Whether a "digital asset" is property at all has been the subject of live law reform work, and the direction of travel is towards recognising a distinct category of digital things that can be owned. That helps with crypto-assets and tokens. It does very little for an email account, because an email account was never the thing you owned — the thing you had was a contract, and contracts of that kind are drafted to end with you.
The conclusion that holds in any jurisdiction: settings inside services are not an appendix to a will — they are the first thing to do. The service executes them itself, automatically, without a court and without documents.
A will: what to put in it and what not to
Worth including: property rights (domains, accounts, rights in works and the income from them), the appointment of an executor, a statement that you have a digital archive, and where to find the instructions for it.
Not worth including — passwords. Four reasons, each sufficient on its own.
- A will stops being confidential after death. Its contents become known to the circle of heirs, and in common-law countries a will admitted to probate becomes a public record: anyone can turn up and obtain a copy. A password in such a document is a password published on a delay.
- Passwords change, wills do not. Every password change would require re-executing the document. Within a year the list will be stale, and you will not find out.
- Time works against paper. In Russia a certificate of the right to inheritance is issued, as a general rule, after six months (art. 1154 of the Civil Code). In England a grant of probate routinely takes months more once the paperwork begins, and in the United States probate is measured in months to years depending on the state. Services, meanwhile, run on their own clocks: Google deletes a personal account after two years of silence, and Telegram self-destructs an account by default after 18 months without a sign-in. Six months for paperwork is half the runway, and that is in the best case.
- Passing on a password breaches the service agreement. Signing in under someone else's account may in a number of countries be treated as unauthorised access — even if it is the son or the wife signing in. Heirs receive a right to property, not a right to impersonate the deceased.
Access to passwords: a trusted contact instead of an envelope
The mechanism that works is built differently from "hand over the password." It hands over not the password but the ability to obtain it after a delay you can cancel if you are alive.
- Bitwarden — emergency access. You designate a trusted contact, a waiting period (from 1 day to 90 days) and a level: view only, or full takeover of the vault. The contact requests access and you get a notification. Reject it and nothing happened. Fail to respond and access opens when the period expires.
- 1Password — recovery via a family account organiser, plus a printed Emergency Kit, which logically belongs wherever the rest of your death-related documents are.
The waiting period is the insurance. Three days is enough for you to notice a request and reject it if it was made in error, and far too short for the family to lose access to everything.
The right to be forgotten versus the permanent record
Here there is a genuine conflict, and it should not be papered over. Article 17 of the GDPR gives a right to demand erasure of personal data. A blockchain is built so that a record cannot be removed from it — that is the point of it. A demand to "erase this" is technically unenforceable.
Regulators have acknowledged this and proposed a way around. The European Data Protection Board, in Guidelines 02/2025 on the processing of personal data through blockchain technologies (first version adopted 8 April 2025, updated version adopted 7 July 2026), strongly advises against placing personal data in the chain itself — neither in clear text nor in encrypted or hashed form: what belongs on-chain is a pointer, with the data itself off-chain. France's regulator CNIL pointed to a different route back in 2018: delete the key with which the data was encrypted, and the record remains while becoming impossible to read.
From which come three questions worth asking any eternal-storage service — including us:
- What exactly goes on-chain: the data itself, or only a fingerprint?
- Is the data encrypted before it leaves for storage?
- Who holds the key, and can a copy of it end up with the service?
If what goes on-chain is an encrypted block, and the key is held by you and by whoever you passed it to, "deletion" turns into destroying the key. The record stays forever and there is nobody left to read it. This is the only known way to reconcile eternal storage with a right to erasure — and it is also why the key must not be casually lost: it cannot be recovered from outside, and that is precisely where its value lies.
Checklist: an evening's work
Every item can be done today, and none of them requires a lawyer.
- Google — open Inactive Account Manager in your settings. Set the period of silence and name your trusted people: Google allows up to ten, and each can be given different data.
- Apple — add a Legacy Contact. They are issued an access key; together with a death certificate that is sufficient. Access lasts three years from the approval of the first request, after which the account is deleted.
- Check what Apple does not hand over — purchased films, music and books, subscriptions and the contents of Keychain do not pass to a Legacy Contact. Whatever of that matters to you, save separately.
- Facebook and Instagram — appoint a legacy contact, or conversely instruct that the profile be deleted. A legacy contact cannot log into the account and will not see private messages — they pin a farewell post and, if you allowed it, download an archive.
- Telegram — check "Delete my account if away for." The default is 18 months without a sign-in, and it silently takes all the correspondence with it.
