Best Dead Man's Switch Apps in 2026, Compared
Seven products, each checked against its own public pages in August 2026: Sanctia, Dead Man's Switch, Myend, CipherWill, GoodTrust, Google's Inactive Account Manager and Apple's Legacy Contact. We wrote the criteria down before we looked at any product, including our own.
A dead man's switch spends almost all of its life not firing. So the question that decides whether you can live with one isn't what it does the day you die. It's what it does the week you're in hospital with your phone in a locker. Two of the seven don't document an inactivity trigger at all.
What to use, depending on what you are protecting
All you care about is your Google account
Google Inactive Account Manager. Free, already in your settings, nothing to maintain. Don't pay for anything else. One caveat: as of August 2026 Google's help pages say these settings don't override its right to delete an account inactive for two years.
You're handing over passwords, recovery phrases or private keys
CipherWill. It's purpose-built for that handoff, with per-beneficiary key release as the core workflow. Sanctia can carry a credential inside a passphrase-encrypted message the server cannot read, but isn't built around it.
You need a will, a trust, or health directives
GoodTrust, or a lawyer. A dead man's switch isn't an estate plan and won't be treated as one.
You own an iPhone and assumed Apple had this covered
Set up Legacy Contact anyway, it's free. But it hands iCloud data to a contact holding a death certificate. Going quiet starts nothing.
You want the paperwork and the goodbye letters in one place, paid for once
Myend. Ninety-nine dollars, a cadence you pick, five missed checks before anything is shared, and any single reply stops it.
You want plain email, cheap, from a service with a long track record
Dead Man's Switch. Two dollars a month billed yearly, and a timeline published to the day.
You want particular people to hear from you, in your own voice
Sanctia. Voice notes, photos and formatted letters, not just plain text, and a private vault per recipient by default. Underneath it, three consecutive misses by default and a hold before anything sends.
Two of those lines can describe the same person. Nothing about running Google's tool stops you also writing letters.
Who publishes this page
Sanctia does, and Sanctia is one of the seven. That's a conflict of interest, so here's the handling.
Every claim about another product comes from that product's own public pages, and this page names which page and when. Where a product doesn't publish something, this page says "not documented" rather than guessing. Where a different product is the better answer, it gets said by name.
How the seven compare
| Sanctia | Dead Man's Switch | Myend | CipherWill | GoodTrust | Google Inactive Account Manager | Apple Legacy Contact | |
|---|---|---|---|---|---|---|---|
| On a false alarm | Three consecutive misses by default, count set by you, reminder at each step, then a 24-hour hold | Reminders at 30, 45 and 52 days by default; everything sends at 60 days | Five missed checks before release; any reply stops it | Alerts from day 30, keys release at day 100; logging in resets the schedule | No inactivity trigger documented | Contacts are notified once the account has been inactive for the period you set | No inactivity trigger documented; death certificate and access key required |
| Human check | If enabled, trusted contact confirms first, and they can stop it | Not documented | Notified at the end, not asked first | Not documented; only you can reset the clock | Not applicable | None documented | None documented; your contact starts the claim |
| What you can send | Letters, voice notes, photos | Email; file attachments up to 10 MB on the paid tier | Goodbye messages, directives, documents | Passwords, recovery phrases, private keys, documents, notes | Estate documents and account records | A note you write, plus chosen Google account data, to up to 10 people | iCloud data: photos, messages, notes, files; no message field documented |
| Encryption | Envelope encryption at rest by default, AES-256-GCM with keys held in AWS KMS; optional passphrase encryption the server cannot read, Argon2id at 64 MB, 3 iterations, 4-way parallelism, checked against reference known-answer tests in CI whenever that code changes; encryption code published at github.com/dhruvaashok/sanctia-crypto, full model on the security page | Not documented | "AES-256, encrypted client-side"; team cannot read your plan | Zero knowledge, AES-256-GCM sealed in the browser; payload locked to one named beneficiary by an ECDH key exchange | "256-bit encryption", per its own description | Your Google account's own protections | Access key held by your contact; iCloud Keychain excluded |
| Price | Free during early access | Free, capped at one message and one recipient; $2/mo billed yearly; or $100 once for two lifetime accounts | Free, $19 once, or $99 once with check-ins | Free for life, up to five beneficiaries; or $40/year | $149 | Free | Free with an Apple Account |
| Platform | Web now; iPhone via TestFlight; Android via Google Play | Web, plus an Android app | Web; native apps not documented | Browser | Not documented | A setting in your Google account | A setting in your Apple Account |
"Not documented" means the claim could not be found published on the product's own pages as of August 2026. It is not a statement that the product lacks the capability. Several of these products may well do more than they say.
