Privacy in the writing room
The notice is yours, not ours.
The private parts of Obituate live in your browser. We can count that the tool helped someone reach a milestone without receiving the words, people, dates, voice, or story that got them there.
Effective August 28, 2026
What stays on your device
The obituary draft, fact checks, family roster, review marks, newspaper notes, photograph, care-reminder choice, display preferences, and any Kit key are stored in your browser’s local storage. They are not uploaded to an Obituate account because there is no Obituate account.
Local storage is necessary to save your place and return to the work. It remains until you remove the draft, clear this site’s storage, or lose access to the browser or device. Obituate cannot recover a browser-only draft. Save a file or archive somewhere you control if you need a durable copy.
A photograph is resized and re-encoded in the browser before it is kept with the draft. That process drops the phone’s embedded location metadata.
When you choose to share
Obituate makes family review links and files on your device. A review link carries the proof inside the part of the web address after the # symbol. That fragment is not sent to the Obituate web server, but the person you send it to can read it, and the messaging or email service you use may process the link.
When you download, print, copy, email, or submit an obituary, you direct the material to your device, family member, email provider, newspaper, funeral home, or another destination. Their privacy practices apply to the copy you choose to send. Obituate does not silently submit the notice to a publication.
Speaking instead of typing
Speech recognition belongs to your browser or device. Obituate asks that service for words; Obituate itself does not receive, record, save, or send voice or audio. Finished words appear in the field and are saved locally like words you typed.
Your browser, operating system, or keyboard provider may process speech under its own privacy terms. You can always type, use the keyboard’s microphone, or leave a section for later.
The little we count
Obituate can make a small, same-origin request when a notice reaches a useful milestone: starting; reaching 100 words; beginning fact checks; making a family round; initiating the first export; returning review marks; opening the Kit; or initiating another export action. Its JSON body can contain only fixed categories: the event, live or family-example mode, broad device and source categories, and—for an export—such things as copy, download, print, or email-client handoff. The endpoint rejects query strings, unknown fields, free text, customer identifiers, and obituary content. The request does not use or set an analytics cookie.
The web host necessarily receives ordinary request information long enough to deliver and secure the request, including a network address, time, and basic browser information. The analytics record never keeps the network address or user-agent string, and stores time only to the UTC hour. It may keep country or first-level region derived at the edge, but never a precise location, city, postal code, GPS coordinates, or movement history. In the private operating Sheet, a country or region is named only after at least 10 live starts or first exports; smaller cells are combined before Google receives them. Rare daily source, campaign, device, and export categories are combined there too.
Never in these counts: obituary words, names, dates, relationships, cause of death, family contact details, photographs, voice, audio, transcripts, email recipients, publication names, or file contents.
Counting is optional. It does not run from an offline archive, stops when Global Privacy Control or Do Not Track is present, and can be switched off in Obituate. The choice is remembered on that browser.
An export count means that an export action was initiated. It does not prove a file was saved, an email was sent, a newspaper received or accepted anything, or an obituary was published.
Our retention limit is 30 days for validated raw event records and 25 months for daily aggregate totals. Unsuppressed coarse geography is kept only for the rolling 30-day privacy calculation. The private operating dashboard receives aggregate totals with rare daily categories and geography already combined; raw event records and family content are not sent there.
Payments & messages
Writing, checking, and newspaper-ready text are free. If you buy the optional Kit, Stripe handles the payment page and receives the name, email, and payment information you provide there. Obituate sends Stripe a product and return path, not the obituary. After payment, the browser removes Stripe’s return value from the visible address and sends it to our same-origin key function in a small no-query POST. The server asks Stripe whether the session was paid and returns a signed Kit key bearing the purchaser name or email. The browser stores that key locally.
Payment and accounting records follow the retention required for transactions and legal obligations; they are not joined to writing-room analytics. Stripe never receives the draft from Obituate.
“Report a bug,” waiver, professional-practice, and newspaper-email controls open your own email app. The prepared bug message can include browser type and window size so we can diagnose the problem. Review the message before sending and remove anything you do not want to share.
No ad trackers in the room
Microsoft Clarity, Google Analytics, advertising pixels, session-replay tools, and social-media trackers do not load in the Obituate writing and review experience. We do not sell information, build advertising profiles, or use writing-room activity for behavioral advertising.
The separate Bainbridge Death Support marketing site may use Google Analytics and Microsoft Clarity only after a visitor opts in there. That choice does not place those tools inside Obituate.
Your choices & requests
You can turn content-blind counting off in Obituate, send a supported Global Privacy Control signal, clear local storage, export a copy, and delete local files when you choose. Clearing local storage is permanent; save anything you need first.
You may also ask what server-side information Bainbridge Death Support holds about you, request access or correction, ask for deletion where we can, withdraw optional consent, or appeal a privacy decision. Contact miranda@bainbridgedeathsupport.com or (206) 617‑1199. Please do not include the obituary or medical details merely to make a request. We aim to respond within 45 days.
A browser-only draft is not on our server, so we cannot open, identify, retrieve, or remotely delete it. We can help you find the controls on your device.
A note for Washington
An obituary or a message someone chooses to send us can touch health, cause of death, grief, end-of-life care, or another sensitive part of life. Whether a particular record is legally classified as consumer health data depends on the person, the information, and the context. We do not ask you to make that legal determination before seeking help.
If you believe we hold sensitive or consumer health information about you, contact us and say whether you want access, deletion, correction, or withdrawal of consent. We will use only what is needed to verify and answer the request, and we will not discriminate against you for asking.
Security & changes
Obituate reduces risk first by not receiving the draft. Server-side access is limited, connections are encrypted, and content-blind records are kept on a short schedule. No system or device is perfectly secure; protect shared links and exported files as carefully as the obituary itself.
If this notice changes materially, we will update the effective date and explain any new use before asking for a new choice. Questions are welcome at miranda@bainbridgedeathsupport.com.