Everything else you need to know
What would you like to know?
Answers to the questions people ask us most often. If you can't find what you need, our team is only an email away at support@filumio.com.
Billing & Subscriptions
-
How do I view and download my invoices?
Sign in and go to **Settings → Billing**. You'll see up to twelve months of invoices. Click any row to open the PDF, it's generated on demand and includes all line items for that month.
If an invoice is missing for a month you expected, and it usually means no charge was taken (for example, while you were on the free tier). If you believe that's incorrect, contact support with the month in question.
-
How do I move between the Free and Paid plans?
Go to **Settings → Billing → Change plan**.
- Upgrading is instant: you'll have access to all Premium features immediately.
- Downgrading is also instant, but if your vault currently has more items than the Free tier allows, we'll walk you through choosing which items to keep active before the change takes effect.Nothing is ever deleted when you change plans, items just become read-only if you're over the Free limit.
-
I was charged but my plan still shows as Free, what now?
Stripe occasionally takes a few minutes to sync. If your plan hasn't updated after 15 minutes:
1. Sign out and back in to refresh your session.
2. Check **Settings → Billing** for the most recent invoice.
3. If the invoice is there but the plan still says Free, contact support with the invoice number and we'll reconcile it for you manually. -
Can I get a refund?
Yes, and we offer a no-questions-asked refund within 14 days of any charge. Email **support@evervault.app** from the address on your account and we'll process it within two business days. Your vault and data stay intact after a refund.
Sensitive Files & Vault Items
-
Can EverVault staff see the contents of my vault?
No. Your vault items are end-to-end encrypted with keys derived from your password and, where applicable, your biometric factors. Our staff can see **metadata**, the titles you chose, item types, timestamps, and which trusted people you've invited, but never the contents of a note, document, or credential.
This is by design. It also means that if you lose your password **and** your recovery codes, even we cannot decrypt your data for you.
-
Where are my uploaded files stored?
Files are encrypted in your browser before being uploaded, then stored on globally-distributed, access-controlled object storage. The encryption keys never leave your devices in a readable form. We comply with POPIA's cross-border transfer requirements through encryption, contractual safeguards, and your explicit consent.
-
What's the difference between a Note, a Credential, and a Document?
- **Note**: free-form text, useful for instructions, last wishes, or context for your executor.
- **Credential**: a label + username + password (or secret). Credentials get extra protection like masking and optional step-up authentication before viewing.
- **Document**: one or more file attachments (PDF, image, etc.) with a title and optional summary.You can change an item's type later, though attachments only travel with Document items.
-
Why do some items ask me for biometric or extra verification again?
High-sensitivity items (S3 and S4) require **step-up authentication**, a fresh biometric or TOTP check, before they can be viewed, even if you're already signed in. This protects the most critical secrets from being accessed if you leave your session unattended.
You can see and adjust an item's sensitivity by opening it and choosing **Security → Sensitivity level**.
Email & Notifications
-
My trusted contact didn't get the invitation email.
First, ask them to check spam / promotions folders, our invitation comes from **no-reply@evervault.app**.
If it's not there:
1. Open the **Trusted People** section and look at the contact. The status should show "Invited".
2. Click **Resend invitation**, this generates a new secure link.
3. If that still doesn't arrive within 10 minutes, the recipient mail server may be blocking us. Try a different email address for the contact, or contact support.Invitation links are single-use and expire after 7 days for security.
-
Why am I getting emails about my vault that I didn't trigger?
EverVault sends transactional emails for: sign-in alerts from a new device, security events (password changes, MFA changes), and death-report workflows initiated by your trusted contacts.
If you see an email you didn't expect:
- **Sign-in alert**: check **Settings → Security → Sessions** and revoke anything you don't recognise. Rotate your password immediately.
- **Death-reported alert**: your trusted contact triggered the process. Sign in to pause or cancel the workflow.If anything looks suspicious, contact support straight away.
-
Can I stop marketing emails without disabling security alerts?
Yes. **Settings → Notifications** separates the two:
- **Security & account** emails are always on (required for the service).
- **Product updates and tips** can be toggled off independently.We will never mute a security email even if you unsubscribe from product updates.
Account Security & Access
-
I'm locked out after too many failed attempts. How do I get back in?
EverVault locks an account after 10 consecutive failed sign-in attempts to protect you from brute-force attacks.
To unlock:
1. Wait 15 minutes, many automatic locks clear on their own.
2. If it doesn't clear, use **Forgot password** on the sign-in page. A successful password reset will also unlock the account.
