Using our Platform.
View the details of some of our features and our platform policies.
Effective date: 10 September 2026 | Version 2.2 | Forms part of the Terms of Service
- The Inactivity Safeguard is a welfare check first, and a handover second.
- Nothing is released until the Lyff Release process is complete and a 48-hour hold has passed.
- Your Guardian and Custodian only ever receive the items you chose for them.
- If you log in or reply at any point, everything stops and resets.
- Purpose and scope
- Check-in settings
- Contact sequence after a missed check-in
- Guardian welfare check
- Custodian advisory notification
- The Lyff Release process
- Future Messages delivery
- Account lifecycle
- Subscriber protections and controls
- Communications tone requirements
- Data retention and re-identification safeguards
- Liability and indemnity
- General
1.1 The Inactivity Safeguard is Lyff’s mechanism for ensuring that when a subscriber is no longer able to manage their vault, through death, incapacity, or any other reason, the people they have designated receive what was prepared for them, in a careful, verified, and humane way.
1.2 This policy covers:
The Inactivity Safeguard check-in settings and timing
The full contact sequence after a missed check-in
Guardian welfare check and Custodian advisory notification procedures
The Lyff Release process, the single verification standard that applies to both Guardian and Custodian access
Future Messages delivery timing and conditions
Account lifecycle, deletion policy, and extension requests
Subscriber protections and controls
Communications tone requirements
Liability, indemnity, and re-identification safeguards
1.3 Core principle. No item is released, and no Future Message is delivered, until the Lyff Release process has been completed and a mandatory waiting period has elapsed. The Safeguard is a welfare system first and a handover mechanism second. Lyff exercises no independent judgement over whether a release is appropriate; that decision was made by the subscriber in advance, when they set each item’s Sharing Setting.
2.1 Default interval. The default check-in interval is 6 months. Subscribers may change this in Settings to every 3 months, every 6 months (default), or every 12 months.
2.2 What a check-in looks like. On the check-in date, Lyff sends a warm, non-alarming email to the subscriber’s registered address. Tapping the confirmation link resets the timer. No further action is needed.
3.1 If the subscriber does not respond to the check-in email, Lyff initiates the following sequence. No access is granted and no Guardian is contacted until the full sequence is exhausted.
| Timeline | Action |
|---|---|
| Day 0 | Check-in email sent. No response received. |
| Day 7 | Second email and SMS to registered mobile number. If no response within 48 hours, Lyff will attempt one phone call to the registered mobile number during business hours (9 am to 5 pm AEST, Monday to Friday). |
| Day 14 | Third and final email and SMS. If no response within 48 hours, Lyff will attempt a second phone call to the registered mobile number. |
| Day 28 | Guardian welfare check initiated (clause 4). No access granted at this point. |
| Day 42 | If the Guardian cannot confirm the subscriber is okay: Custodian advisory notification (clause 5). |
| Day 56 | If no confirmation from any party: the Lyff Release process opens (clause 6). |
3.2 Retry rules. Each phone call attempt is made on a separate business day. If a call is unanswered, Lyff will leave a brief, non-alarming voicemail using the communications tone requirements in clause 10. No more than two phone call attempts are made per contact stage. Lyff records the date, time, and outcome of each contact attempt in the subscriber’s activity log.
3.3 Contact currency. Lyff will use the most recently updated contact details held on the subscriber’s account at the time each contact attempt is made. Subscribers are responsible for keeping their registered email address, mobile number, and nominated contacts current in Settings.
3.4 Minimum period before any release. The minimum from first missed check-in to any release is 56 days, assuming all contacts are non-responsive. The Lyff Release process adds a further mandatory 48-hour hold after documents are received. The realistic minimum is therefore approximately 9 weeks.
3.5 At any point in this sequence, if the subscriber logs in or confirms a check-in, the entire sequence resets immediately.
4.1 Triggered: Day 28 after a missed check-in, if the subscriber has not responded to any of the three contact attempts (including any phone call attempts under clause 3).
| Guardian response | Lyff action |
|---|---|
| Confirms subscriber is fine | Timer resets. Subscriber notified their Guardian confirmed contact. |
| Confirms subscriber has passed or is incapacitated | Move to clause 6, the Lyff Release process. |
| Does not respond within 14 days | Move to clause 5, Custodian notification. |
| No Guardian exists | Contact the Emergency Contact if nominated. If none, move directly to clause 6 with a 30-day extended waiting period. |
5.1 Triggered: Day 42, 14 days after the Guardian welfare check with no resolution. Applies to subscribers on the Complete or Family plan with a Custodian nominated.
| Custodian response | Lyff action |
|---|---|
| Confirms subscriber is fine | Timer resets. |
| Confirms subscriber has passed or is incapacitated | Move to clause 6, the Lyff Release process. |
| Does not respond within 14 days, or no Custodian exists | Move to clause 6 at Day 56. |
6.1 Trigger. Triggered: Day 56 after the original missed check-in, or earlier if a Guardian or Custodian has confirmed the subscriber has passed or is incapacitated.
