Last Updated: August 7, 2026
This page explains, in plain language, how risk is allocated between you and DokuDocs (a service of Online Services Internet Development & Marketing) when you use our document vault. It is a companion to, and incorporated by reference into, our Terms of Service — specifically Sections 8 through 11. If anything here appears to conflict with the Terms of Service, the Terms of Service control. This page is provided for clarity, not as a substitute for legal advice.
DokuDocs is a tool that stores documents and follows the instructions you configure. We work hard to make that tool reliable, secure, and accurate. But DokuDocs cannot control everything that happens outside our systems — whether a Recipient checks their email, whether your contact information stays current, or whether a bad actor attempts to break in. Below are the three scenarios we are asked about most often.
On plans that include Recipients (Family and Legacy), you choose which Recipients can access which categories of documents. Once a status change is detected, DokuDocs applies a standard access-delay window — currently four to five days — before granting any access. This window is a fixed feature of the Service, not something Customers individually configure, and gives you an opportunity to respond and deny access if the determination was incorrect. Our status-verification system and access-delay timers are designed to follow this process consistently for every account on an included plan.
What we control: we will not release documents outside the standard process described above, absent a bug or security failure.
What we can't fully control: like any software, our status-verification system, timers, or third-party data sources could theoretically malfunction or be manipulated. If an early release occurs due to our error, we will investigate and take corrective action; however, as described in our Terms of Service (Section 10), our financial liability for any such error is limited, and we are not liable for indirect or consequential damages (such as a Recipient acting on a document before you intended).
What reduces this risk: using the "I Am Alive — Deny Access" option promptly if you receive a notification in error, and reviewing your Recipient and access settings periodically.
We use encrypted transmission (HTTPS/TLS), hashed passwords, token-based Recipient access, and access logging to protect your account and documents. We monitor for suspicious activity and apply security updates on an ongoing basis.
What we control: implementing and maintaining reasonable, industry-standard security practices, and responding promptly if we detect a breach, including notifying affected Customers as required by law.
What we can't fully control: no system connected to the internet can be guaranteed unbreakable. Sophisticated attacks, previously unknown software vulnerabilities, or a Customer's own compromised email or password (for example, through phishing) can lead to unauthorized access despite our safeguards. As described in our Terms of Service (Section 8), we are not liable for losses resulting from unauthorized access except where caused by our gross negligence or willful misconduct, or where such liability cannot legally be excluded.
What reduces this risk: using a strong, unique password for your DokuDocs account, enabling any additional security features we offer, and never sharing your login credentials.
When a status change is detected, we attempt to notify each Recipient using the contact information you provided, via email and (if you've enabled it) postal mail.
What we control: sending notifications promptly to the contact information on file, using reliable third-party email and mail delivery providers.
What we can't fully control: we cannot guarantee that a Recipient's email address or mailing address is current, that their email provider won't filter our message as spam, that they will check their inbox or mail, or that they remain reachable at all. As described in our Terms of Service (Section 7), we are not liable for delayed, failed, or non-delivered notifications resulting from outdated contact information or third-party delivery failures, except where such liability cannot be excluded under applicable law.
What reduces this risk: keeping Recipient contact information current, designating more than one Recipient where appropriate, and periodically confirming with your Recipients that they understand their role.
The scenarios above are addressed more formally in our Terms of Service:
A note on what isn't limited: nothing in this page or our Terms of Service is intended to limit liability in ways not permitted by law. Some states do not allow certain limitations of liability or exclusions of warranties, so some of the limitations described here and in our Terms of Service may not apply to you, and you may have additional rights under your state's law.
If you have questions about how risk is allocated under our Terms, or want help understanding your Recipients or access settings to reduce risk in your specific situation, contact us at support@dokudocs.com or through our Contact page. This page is informational and does not constitute legal advice; for advice specific to your estate plan, please consult a licensed attorney.