3. Still stuck? Contact support. A member of our team can verify your identity and unlock it manually. -
I forgot my password, can support help me recover my vault?
We can help you reset your password and regain sign-in access. What we **cannot** do is decrypt your existing vault items without your original password or a valid recovery code.
If you set up **Recovery codes** (Settings → Security), now is the time to use one. If you didn't, and your password is truly lost, the encrypted data will remain intact but inaccessible. Sorry, this is the trade-off for zero-knowledge encryption.
Going forward, and we strongly recommend (a) saving one recovery code in a physical safe and (b) appointing at least one trusted contact with `Executor` role.
-
How do I set up two-factor authentication (MFA)?
**Settings → Security → Multi-factor authentication** offers two options:
- **Authenticator app (TOTP)**, scan a QR code with Google Authenticator, 1Password, Authy, etc. Six-digit codes rotate every 30 seconds.
- **WebAuthn / passkey**, use a hardware key (YubiKey) or your device's built-in biometrics (Face ID, Touch ID, Windows Hello).WebAuthn is the most phishing-resistant option. You can enrol both and use whichever is convenient.
While you're there, print or download your **recovery codes**, you'll need them if you lose your second factor.
-
I want to sign out of all my other devices.
Open **Settings → Security → Sessions**. You'll see every active session with its device, IP, and last-seen time. Click **Revoke** next to anything that isn't your current device, those sessions become invalid immediately.
If you suspect a compromise, also **rotate your password** and rotate your recovery codes.
Guidance After Loss
-
My family member passed away. What do I do as their trusted contact?
First, we're sorry for your loss. Take the time you need.
When you're ready:
1. Sign into your own EverVault account.
2. Open **Shared With Me**, their vault will appear with an option to **Report death event**.
3. We'll ask for basic details (date of passing) and walk you through uploading a death certificate when you have one.Before a certificate is uploaded you'll have **Tier 1** access, essentially what the deceased pre-designated as "immediate" information (e.g. funeral wishes, utility accounts). Higher tiers unlock as verification documents are validated.
-
What documents do I need to unlock full estate access?
EverVault uses a four-tier exposure model:
| Tier | Access | Required document |
|------|--------|-------------------|
| 1 | Death reported | Self-attestation by a trusted contact |
| 2 | Death certificate validated | Copy of the official death certificate |
| 3 | Executor validated | Letter of Executorship from the Master of the High Court |
| 4 | Full (reserved for extreme cases) | Additional verification by EverVault staff |Documents can be uploaded from the Shared Vault screen. Validation is typically automated within minutes, but documents that need human review can take up to two business days.
-
I reported a death event by mistake, can I cancel it?
Yes, as long as the vault owner is still alive and signs in. The vault owner can pause or cancel the workflow from **Dashboard → Security banner** the next time they log in.
If the owner cannot sign in for a legitimate reason, contact support and we will cancel the workflow once we've confirmed the mistake.
Trusted People & Sharing
-
What's the difference between Executor, Trusted Contact, Viewer, and Verifier?
- **Executor**, can trigger the death-event workflow and, once verified, access the highest exposure tiers. Usually the person named in your will.
- **Trusted Contact**, can raise a death report and see the tier you've granted them. No legal authority.
- **Viewer**, read-only access, limited to the exposure tier you set, while you're alive. Useful for partners or co-administrators.
- **Verifier**, can upload verification documents (death certificate, letter of executorship) but doesn't get access to the vault contents themselves.Mix and match, for example, a solicitor as Verifier, your spouse as Executor, and your adult children as Trusted Contacts.
-
How do I change what a trusted person can see?
Open **Trusted People**, click the contact, then **Edit access**. You can:
- Change their role.
- Cap the maximum exposure tier they can ever reach.
- Require an extra MFA step before they can view anything.
- Revoke access entirely, they'll be removed and any invitation link becomes invalid.The contact will receive an email notification of any change, so they're never surprised.
-
My trusted person can't log into the shared vault.
Walk through this with them:
1. Have they accepted the invitation email? The link expires after 7 days, you may need to **Resend invitation** from **Trusted People**.
2. Are they signing in with the same email the invitation was sent to? If they already have an EverVault account, and they must use that address.
3. After signing in, do they see a **Shared With Me** section in the sidebar? If not, their invitation is still in "Invited" status, accept it first.
4. Still no luck? Contact support with the contact's email and we'll investigate.Reminder: during this stressful time you can walk the person through these steps on a call. You don't need to ask for their password or send their invitation link anywhere.