6.2 One process, whoever initiates it. The Lyff Release process is identical whether it is initiated by a Guardian, a Custodian, or (in a no-Guardian scenario) an Emergency Contact. It does not require a Grant of Probate or Letters of Administration. The same standard of proof applies regardless of who is asking or what they are asking for.
6.3 Documents required before any release.
| Requirement | Who provides it | How verified |
|---|---|---|
| Proof of death (death certificate) or proof of incapacity | Guardian, Custodian or Emergency Contact | Uploaded via secure Lyff upload link; verified by Lyff staff against subscriber records |
| Proof of the requesting party’s identity | Guardian, Custodian or Emergency Contact | Photo ID, driver’s licence or passport, uploaded via the same secure link |
| Signed declaration confirming the requesting party is acting in good faith and is the person nominated by the subscriber | Guardian, Custodian | Signed statutory declaration; witnessed by a JP or police officer |
| Lyff staff internal verification | Lyff internal | Correct name, correct nominated relationship, no recent login activity inconsistent with the claim |
6.4 Mandatory 48-hour waiting period. After all documents are received and verified, a mandatory 48-hour waiting period applies before anything releases. This provides a final window for the subscriber to contact Lyff and dispute the claim if they are alive. If Lyff receives any communication from the subscriber at any stage, including during this window, all steps halt immediately and the sequence resets.
6.5 What the Lyff Release process releases, and the symmetric trigger. Whichever party, Guardian or Custodian, completes the Lyff Release process first, that verification unlocks every item classified for Guardian access and every item classified for Custodian access at the same time. The party who did not complete the verification is notified that access has unlocked; nothing releases silently to one side without the other being told.
Every item classified as shared with the Guardian, when verified, becomes accessible to the Guardian.
Every item classified as shared with the Custodian, when verified, becomes accessible to the Custodian.
Items already classified as shared immediately were already visible and are unaffected; this is a formal confirmation the context has changed, not new access.
Future Messages set to “if something happened to me” are queued for delivery. They are not sent immediately; see clause 7.
6.6 No item is released beyond what the subscriber classified for that recipient. A Guardian never receives items classified only for the Custodian, and vice versa.
6.7 Dispute protection. Neither a Guardian nor a Custodian can unilaterally activate the trigger. They can only confirm a status in response to Lyff’s welfare check, or initiate the Lyff Release process with the required documentation. The 48-hour post-verification window exists specifically to protect against fraudulent or mistaken notifications.
7.1 Date-scheduled Future Messages. Future Messages scheduled for a specific date deliver on that date, entirely independent of the Inactivity Safeguard and regardless of vault activity.
7.2 Trigger-based Future Messages. Future Messages set to “deliver if something happened to me” are held in a queue for 14 days after the Lyff Release process completes. After 14 days, messages are delivered: written messages as the message body in a Lyff-branded email; video messages as a secure link accessible for 90 days. Recipients do not need a Lyff account.
7.3 Subscriber notice at Future Message creation. When a subscriber creates a Future Message set to this condition, Lyff must display: “If your Inactivity Safeguard triggers and is verified, your messages set for this condition will be delivered to your loved ones within 14 days of verification.”
7.4 Recipients. Future Messages go to whoever the subscriber designates. Recipients do not need a Lyff account. They receive a notification 24 hours before delivery so the arrival is not completely unexpected.
8.1 Standard account lifecycle after the trigger:
| Timeline | Event |
|---|---|
| Day 0 (trigger fires) | Guardian and Custodian items formally released, per their respective classifications. Future Messages queued. |
| Day 14 | Future Messages delivered to all designated recipients. |
| Month 3 | Lyff notifies the Guardian and any Custodian that the vault remains accessible. |
| Month 9 | 90-day notice: the vault will be permanently closed and all remaining documents deleted in 90 days. |
| Month 11 | 30-day final notice. |
| Month 12 | Unless an approved extension or preservation hold applies, all vault contents permanently and irreversibly deleted. The account record is de-identified in accordance with clause 11. Activity logs retained in de-identified form for 7 years. |
8.2 Extension requests after the trigger. Lyff recognises that families and estates may require additional time to retrieve vault contents, particularly where an estate dispute is ongoing, probate is delayed, or a subscriber’s nominated contacts require more time to act.