- A password manager — get one if you do not have one, and switch on emergency access with a delay of several days.
- Two-factor backup codes — print them. Without them, access to the phone will not save you.
- A list of paid services on a single sheet: domains, hosting, subscriptions, accounts. No passwords — just the names and whose name each is in.
- Export the photo archive (Google Takeout, iCloud) to an external drive and put it where the family will find it.
- A letter of instruction — "where everything is": no passwords, with a pointer to the password manager and the names of the trusted contacts.
- Say it out loud to two people — that you have done all this, and where the envelope is. A setting nobody knows about does not work.
- A calendar reminder once a year — to re-check that the contacts are still alive and the services have not changed their rules.
The first five items take under an hour and close most of the risk. The rest is one evening's work.
And once more: for your specific situation — an inheritance agreement, a business, assets in several countries, minor children — go to a notary or a solicitor. The service settings you can do yourself today; everything touching property and money is worth executing with a person who is answerable for the wording.
Chapter 6. What to Pass On to Children Besides Files
The legal part closes the question of who gets access. A second question remains, and it is no less important: what exactly does a person receive once they have the access.
A folder is a burden. An archive is a gift
Picture a four-terabyte external drive with a label reading "Misc." Inside: sixty thousand photographs named IMG_2847.HEIC, three folders called "New folder (2)," a mail archive that will not open without a password, and a birthday video in which it is impossible to work out whose birthday it is.
Whoever receives that drive will first be at a loss, then feel guilty, and a year later put it on a shelf. Not because they do not care. Because opening a drive like that is many evenings of work, and there is no obvious place to start.
The difference between a burden and a gift is not the volume, and not where things are stored. It is whether there are human words next to the files.
| A folder of files | A living archive |
|---|---|
IMG_2847.HEIC | "July 2009, Lake Naroch. On the left is Uncle Slava; he left the country a year later" |
| A chronology based on file modification dates | Stories that have a beginning and an end |
| Passwords unknown, part of the data unopenable | It is clear who gets in and how |
| A format nobody will be able to open in 20 years | Text, jpeg, ordinary audio files |
| No way to tell what is valuable here | There is a map: "start here" |
An archive becomes comprehensible when it has five things: captions (who, where, when), explanations (why this was kept), an order based on meaning rather than file dates, simple formats, and one point of entry — a short text that explains the rest.
What is worth recording deliberately
There are things nobody records, because they seem self-evident. And those are exactly the things people ask about when there is no longer anybody to ask.
- Where the family came from. Names, cities, who resembles whom, how they ended up where they ended up. Two generations on, this gets reconstructed from registry archives — if it gets reconstructed at all.
- Why the decisions were what they were. Why you left in ninety-eight. Why you did not sell the flat. Why you fell out with your brother and why you made it up afterwards. The event can be learned from relatives; the reason only from you.
- Your voice. Fifteen minutes of a recording of your ordinary speech is worth more than a hundred photographs. People forget how someone sounded very quickly, and it is one of the most painful losses.
- Who is who in the photographs. Go through a hundred pictures and name the people out loud. Nobody else will ever be able to do this.
- The everyday things. The recipe everyone asks for. How you make tea. The catchphrase the children repeat without remembering where it came from.
- What is kept and why. Not a will but an explanation: this box is your father's letters, do not throw it out; the dinner service can go, it is not a family piece.
- Answers to the questions they will ask later. "Were you frightened?" "Do you regret it?" "What would you do differently?" Answer them now, before the question turns into silence.
How to talk to AIfa so that you end up with an archive rather than a pile of queries
The difference between "I used an AI" and "I ended up with an archive" comes down to a few habits. They are simple.
- Name people by name and relationship. Not "grandmother" but "Grandmother Nina, my mother's mother, from Gomel." In thirty years, "grandmother" is an unknown person.
- Start with a date and a place. One sentence at the beginning of a story: "Summer of 1996, Minsk." After that, talk however you like.
- Tell a story whole, in one go. A fragment spread across three different days is harder to assemble than one long rambling story.
- Ask to be questioned. Say: "Ask me three questions about my school." An interview pulls out more than a monologue — you answer things you would never have thought of yourself.
- Explain, do not list. "We moved in 1998" is a fact. "We moved in 1998 because my father was made redundant, and I am still not sure we did the right thing" is an inheritance.
- Mark who it is for. "This is for Anya, for when she is eighteen." Notes like that later make it possible to assemble a letter to one specific person.
- Do not edit yourself. The slips, the pauses, the "well, anyway" — that is you. Tidied-up text reads like somebody else.
