Privacy policy
How WillWise handles your information
This policy explains what information WillWise uses, why it is needed, and the choices available to you.
Last updated: 1 August 2026
Who this policy applies to
This policy applies when you visit WillWise, create an account, complete a preparation, purchase a professional report, or contact support. WillWise is designed for people preparing to speak with a Scottish solicitor.
Information we collect
Depending on how you use WillWise, information may include:
- your email address, display name, and authentication records;
- answers about you, your family, assets, wishes, and existing arrangements;
- optional provider names and safe references for important digital accounts or assets, but never passwords or security credentials;
- preparation progress, score, resume position, and generated report snapshots;
- for the optional public readiness check, only allowlisted high-level choices, the deterministic score, category percentages and completion time;
- Stripe purchase identifiers, payment status, amount, currency, and entitlement status;
- if subscriptions are introduced, the plan, billing interval, subscription status, service period and cancellation state needed to provide access, but not card details;
- ratings, feedback comments, optional contact details, and limited technical context such as the page, browser category, device category and application version; and
- optional review-reminder preferences, recorded life-event type and date, reminder delivery status, and dashboard notification status; and
- optional encrypted Family Vault information, including professional and emergency contacts, policies, pensions, plans, safe-deposit references and medical wishes; and
- optional supporting documents, their filenames, titles, categories, file types and sizes when you choose to use secure document storage; and
- limited solicitor-directory activity consisting of a listing reference, event type, time and optional signed-in account reference; and
- limited technical, page-view, and error information needed to operate, improve, and secure the service.
Please avoid adding information that is not needed for your preparation. Never enter passwords, PINs, account numbers, recovery phrases, private keys or security answers in WillWise. Do not send preparation answers or sensitive personal details in support emails.
Public readiness check
The public readiness check does not ask for names, addresses, financial values, account details or full preparation answers. An anonymous result may be retained for up to 90 days to operate the journey and understand aggregate completion. If you subsequently create or use an account, that result may be linked to your account so it is not duplicated. Behavioural analytics remain subject to your analytics-consent choice.
How information is used
Information is used to provide the questionnaire, save and restore progress, calculate preparation readiness, produce rule-based insights and risk flags, create reports, confirm purchases, prevent misuse, and respond to support requests. If you enable preparation review reminders, the selected interval and any life event you record are used to create dashboard notifications and optional email reminders. The preparation score measures completion only; it is not a legal assessment.
Signed-out and signed-in preparations
While signed out, preparation progress is stored in your browser using local storage. It is not uploaded automatically. After signing in, you may explicitly choose whether to save existing local progress to your account. Signed-in preparations are stored in Supabase and protected by user-specific database access rules.
Authentication
Supabase provides account creation, email confirmation, login, session management, and password recovery. Supabase processes the account and authentication information needed for those functions. Authentication emails are delivered using configured email infrastructure. WillWise does not receive or store your password in its application database.
AI and automated processing
If the optional Preparation Assistant is enabled and you request a topic, WillWise sends OpenAI only a small set of yes/no indicators derived from your saved preparation. It does not send names, addresses, financial amounts, free-text answers, beneficiaries, reports, documents or authentication details. The model can only select from approved WillWise guidance; it cannot write the legal content shown to you.
WillWise records only operational details such as topic, outcome, latency and token counts. It does not store the AI prompt, model output or answers in its AI usage log. The assistant is optional, is not a chatbot, and does not provide legal advice. Smart Insights, readiness results, risk flags and reports remain deterministic. WillWise does not make automated legal decisions about you.
Family Vault encryption
If you use Family Vault, its content fields are encrypted by WillWise using authenticated AES-256-GCM encryption before being stored in Supabase. The encryption keys remain in server-only configuration and are not sent to your browser or stored in the database. Account and record identifiers, encryption-key version, encrypted payload, nonce and creation/update times remain available to operate the feature and enforce access controls.
Decrypted information is returned only after authentication and owner checks. If you include vault information in a report, that information becomes part of the displayed or downloaded report and should be handled carefully. Do not store passwords, access codes, private keys, recovery phrases or safe combinations in Family Vault.
Secure document storage
If you upload supporting documents, they are stored in a private Supabase Storage bucket. Access requires your signed-in account and uses short-lived links after an ownership check. File types, extensions and signatures are checked and file size is limited. The service does not currently include automated virus scanning, so upload only files you trust and retain your original documents and appropriate backups. Founders can view aggregate storage totals, but not document contents, filenames, titles or categories.