A Guardian, Custodian, or the executor of the subscriber’s estate may submit a written extension request to Lyff through Lyff Support or by emailing hello@lyff.com.au before the Month 11 final notice date.
Extension requests must state the reason for the request and the additional time required.
Lyff will consider extension requests reasonably and consistently, and may grant a single extension of up to 6 months beyond the standard 12-month lifecycle. No further extensions will be granted after the first extension period expires.
Extensions are not automatic and are subject to Lyff’s assessment of the circumstances. Lyff will respond to extension requests within 14 days of receipt.
No partial refunds or fee credits are issued in connection with an extension.
Lyff may retain vault contents beyond the stated period where reasonably required by law, a court or regulatory direction, fraud or security investigation, unresolved dispute, or another valid preservation obligation.
8.3 Cancellation before the trigger. If a subscriber cancels a paid plan before the trigger fires, the Standard Cancellation, Retrieval and Deletion Process in clause 16.1 of the Terms of Service applies. In summary: paid access continues until the end of the current paid subscription period; the vault then enters read-only mode for 90 days, with export available; Lyff sends reminders before the scheduled deletion date; the subscriber may request one extension of up to six months before that date; and the vault is permanently deleted when the 90-day period or approved extension ends, unless a preservation hold applies.
8.4 No refunds after trigger. No partial refunds or access extensions are issued as of right after the trigger fires. Lyff’s contractual obligation is fulfilled on verified release. The 12-month account lifecycle (subject to clause 8.2) gives families sufficient time to retrieve what they need.
9.1 What subscribers can do at any time:
Change the check-in interval (3, 6, or 12 months) in Settings.
Reset the check-in timer manually.
Pause the Safeguard with a defined resumption date, for an extended trip.
Change or remove a Guardian or Custodian, and change any item’s Sharing Setting.
Add or update an Emergency Contact.
Export their vault at any time.
9.2 If no Guardian, Custodian or Emergency Contact ever responds. If none of a subscriber’s nominated contacts ever confirms their status, and no Emergency Contact is nominated or reachable, Lyff has no independent way to detect that a trigger event has occurred. This is a limitation shared across every service in this category; no digital vault or legacy platform can act on behalf of a subscriber that nobody has come forward for. Lyff recommends subscribers nominate at least one Guardian or Emergency Contact for this reason, but does not require it, and does not guarantee resolution where nobody is nominated or nobody responds.
9.3 False trigger protections:
The subscriber can dispute a trigger at any point before the 48-hour post-verification window closes.
Any communication from the subscriber during the sequence halts all steps and resets it immediately.
Neither a Guardian nor a Custodian can unilaterally activate the trigger; they can only confirm a status or initiate the Lyff Release process with the required documentation.
10.1 All automated and manual communications in this sequence must:
Use warm, human language; never clinical, legal, or alarming in automated subscriber-facing emails or voicemails.
Never use the words “death,” “dying,” or “deceased” in automated emails, SMS messages, or voicemails to subscribers or Guardians during the welfare-check phase. Use “if something happened to you” or “we have been unable to reach [name].”
Frame each contact as a welfare check, not a legal process, until the Lyff Release process is required.
Include a direct support phone number and email address in every communication.
For phone calls and voicemails, use a calm, unhurried tone and identify the caller as Lyff support. Do not leave detailed account information in a voicemail; direct the subscriber to call back or log in.
10.2 Exception. The Lyff Release process request may use appropriate legal and administrative language, as it is directed to a person who has already confirmed the subscriber has passed or is incapacitated.
11.1 Storage. All vault contents and subscriber data are stored on Lyff’s standard storage servers located in Australia.
11.2 De-identification standard. When an account record is de-identified under clause 8.1, Lyff will apply a de-identification process that:
Removes or replaces all direct identifiers, including name, email address, mobile number, date of birth, and government-issued identification numbers.
Removes or replaces all indirect identifiers that, alone or in combination, could reasonably be used to re-identify the individual, including account number, IP address history, and nominated contact details.
Is consistent with the de-identification guidance issued by the Office of the Australian Information Commissioner (OAIC) under the Privacy Act 1988 (Cth).
11.3 Re-identification safeguard application. Lyff will develop and maintain a re-identification safeguard application (the Re-identification Safeguard) that:
Allows subscribers, during their active account period, to register a re-identification key that can be used to verify their identity if they believe their de-identified data has been incorrectly processed or linked to them.