- Once a month, take apart one photograph. Send a picture and describe what is in it. Twelve conversations a year, and in ten years a hundred and twenty photographs are captioned.
Nothing needs to be saved separately: the conversation preserves itself — once an hour, or immediately once the dialogue grows past 90 kilobytes. That is the main difference from "I must remember to make a backup." People always forget the backup.
Why memory that answers back is a different thing
A photo album holds the answer to a question you already asked when you took the picture. An archive you can query answers a question nobody has thought of yet.
The daughter is thirty-four, she has just had a baby and has not slept for three weeks. She wants to ask: "Mum, how did I sleep?" A folder with twelve thousand photographs does not answer that. An archive with words in it does: it finds the conversation in which you told the story, and shows exactly when you said it.
An honest boundary matters here. This is not resurrection and not "mum is back with us." AIfa does not become the person and does not speak for them. It finds what was said and shows the source: where, when, in which conversation. The difference between "mum would have said" and "mum said, on this date" is fundamental, and it has to be kept honest, or the archive turns into fantasy.
That same distinction explains why any of this sits on top of the platforms' own tools. Apple's Legacy Contact, Google's Inactive Account Manager, a Facebook page's legacy contact — these are good mechanisms, but they are about the account, not the person: one hands over files for three years, another an archive behind a link, and the third does not read the correspondence at all. An account can be closed; memory cannot, if it is preserved separately and in your hands.
Frequently Asked Questions
What follows is what people ask when they get this far. Short answers, no hedging, including the uncomfortable parts.
What if your project shuts down? Then the website, the dashboard and AIfa herself stop working — that is where the answer has to start. But the records already committed to Arweave are not on our servers: the network stores them regardless of whether we exist. Every record has a transaction identifier, and with it the document can be read through any public gateway — there are hundreds. The space is paid for once, upfront. This is not a claim to take on trust: open a passport link and it will open without signing into any dashboard.
Who can read my memory? Can AIfa show it to somebody? To other users — no: everyone has their own folder tied to their account. What goes to the blockchain is encrypted with AES-256-GCM; we checked by pulling our own records back out of the network, and what is there is unreadable bytes. Now the uncomfortable part. On the server the archive is protected by access controls, not by your personal key: there is no end-to-end encryption today under which even we could not read it. It has been written but not enabled: a key that lives only in the browser means that clearing the browser by accident kills the memory forever.
And if I change my mind and want everything deleted? The account and the copies on our side we will delete on request. The blockchain is different: a record accepted by the network cannot be withdrawn by the network, by you or by us. That is not our policy but how Arweave is built, and it should be known in advance. The record stays in the network encrypted, but the honest formulation is this: we cannot promise it will disappear. If erasing everything down to the last byte is essential to you, eternal memory is not for you.
Is it not dangerous that a record cannot be erased? That is the flip side of what people come here for: what cannot be erased also cannot be lost when a company changes its policy. The risk is real: an eternal record is no place for things you might regret — other people's secrets, documents, passwords, diagnoses. The European regulator says plainly in its blockchain guidelines that immutability conflicts with the right to erasure, and advises against placing personal data in the chain itself without pressing need.
What does an heir see — everything, or only what I left? There is no separate "heir" role with a ready-made button in the dashboard yet, and I am not going to pretend there is. Today it works like this: the public passport opens from a link without signing in and is visible to anybody you gave the link to; the encrypted conversation archive is tied to the account and does not open to anybody by itself. You set the scope of access: whatever you handed over along with the access is what the heir sees.
How is this different from a cloud drive with an "archive" folder? A cloud lives as long as the account lives: Google reserves the right to delete an account and its contents after two years of inactivity — and inactivity begins precisely when the person dies. A cloud requires a password, and platforms prohibit passing passwords on even to heirs. And what is on the drive is files, not meaning: a folder with ten thousand messages is technically intact, but nobody will read it. We store correspondence in a way that lets you not only download it but ask it: "what did grandfather say about this house?"
Why pay, if I can download my own correspondence? Downloading it is the right thing to do, and it is not competition for us, it is hygiene. Google Takeout exports mail and photos, Telegram Desktop hands over the full history as JSON or HTML, WhatsApp has an export too, though a limited one. The problem is not the export but what comes next: a drive breaks, or goes to the tip with an old laptop, and ten years later it is unclear what would even open the archive. We take on the repeatability: the copy is made automatically, once an hour, and travels to several independent stores.
