What happens to your online accounts when you die?
Most people picture the same thing: after they’re gone, a spouse or a grown kid will sit down at the computer, log in, and quietly sort everything out. It’s a comforting picture. It’s also usually wrong, and the gap between the picture and reality is where digital estates fall apart.
Nobody hands your family your passwords. Providers won’t. Devices lock themselves. Accounts get frozen and, given enough time, deleted. And the person trying to help is often working blind, because they never knew what accounts existed in the first place.
So let’s walk through what actually happens, and the few decisions that separate an afternoon of tidying from a two-year ordeal.
Without a plan, the default is loss
When you die without preparing, each account follows its provider’s rules, and almost none of those rules involve giving your relatives a way in.
Start with email, because email is the master key. It’s the reset hub for nearly everything else you own online. If your family can’t get into your inbox, they can’t reset the bank, the utilities, the photo storage, or anything else that mails a link to that address. And providers don’t just open inboxes on request. Most want a court order, and some quietly delete accounts that sit unused.
That inactivity clock catches people off guard. Microsoft, for instance, freezes Outlook and OneDrive after a year without a sign-in and deletes the contents soon after; the whole account expires at two years. Free cloud storage gets purged on similar timers. An account nobody thinks to check can be gone before anyone goes looking.
Money has its own trap. Logging into a dead person’s bank account, even a spouse doing it with the best intentions, can count as unauthorized access, and money moved outside the proper estate process sometimes has to be clawed back. Banks run estate departments precisely so families don’t have to improvise this.
Then there’s two-factor authentication. Even with the right password in hand, a login that texts a code to a phone that’s been shut off goes nowhere. That’s why the phone number turns out to be one of the quietly important things in an estate: it’s where everyone else’s reset codes land.
Put it together and the picture is clear. Skip the preparation, and your family inherits a scavenger hunt played behind locked doors.
The tools that exist, and the ones that don’t
A few companies have built honest answers to “what happens when I die,” and they’re worth using because they hand data to your family without passwords or lawyers.
Google’s Inactive Account Manager is the best of them: a real dead man’s switch. You pick how long Google should wait after you stop signing in, and when the timer runs out it notifies the people you named and lets them download what you chose. It takes about ten minutes to set up. Apple has Legacy Contact, where you designate people ahead of time and Apple issues them an access key. Bitwarden, 1Password, and a few other password managers offer emergency access on a waiting period.
The mistake is assuming everyone offers this. Plenty of the biggest names don’t. Microsoft, Dropbox, and most banks have no legacy feature at all. There, access means a court order, and even that isn’t guaranteed. For those accounts, the only plan that actually works is to leave the credentials somewhere your people can safely reach.
The moves that decide the outcome
You don’t have to solve every account you own. You have to make a few decisions.
The first is to write down what exists. Not the passwords, a map. Which banks, which email is the hub, what’s joint, which autopays will bounce when the card stops working. Most of the harm after a death comes from things nobody knew were there, not from a forgotten password.
The second is to switch on the legacy tools you already have. Google, Apple, your password manager. Ten minutes each, and the companies do the handoff for you.
For everything without a tool, you escrow the credentials yourself. This is the part almost every homemade plan gets dangerously wrong. “It’s all written in a notebook in my desk” protects nobody, because that notebook is readable today, by anyone in the house, while you’re very much alive. The trick is a place your chosen people can reach after you’re gone, and not a moment before. That’s a genuinely hard thing to build on your own, and it’s worth being honest about.
The last two are easy to say and easy to skip. Keep the phone number alive and make sure someone can unlock your devices, because an unlocked phone is most of your second factors. And keep the whole thing current: a plan made once and never touched rots, as passwords change and accounts close. The plans that work get a quick look once or twice a year.
Where AmberKey fits
The hardest of those moves is the third one, the “reachable later but not now” problem, and it’s the reason this product exists. A notebook is readable today. A file on your laptop dies with the laptop. A copy left with a lawyer is a single point of failure and a standing temptation.
AmberKey splits your plan in two. One layer is a plain-language packet your executor can act on. The other is an encrypted vault whose key is split across the people you choose, so no one person can open it alone, and it only releases after you’ve stopped checking in and a waiting period has passed, during which a single tap from you calls the whole thing off. Our servers hold nothing but ciphertext. By design, we can’t read your vault, and recovery still works with open formats and an offline tool even if the company disappears.
You can build the entire map and print your kit for free. But whether you ever use AmberKey or not, the moves above are the plan. Make them now, while it’s an afternoon of your time instead of your family’s two-year problem.
This is general information, not legal advice. For wills and estate law, use a licensed attorney. AmberKey handles the “can they actually find and reach it” problem that sits next to the will, not the will itself.
AmberKey is a two-layer plan for your digital estate: a plain-language packet for your executor and an encrypted vault only your chosen circle can open, a design where our servers can never read your vault. See how it works →