12 answers, 5 groups, one screen
Security & privacy
4Constellation uses multiple layers of protection. Your Document vault contents are encrypted with AES-256-GCM using unique per-item data keys — each item gets its own encryption key, and those keys are themselves wrapped with envelope encryption, so a compromise of one item cannot expose any other. Nothing is stored in plaintext — not in the database, not in the logs, not in the backups. All data in transit is protected by TLS 1.3. Authentication is handled by Clerk, an enterprise-grade identity provider — Constellation never stores your password. Every API route requires authentication, and service accounts follow the principle of least privilege. Row-level security (RLS) policies in our database ensure users can only access their own data. Every significant action — logins, inventory changes, vault access, access request approvals — is recorded in an immutable audit log you can export at any time. We do not sell, analyze for marketing, or share your personal information with third parties. For email discovery, we read only metadata (sender domains, subject patterns) — never message content. Your data is yours: you can export it at any time, and if you cancel, it is permanently deleted after a 30-day retention window.
- Vault encryption
- AES-256-GCM with a unique data key per item, each wrapped by envelope encryption — so compromising one item cannot expose any other.
- At rest
- Objects are written to storage already encrypted. What sits on disk is ciphertext and nothing else.
- Administrative access
- Reaching a decrypted document requires membership of a named allow-list, and every administrative action is recorded in a separate append-only log.
- In transit
- All data is protected by TLS 1.3.
- Authentication
- Handled by Clerk, an enterprise-grade identity provider. Constellation never stores your password.
- Least privilege
- Every API route requires authentication, and service accounts hold only the permissions they need.
- Data isolation
- Every API request is authorized against the account that made it, so a request for another user’s record returns nothing. An automated cross-tenant suite re-proves this on every deploy.
- Audit log
- Logins, inventory changes, vault access, and access-request approvals are recorded immutably — and you can export the log at any time.
- Privacy
- We do not sell, analyze for marketing, or share your personal information. Email discovery reads sender domains and subject patterns only — never message content.
- Your data is yours
- Export it at any time. If you cancel, it is permanently deleted after a 30-day retention window.
No. Constellation stores account metadata, recovery methods, and executor notes — not your passwords. If you use a password manager, Constellation helps you organize information about it (which manager you use, how to access it) so your executor knows where to look.
The Vault holds your most sensitive documents and notes — wills, powers of attorney, recovery codes, safe deposit instructions. Every item is encrypted with AES-256-GCM under its own unique key, and each of those keys is wrapped by a master key that lives inside an AWS KMS hardware security module and never leaves it. Break into one item and you have exactly one item, not a library. We will not tell you it is impossible for anyone here to reach your documents. We will tell you how narrow the path is: administrative access is a named allow-list held in AWS Secrets Manager — not a role, not a checkbox — and every administrative action lands in a separate append-only log with no delete path. The full picture, including what we have not built yet, is at /security.
Yes. Constellation supports social login with Google, Microsoft, and Apple accounts, in addition to traditional email and password. Your authentication is handled by Clerk, an enterprise-grade identity provider — Constellation never stores your password.
Getting started
3Digital life planning is the process of organizing your online accounts, subscriptions, financial services, and digital assets so your family can manage them if something happens to you. Constellation makes this simple with a visual dashboard, automated discovery, and guided action steps.
Constellation connects to your email provider (Gmail, Outlook, or Apple Mail) and scans for patterns that indicate you have accounts with services — receipt emails, security alerts, password reset emails. We also support Plaid for financial account discovery. We only read metadata — never message content.
Yes — seven days, free. A card is required to start, and you are not charged until day seven. Cancel any time before then and you pay nothing. If you want to see the value before signing up at all, run the 30-second simulation at /simulation — nine questions, no account needed.
Family's access
3No — access is controlled by your Activation. You define the conditions under which your Trusted Circle gains access, including grace periods where you can override or cancel. You stay in control at all times.
Your Activation triggers your designated Executor and Trusted Contacts. They receive access to the information you've organized — your inventory, documents, and guidance notes — based on the rules you've configured. Constellation makes sure they know where to start.
Linked constellations let you connect your digital life plan with family members or your financial advisor. You can see each other's readiness status and coordinate emergency plans without exposing private account details. It's like a shared family dashboard for digital preparedness.
Your data
1You can export your complete data at any time from your Account settings. If you cancel your subscription, your data is retained for 30 days before being permanently deleted per our data retention policy.
Everything else
1Yes. You can assign an Executor (manages the estate), Trusted Contacts (check in and verify), and Advisors (provide guidance). Each role has defined responsibilities and access levels.
