The two failure modes
Legacy plans fail in one of two directions. Too open: shared passcodes, a "family" cloud folder, an executor with standing access — privacy is spent years before it is needed, and every added person is an added risk surface. Too closed: perfect encryption, keys nowhere, and the family faces a mathematically sealed archive at the worst possible time. Both failures come from using one mechanism for two jobs — daily privacy and eventual transfer — that need opposite properties.
The sealed-key pattern
Separate the jobs. Daily privacy: an encrypted vault only you can open, exactly as before. Eventual transfer: the vault’s recovery phrase — a key that opens that vault and nothing else — written down, sealed, and stored where your estate process will surface it: with a lawyer or notary, in a safe-deposit box, or split between two people you trust for different reasons.
The properties fall out naturally. Nobody has access while you live, and you can tell how access would happen — a physical envelope, visibly opened. The scope is one curated vault, not your digital life. Revocation is trivial: move the contents to a new vault with a new phrase, and the old envelope is paper. And the person retrieving it needs no technical skill — a phrase and an app install, with your instructions in the envelope.
Making it real
Three practical steps turn the pattern into a plan. Write instructions for a stressed non-expert: what this envelope is, what app to install, how to enter the phrase, who to call if stuck. Rehearse the restore once yourself on a second device, so you know the phrase on the paper actually works. And put a yearly reminder to review the vault’s contents — the plan should age with your life, not fossilise at the moment you made it.