Digital Estate Planning

What Happens to Your Online Accounts When You Die?

Online accounts do not automatically transfer to your family when you die. Depending on the provider, an account may remain active, become memorialized, be deleted after inactivity, release limited data to a designated contact, or require formal legal process.

Configure provider legacy tools while alive. They are usually faster and more predictable than asking relatives to prove entitlement afterward.

Last policy verification: August 27, 2026. Provider features and regional requirements change; follow the linked official instructions before acting.

Provider comparison

ProviderBest advance actionWhat a designated person may receiveImportant exclusion or limitation
GoogleInactive Account ManagerSelected data, based on the owner's settingsGoogle decides post-death requests case by case
AppleLegacy Contact and access keyCertain Apple Account data after proof of deathiCloud Keychain passwords/passkeys and purchased media are excluded
MicrosoftOneDrive Digital Legacy where availableRead-only OneDrive files/photos for a trusted contactOther personal-account content may require legal process; availability varies
FacebookLegacy ContactLimited management of a memorialized profileThe contact does not simply become the account owner
InstagramLegacy Contact where available or memorialization requestLimited memorialized-profile actionsProcedures and feature availability may vary

Google

Google says Inactive Account Manager lets a user decide when an account should be considered inactive, who should be notified, which selected information should be shared, and whether the account should be deleted.

Google calls it the best way to communicate access and deletion wishes in its deceased-user account guidance.

Without advance configuration, immediate family members or representatives can request closure and, in some circumstances, content. Google says it will not provide passwords or other login details and evaluates requests carefully.

Google also reserves the right to delete a personal account and its data after at least two years of inactivity, subject to exceptions. See the Inactive Google Account Policy.

Plan now

  • Configure Inactive Account Manager.
  • Choose a timeout appropriate to your normal use.
  • Select only data each contact should receive.
  • Keep recovery information current.
  • Decide whether deletion is appropriate.

Apple

Apple's Legacy Contact feature lets an owner generate an access key for one or more trusted people. After the owner's death, the contact generally needs the access key and a death certificate or region-specific equivalent.

Apple says accessible data may include photos, messages, notes, files, and device backups. It excludes licensed media, subscriptions, and data stored in iCloud Keychain, including payment information, passwords, and passkeys. See How to add a Legacy Contact.

Apple's deceased-family-member guidance also describes court-order requests in relevant jurisdictions and warns that Apple may be unable to decrypt end-to-end encrypted data.

Plan now

  • Add appropriate Legacy Contacts.
  • Securely give each contact the access key.
  • Do not assume that the contact can recover iCloud Keychain credentials.
  • Maintain a separate plan for device passcodes and encrypted data where lawful.

Microsoft

Microsoft's documented procedures are less uniform across services and regions.

Its deceased or incapacitated user guidance says that if no one knows the credentials, personal account content may require a valid subpoena or court order for Microsoft even to consider release, and release is not guaranteed. It also states that accounts can expire after prolonged inactivity.

Microsoft separately documents OneDrive Digital Legacy, which can grant a trusted contact read-only access to OneDrive files and photos. Check whether the feature is available for your account and jurisdiction.

Plan now

  • Configure OneDrive Digital Legacy if available and appropriate.
  • Document Microsoft subscriptions and payment sources.
  • Maintain lawful business continuity outside a personal Microsoft account.
  • Do not assume a relative can obtain Outlook or OneDrive content without advance action.

Facebook

Facebook lets eligible users select a legacy contact. After memorialization, the contact may perform limited actions such as managing tribute-related settings, pinning a post, changing profile or cover images, responding to some friend requests, downloading permitted profile information if the owner enabled it, or requesting deletion.

The legacy contact cannot log in as the deceased person or read private messages merely because of the designation. See Facebook's Legacy Contacts help and Memorialized Accounts help.

Plan now

  • Choose a legacy contact.
  • Decide between memorialization and deletion.
  • Review whether archive download is permitted.
  • Tell the contact what you want.

Instagram

Meta documents memorialization and legacy-contact functionality for Instagram, although availability and controls may change. A memorialized account remains visible with protections against login and alteration. Verified family members may request removal.

Use the current Instagram Legacy Contact help and official memorialization process rather than sharing a password informally.

Financial institutions

Banks, brokerages, insurers, and payment services commonly require documents such as:

  • Death certificate
  • Executor or administrator appointment
  • Trust documentation
  • Government identification
  • Institution-specific forms

An online password does not replace those requirements. Logging in as the deceased may violate terms, obscure the audit trail, or complicate administration.

Record the institution and account identifier in your Digital Estate Checklist, but direct representatives to the institution's estate department.

Cryptocurrency

Custodial exchange

The exchange controls the account infrastructure and normally requires an estate or beneficiary process. Document the exchange, account identity, MFA dependencies, and legal ownership.

Self-custodied wallet

Control may depend entirely on the seed phrase or private keys. No provider may be capable of recovering them. Anyone who obtains them may be able to move assets irreversibly.

Use a specialized succession plan with secure redundancy, clear instructions, and professional legal and security advice. Do not place an unencrypted seed phrase in a general estate inventory.

Domains, websites, and business systems

Domains can expire quickly and disrupt websites, email, and customer access. Record:

  • Registrar
  • Registrant or business owner
  • Renewal payment method
  • DNS provider
  • Hosting provider
  • Source repository
  • Deployment authority
  • App-store and certificate accounts

Move business-critical systems into organization-owned accounts with multiple authorized administrators. A founder's personal password vault should not be the only succession mechanism.

The Revised Uniform Fiduciary Access to Digital Assets Act provides a framework used by many U.S. states for fiduciary access, including executors, trustees, conservators, and agents. The enacted law, provider terms, account-owner directions, and the type of content all affect access.

For why credentials and legal authority must be coordinated, read Password Manager vs. Digital Estate Plan.

The bottom line

Each provider has its own definition of legacy access. Some release selected files; some permit limited memorialization; some require legal process; some cannot decrypt important data at all.

Use official designation tools now, keep their keys outside inaccessible accounts, and document the intended action for every important service.

All guides