Privacy

What we hold, and what we refuse to hold.

This describes actual behavior of the software as built, not aspirations. Where a practice is not yet in place, it says so.

What we store

Your account identity comes from Manus OAuth: an opaque identifier, your name, and your email address. We never see or store a password.

For each policy you record: the carrier name, the policy number, the product type, the face value, your chosen re-attestation cadence, and any note you write about your intent. Policy numbers are masked in every interface, showing only the last four characters.

For each person in your family graph: their name, relationship to you, date of birth if you provide it, contact details if you provide them, prior legal names if you provide them, and whether they have died.

What we deliberately do not store

We do not ask for or store Social Security numbers, government identification numbers, medical records, or bank account details. The monitoring rules do not need them, and holding them would create risk for you with no corresponding benefit.

We do not store card numbers. Contributions are processed entirely by Stripe; we retain only a Stripe session identifier so a payment can be reconciled.

The audit vault is permanent by design

Audit entries are append-only and hash-chained. There is no function in this application that edits or deletes one. This is the point of the feature: a record that could be quietly revised is not evidence. It also means audit history persists even after you delete the policy or person it refers to.

Consent and monitoring

Every monitoring source is off until you turn it on, and each grant or withdrawal of consent is itself written to your audit vault. No external source is queried for a source you have not permitted.

The AI assistant

Messages you type into the assistant are sent to a language model to generate a reply. Do not paste account numbers or identification numbers into it. The assistant has no access to your policies, your family graph, or your vault — it answers questions about the product only.

If an estate planner holds your record

A planner who adds you to their roster can see and edit your policies, your family graph, and your findings. Everything they change is written to your audit vault with their name against it, so you can see who did what and when.

What the vault does not record is every time they simply look. We log changes, not page views. Logging reads would add hundreds of entries to your record and bury the events that would actually matter in a dispute. If you would rather have read-level logging, say so — it is a switch we can add, not a rewrite.

Honest limitations

This is a small, independently operated product. It does not currently carry SOC 2 attestation, HIPAA coverage, or a formal third-party penetration test. If your situation requires those assurances, you should know that before you begin rather than after.

Beneficiary ContinuityGuard

Beneficiary designations are the most consequential paperwork most people never revisit. We keep watch, and we keep the record.

Beneficiary Continuity Guard is a records and monitoring service. It is not a law firm, insurance producer, or financial adviser, and nothing here is legal, tax, or insurance advice. Only the carrier that issued a policy can change a beneficiary designation, on that carrier's own form. Beneficiary law varies by state, and employer-sponsored plans may be governed by federal law instead. Consult a qualified estate planning attorney about your own situation.

© 2026 Beneficiary Continuity Guard. All rights reserved.

Built in Des Moines, Iowa.