Sources, each read in August 2026: deadmansswitch.net, myend.com and its pricing, security and proof-of-life pages, cipherwill.com and cipherwill.com/how-it-works, mygoodtrust.com, Google's Inactive Account Manager support pages, and Apple's Legacy Contact and platform security documentation.
What most of these get wrong
Almost every product in this category treats the false alarm as an edge case. Over ten years it's the normal operating condition.
Do the arithmetic. On a weekly interval, a switch you keep for a decade asks you roughly five hundred times whether you're still alive and expects an answer every time. Each one is a chance to be wrong for a boring reason. A dead battery on the second morning of a walking holiday. A new SIM in a country where the old number quietly stopped receiving anything. A fortnight where your father was in hospital and nobody once opened their own inbox. Software cannot tell silence from death and never will. All it can do is make silence expensive to misread.
There are four honest ways to do that.
Require more than one miss
With the number yours to set. Someone who checks in daily can miss three in a row and still be inside a long weekend. Someone who checks in quarterly cannot afford anything like that much slack, and one default cannot serve both.
Offer more than one way to answer
If the only thing that counts is clicking a link in an email, the switch is really a test of your spam filter, and you find out it failed on the one day it mattered. CipherWill's Premium plan documents call, SMS and WhatsApp check-ins alongside email, which is the right instinct.
Let people pause it
A surgery date is known weeks ahead. So is the flight to the place with no coverage. If a switch cannot be paused, you end up planning your month around the software instead of the other way round, and the people who forget are the ones it fires on.
Ask a person
Every automated rule can be wrong in a way its designer didn't anticipate, and a trusted contact who can answer "no, she's fine" is the only safeguard that doesn't depend on the software having imagined the failure correctly. On Sanctia this fourth one is opt-in rather than default, and naming a contact doesn't switch it on.
Sanctia does all four. Of the other six products on this page, Dead Man's Switch, CipherWill and Myend publish escalating reminder timelines, and as of August 2026 none of them documents a point at which another person is asked first and can answer no. A published timeline is genuinely useful and far better than nothing. It still only warns you; nobody gets to stop the thing.
The reason to care is the asymmetry. A message that never arrives is a sad outcome. A message that arrives while you're alive is a different order of mistake, and no apology puts it back. Picture your sister opening a letter that starts from the assumption you are dead, on an ordinary Tuesday, because you spent four days on a trail with no signal. False alarms works through the scenarios one at a time, and how each one gets handled.
Why Sanctia
Four situations, and what the product actually does in each.
You have a surgery date next month
Pause it. You pick the length, and a timed pause resumes on its own, so the protection you set up in a careful mood doesn't quietly stay switched off for the next two years because you never went back to it. That is the whole feature. It exists because the date is known in advance, and the software should not be one more thing to remember on the morning.
Your job worries your family
Then the message matters more than the machinery, and the machinery should stay out of the way. You write letters with real formatting, record voice notes, and add photos, each addressed to a particular person. Recipients get their own private vault by default rather than an email carrying the body, so what you wrote is not sitting in an inbox waiting to be forwarded, and it does not have to survive a spam filter four years from now.
A new baby, and you fly for work most months
Missing one check-in does nothing. Delivery needs three consecutive misses by default, the count is yours to set, and a fresh reminder goes out at every step. Check-ins arrive by email on a new account; push and SMS are in settings, and SMS needs a phone number you have added and verified. Turn a second channel on. It is the cheapest insurance on this page, because an email provider throttling a sender is the kind of failure you never see happen.
Your mother lives alone and you are the one who checks on her
Name a trusted contact and switch confirmation on, and that person is asked before anything is sent. It is off until you switch it on, and naming someone does not switch it on. Two things are worth knowing before you rely on it. If the window you set expires with nobody answering, delivery proceeds. Silence is not a veto, and if you want it to be, set the request to wait with no limit. And after your contact confirms, delivery still waits an hour, which is there for the case where someone confirms and then the phone rings.
Underneath all four is a hold. Nothing moves the instant the last check-in goes unanswered. It defaults to 24 hours, and you can extend it.
There is no recall
Once messages have been delivered, we cannot pull them back and neither can you. Every layer above exists for that reason alone. Nothing here is a remedy after the fact, and you should discount any product that offers one.
Encryption
Encrypted by default with AES-256-GCM.
Keys are held in AWS KMS.
Add one and it never leaves your device, which means nothing on our servers can open the message.
Argon2id at 64 MB of memory, 3 iterations and 4-way parallelism.
Output checked against reference known-answer tests in CI whenever that code changes.
The parameters are published so you can check them instead of taking our word for it. Full model on the security page; the code that implements it is open source at github.com/dhruvaashok/sanctia-crypto.
Sanctia is in early access. The web app is open to anyone today, the iPhone app comes through Apple's TestFlight, and Android is in open testing on Google Play.
Free during early access. No card, no phone number. Four minutes to set up, and you can delete your account whenever you want.