Prevents Lyff staff and systems from re-identifying de-identified records except where required by law or a court order.
Logs all access attempts to de-identified records, including the date, time, user, and purpose of access.
Is subject to annual internal review to assess its effectiveness against current re-identification risk.
11.4 Permitted uses of de-identified data. De-identified activity logs retained under clause 8.1 may be used by Lyff solely for:
Internal service improvement and analytics.
Compliance with legal obligations.
Aggregate, non-identifiable reporting.
11.5 Deletion verification. On permanent deletion of vault contents under clause 8.1, Lyff will generate an internal deletion record confirming the date, scope, and method of deletion. This record is retained for 7 years and is available to the subscriber’s estate on written request made before deletion occurs.
12.1 Lyff’s liability to subscribers and nominated contacts.
To the maximum extent permitted by law, Lyff’s total aggregate liability to a subscriber, Guardian, Custodian, Emergency Contact, or Future Message recipient arising out of or in connection with this policy, whether in contract, tort (including negligence), statute, or otherwise, is limited to the total subscription fees paid by the subscriber to Lyff in the 12 months immediately preceding the event giving rise to the claim.
To the maximum extent permitted by law, Lyff excludes all liability for indirect, consequential, special, or punitive loss or damage, including loss of data, loss of opportunity, or distress arising from a delayed, failed, or incorrectly processed release, except where such loss arises from Lyff’s fraud or wilful misconduct.
Nothing in this clause limits Lyff’s liability for death or personal injury caused by Lyff’s negligence, or for any liability that cannot be excluded or limited under the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)).
12.2 Subscriber warranty and indemnity.
Each subscriber warrants that: (i) the information they provide when nominating a Guardian, Custodian, or Emergency Contact is accurate and current; (ii) they have obtained the consent of each nominated contact to be nominated and to receive communications from Lyff in accordance with this policy; and (iii) they are authorised to store the documents and information they upload to their vault.
Each subscriber indemnifies Lyff and its officers, employees, and agents against any claim, loss, damage, liability, cost, or expense (including reasonable legal costs) arising from: (i) a breach of the warranties in clause 12.2(a); (ii) the subscriber providing false, misleading, or outdated contact information that causes or contributes to an incorrect or premature release; and (iii) any third-party claim arising from the content of the subscriber’s vault or Future Messages.
12.3 Guardian, Custodian, and Emergency Contact indemnity.
- A Guardian, Custodian, or Emergency Contact who initiates the Lyff Release process indemnifies Lyff and its officers, employees, and agents against any claim, loss, damage, liability, cost, or expense (including reasonable legal costs) arising from: (i) a false, fraudulent, or misleading declaration or document submitted as part of the Lyff Release process; and (ii) any claim by the subscriber or a third party arising from a release initiated on the basis of information that was incorrect or obtained without authority.
12.4 Lyff’s obligations on wrongful release. If Lyff determines, acting reasonably, that a release was processed on the basis of fraudulent or materially incorrect documentation:
Lyff will immediately suspend access to released items pending investigation.
Lyff will notify the subscriber (if reachable) and all nominated contacts of the suspension.
Lyff will cooperate with any law enforcement or legal process relating to the fraudulent release.
Lyff’s liability in connection with a fraudulent release is limited to the cap in clause 12.1(a), except where the release resulted from Lyff’s own fraud or wilful misconduct.
12.5 Dispute resolution. Any dispute arising out of or in connection with this policy that cannot be resolved by the parties within 30 days of written notice of the dispute must be referred to mediation before either party may commence legal proceedings. Mediation is to be conducted in Victoria under the rules of the Resolution Institute (or such other body as the parties agree in writing).
12.6 Governing law. This policy is governed by the laws of Victoria, Australia. Each party submits to the non-exclusive jurisdiction of the courts of Victoria and the Federal Court of Australia.
13.1 Entire policy. This policy, together with the Lyff Terms of Service and Privacy Policy, constitutes the entire agreement between Lyff and subscribers with respect to the Inactivity Safeguard and account lifecycle.
13.2 Amendments. Lyff may amend this policy from time to time. Subscribers will be notified of material changes by email at least 30 days before the change takes effect. Continued use of the Lyff service after the effective date of an amendment constitutes acceptance of the amended policy.
13.3 Severability. If any provision of this policy is held to be invalid, unenforceable, or illegal, that provision is severed and the remaining provisions continue in full force and effect.
This policy forms part of our Terms of Service and should be read together with our Privacy Policy and Refund & Cancellation Policy.