AmberKey is in invite-only beta. Join the newsletter to request an invite and hear the moment it opens to everyone. Sign up ↓

Blog

No one inherits a password

We spent a few weeks reading deceased-user policies. Every major provider: Google, Apple, Microsoft, Meta, Yahoo, Dropbox, the banks, the brokerages, the crypto exchanges, the carriers, the password managers. The pattern is so consistent it’s almost a law of nature.

When you die, four things can happen to an account:

  1. It gets memorialized. Facebook, Instagram, LinkedIn. The public shell stays; the private inside is sealed.
  2. It gets closed. Almost anyone with a death certificate can accomplish this. Closure is easy everywhere.
  3. The property inside gets transferred. Banks, brokerages, PayPal, Coinbase. They move money and assets to a new legal owner through an estate process.
  4. Content gets disclosed after a court fight. Yahoo and Dropbox will consider handing over files, with a court order, maybe.

Notice what’s not on the list. Nobody hands your family the password. Not Google, not Apple, not X, not your bank. Providers will transfer what you own to your heirs. They will not transfer who you were. Your login identity dies with you, by policy and largely by law.

Why the law works this way

Two statutes shape everything in the US. The Stored Communications Act prohibits providers from voluntarily disclosing the content of communications unless an exception applies, and the relevant exception is lawful consent. Dead people can’t consent, so the consent has to be captured while you’re alive.

RUFADAA, adopted in some form by most states, extends fiduciary authority to digital property but keeps communications behind a higher wall. And it establishes a priority order worth internalizing: a direction you set in a provider’s online tool beats your will. If your will says “give my spouse everything” and your Google Inactive Account Manager says otherwise, Google wins.

The upshot: the legal system rewards specific, affirmative, in-life configuration and punishes improvisation after death. A grieving family with a death certificate and the best intentions gets closure and memorialization. A family whose person configured Apple Legacy Contact gets photos.

The ranking, if you configure nothing

The strongest post-death outcomes all come from features you set up in advance: Apple Legacy Contact, Google Inactive Account Manager, OneDrive Digital Legacy, Facebook Legacy Contact, Bitwarden emergency access, POD and TOD beneficiary designations. Every one of these exists because the provider wants a documented, scoped, consented channel instead of a support ticket from a stranger holding a death certificate.

If you configure nothing, your family’s realistic ceiling is: accounts closed, subscriptions cancelled, money eventually transferred through probate, and everything else (email, messages, files, photos) locked behind a court-order threshold most estates will never clear.

And there’s one category where even a court can’t help. A probate order can establish who legally owns your bitcoin. It cannot reconstruct a lost seed phrase. Self-custody means the recovery problem is yours alone, in life and in death.

The part that’s getting worse

Here’s what changed our thinking while doing this research. A generation ago, a person’s intellectual residue was paper in a filing cabinet: physical, discoverable, inheritable by default. Now the most complete record of how you thought lives on servers, and it sits in exactly the category the law protects hardest.

Your Obsidian vault. Your notes, your drafts, your half-finished projects. Your AI conversations, which for many people are becoming the fastest-growing corpus of their actual thinking: months of design reasoning, research, decisions, all of it conversational content with the same legal protection as private email.

And the succession profile of AI services is the worst of any provider category we reviewed. OpenAI, as of mid-2026, has no legacy program at all. No legacy contact, no digital beneficiary, no executor workflow. Deletion and legal process, that’s the menu. Their Trusted Contact feature is a safety mechanism, not an estate one. Your heirs can own the copyright in everything you wrote there (unpublished work is unambiguously estate property, protected for seventy years after you’re gone) and still have no lawful path to read a word of it.

Ownership and access have come apart. That gap widens every year more of your work happens inside someone else’s service.

What actually works

Three cases, three different answers.

Local-first data (Obsidian, local repos, files on your machine) is already solvable. The barrier is a device passcode or disk encryption key, plus discovery: someone has to know the vault exists, where it is, and what matters in it. That’s a secret plus a map. No provider fight involved.

Server-side data (AI chats, Notion, hosted anything) has exactly one reliable answer: export it while you’re alive, on a schedule, and encrypt the export to the person who should eventually have it. An export converts provider-controlled content into bearer data. It moves your work out of the legally hardest category and into the easiest one: a file, held by you, that your plan can hand to the right person.

The archive itself needs a map to be worth anything. This is the honest caveat. Forty thousand notes or three thousand AI conversations is not an asset, it’s a haystack. What makes it valuable to anyone else is curation: what exists, where, what’s finished versus fragmentary, and what you actually want done with it. Publish, sell, preserve, ignore. No exporter produces that. Only you can.

Where AmberKey sits in this

We built AmberKey around the conclusion this research forces: a defensible digital-estate product cannot be a credential-transfer service, because the entire legal and provider landscape is arranged against that outcome. Impersonating the dead is not a plan.

So AmberKey does the two things that actually survive contact with reality. The executor packet is the map: account inventory, per-provider playbooks that point your people at the official process for each service, disposition wishes, and the consent language that makes a fiduciary’s job legally possible. The vault holds the bearer secrets: the seed phrases, the master passwords, the device passcodes, the encrypted exports. Client-side encrypted, split across people you chose, recoverable with an offline tool that works even if we don’t exist anymore.

One layer proves authority and points the way. The other carries the secrets that no provider will ever hand over. Neither requires suing four companies or hoping a support agent bends policy for a death certificate.

Configure the provider tools. Export what lives on servers. Write the map. The law rewards the people who did this while they could, and it is remarkably indifferent to everyone else.

This is general information, not legal advice. Talk to a probate attorney in your jurisdiction about the consent language in your estate documents.


AmberKey is a two-layer plan for your digital estate: a plain-language packet for your executor and an encrypted vault only your chosen circle can open, a design where our servers can never read your vault. See how it works →