What happens if I stop paying? Records already committed to the network are paid for in advance and do not depend on a subscription — they cannot be "switched off for non-payment" even if we wanted to. Preserving the correspondence itself is free: by our own rule, conversations are filed into a person's private folder on the paid tiers and on the free one alike. A subscription pays for AIfa's work — the answers, the amount of memory in active use, the dashboard features — not for your records' right to exist.
Have Google and Apple not solved this already? Partly — and it is worth using regardless of us; the mechanisms are covered in chapter two. But the boundaries are noticeable: Google hands over an archive rather than access, and only if you switched the tool on in advance; Apple does not pass on purchases or Keychain contents, and the access window is capped at three years; a Facebook legacy contact can neither log in nor read private messages. None of them stores conversations with an assistant.
What about the books, music and films I paid for — are they inherited? As a rule no, and it is written into the agreements themselves: the Kindle Store terms state directly that the content is licensed, not sold. The licence is personal and non-transferable: it gives a right to read and listen while you are alive. Family practice frequently departs from the letter — people go on using a shared account, in spite of the rules rather than because of them.
My children do not use AI — do they even need this? No AI is required to open what you left: the passport opens in an ordinary browser from a link, with no installation and no registration. And one observation, offered without pressure: people rarely want to read a parent's archive in the first year. They want it in five or ten years, when they have children of their own and questions of their own. A permanent record will wait for that moment even if today nobody needs it.
What if I change my email address? The email address on the account can be changed. What matters more is that what has been written to the network is not bound to the email: a record is addressed by its transaction identifier, and that does not change because you switched mailbox, provider or country. A nickname is fixed to a person permanently, separately from the account: it stands in the passport, and a passport cannot be rewritten on-chain.
What if my heir loses access? This is the weakest link, and it is not the blockchain. The public passport cannot be lost: it is in the network, the identifier is enough to open it through any gateway, and one gateway going down does not leave an heir with nothing. Access to the encrypted archive rests on a key: if the key is lost, the contents stay in the network unreadable forever. That is mathematics, not a support desk; there is nothing to restore "on application." Hence the advice notaries also give: keep the access where the important papers are kept, and not in a single copy.
How legal is this in my country? We are not lawyers, and the article does not replace a consultation: rules differ from country to country and they change. The general picture is this: correspondence and files inherit badly — under most agreements an account is not property, and platforms explicitly prohibit passing logins and passwords to anybody, heirs included. In the United States, RUFADAA gives executors a defined route in most states, with an in-service setting outranking a will; in the United Kingdom there is no such statute and executors depend on platform policies. Russian notaries adapt familiar instruments: a closed will, a deposit, a bank safe deposit box. It works, but it is a palliative.
Are you promising you will preserve me? Will this be "me"? No. We preserve memory and records — conversations, decisions, intonation, what you told us — and we call it exactly that. It is not you and not a continuation of your consciousness; promising immortality as a physical fact would be a lie. What genuinely remains: an interlocutor who remembers your words and can answer a grandchild's question in your words.
Where do I start if I am not ready to buy anything today? Start with the free things, and without us. Switch on Google's Inactive Account Manager and Apple's Legacy Contact — that is about twenty minutes. Export your correspondence from your messengers and put a copy where it will be found without you; deal with photos and video separately, as they do not travel into a permanent record by themselves. Write down on paper where everything is and who gets what, without passwords in the clear. And if you decide you want the copy to outlive a hard drive — then talk about tiers.
Conclusion
Everything described in this article runs into one inconvenient property of time: the decision about a digital estate is made once, and only the person who will not be around to be asked can make it. Nobody can do it for you — not the family, not the platform, not a court. An hour spent now costs exactly what it would cost in ten years, but in ten years it may not arrive. That is not a reason to rush. It is a reason not to postpone indefinitely.
Where to start
Step 1. Today, twenty minutes — free. Switch on inheritance where it already exists: Google Inactive Account Manager (myaccount.google.com/inactive), Apple's Legacy Contact, a legacy contact on Facebook. Tell the people close to you where your devices are, and write down what should happen to them. The legal part — the will, access to accounts and devices — discuss with a notary or a solicitor: this article does not replace a consultation.
Step 2. This week — start talking. The Spark tier, $15 per month: conversations with AIfa are preserved, encrypted and sent to permanent storage. Take your first topics from the list in chapter six — start with photographs and with your voice.
Step 3. When you realise the archive is not only for you. Family Archive, $100 per month — family access and personal knowledge bases: the family's story can be told together rather than alone. Digital DNA, $1,000 one-off per device and $200 per month thereafter — the full perimeter: a separate protected environment and the most detailed capture of memory available.
Start with the first step. It is free, and it is already more than most people have.