Secure solicitor sharing
If you create a solicitor sharing link, WillWise stores a one-way hash of the random link token, its expiry and revocation state, an optional one-way password hash and a limited audit history of views and downloads. The recipient can access only the professional report selected for that link—not your account, other preparations, Family Vault or uploaded documents. Raw link tokens and passwords cannot be recovered from the database. Share links carefully and revoke them when they are no longer needed.
Solicitor directory and referrals
If you search by postcode, the postcode is sent to Ideal Postcodes to obtain approximate coordinates. Those coordinates and your chosen distance are then sent to Google Places to find nearby firms. If you explicitly choose current location, your browser supplies coordinates directly to that search. WillWise does not save these search locations or add them to analytics, page URLs or referral records.
WillWise records limited aggregate activity such as listing views, visits to a firm website and opening the secure-sharing area. It does not include your preparation answers, report, search filters, recipient details, IP address or browser details. A directory listing is information only and does not mean that WillWise recommends or guarantees a firm.
Signed-in users may save a firm. For Google results WillWise stores only the Google Place ID and refreshes the displayed details from Google, rather than retaining a copy of the listing. You can remove a saved firm at any time. Google's own terms and privacy information also apply when its place information is requested.
Payments
Stripe processes WillWise Plus subscriptions and payments for the optional Professional Preparation Report. Payment card details are entered on Stripe-hosted Checkout and are not stored by WillWise. WillWise stores only the identifiers and payment status needed to associate a Stripe customer with your account, verify subscription or purchase status, provide the relevant access, support re-downloads, and respond to cancellations or confirmed refunds.
WillWise does not store full Stripe Checkout, Customer or Subscription payloads. Temporary support or testing access is recorded with a reason, optional expiry and audit history.
Cookies and local storage
Supabase authentication uses cookies needed to keep signed-in sessions secure. WillWise uses browser local storage to preserve signed-out preparation progress and local-to-account migration choices. Stripe may use its own necessary cookies when you visit Stripe-hosted Checkout. After you accept analytics, WillWise and its analytics providers, Vercel Analytics, Google Tag Manager and Microsoft Clarity, may record privacy-conscious visits and product events. Page-view events are limited to an allowlist of public pages. Product events contain only an event name, while Clarity page content is explicitly masked. WillWise does not add URL query parameters, preparation answers, names, email addresses or advertising identifiers to analytics event payloads, and it does not set its own persistent analytics cookie. Your analytics preference, policy version and decision time are stored in local storage. You can change or withdraw that choice using “Cookie settings” in the footer.
Sharing and service providers
WillWise relies on Vercel for application hosting and consented analytics, Google Tag Manager for consented event delivery, Microsoft Clarity for fully masked consented experience analytics, Supabase for authentication and database services, Ideal Postcodes for optional postcode and search-location lookup, Google Places for optional nearby solicitor information, Stripe for payments, Resend for authentication and optional review-reminder email, and Cloudflare for domain services. If you choose postcode lookup, the postcode you enter is sent securely to Ideal Postcodes to return matching UK addresses; you can always enter the address manually instead. Information is shared only where needed for those services to perform their role or where disclosure is required by law. WillWise does not sell preparation answers.
Retention and security
Account preparations and purchased report snapshots are retained so they remain available through your dashboard. Payment history may be retained for financial, security, and support purposes. Retention periods are reviewed according to operational, legal and user-account requirements. WillWise uses access controls, encrypted HTTPS connections, and database row-level security, but no online service can guarantee absolute security.
Locally saved information is accessible to people who can use your browser profile. Store downloaded or printed reports carefully, particularly on a shared device.
Your choices and rights
Depending on applicable data-protection law, you may have rights to ask for access, correction, deletion, restriction, portability, or to object to certain processing. You may also be entitled to raise a concern with the UK Information Commissioner’s Office. Identity verification may be required before acting on a request.
You can clear signed-out answers using WillWise or your browser settings. Signed-in users can permanently delete their WillWise account, preparations, reports, entitlements and user-linked analytics from Account Settings. WillWise does not delete Stripe’s separate transaction record; Stripe may retain it under its own obligations and retention controls. Contact support@willwiseprep.co.uk if deletion fails or you need help with an export.
Making a privacy request
To request access, correction, deletion, restriction, objection or portability, email support@willwiseprep.co.uk from your account email address where possible. Do not email passwords, preparation answers, reports or unnecessary identity documents. We may ask for proportionate verification before acting on a request.
Changes and questions
This policy may change as the service develops. Material updates will be reflected on this page. For questions, use the contact page.
