Skip to content
Trust & Security

Deliberately boring. Verifiably careful.

This page is written for the skeptical reader. No marketing, no superlatives — just what BitCare stores, what it never touches, and how it is protected.

Non-custodial by architecture

BitCare never holds Bitcoin, keys, or the means to move funds. This is not a policy that could change — it is an architecture that has nothing to hold. There is no wallet inside BitCare, no signing capability, and no field anywhere in the product that accepts a seed phrase. If any screen ever asks you for one, it is not ours.
Data boundaries

What BitCare never collects

The framework works on how your custody behaves, not on what it contains. That means whole categories of data simply never enter the system.

  • Seed phrases — never asked, never accepted, no input field exists
  • Private keys — in any form, including encrypted
  • Wallet addresses — your plans reference devices and places, not addresses
  • Balances and amounts — BitCare does not know how much Bitcoin you have
  • Exchange accounts or API keys — no integrations that touch funds
Data minimisation

What we store, and why

We store the plan, not the treasure map. Every record exists to run your continuity journey — nothing more.

Data Why it exists Who can read it
Account email Sign-in, and the notifications you choose You; BitCare systems for delivery
Assessment answers Compute your health score and recommendations Only your account
Plans you write (recovery, legacy, setup notes) Your continuity documentation, available on every device Only your account — row-level security enforced
Guardian contact details (Legacy plan) Invitation and activation of the guardian you choose You and, after activation, your guardian
Subscription state Unlocking the features of your plan You; payment processors see only their own transaction
Technical measures

How your data is protected

Encryption

Every connection is encrypted in transit with TLS (1.2+). AES-256 encryption at rest. Access to plan content is enforced at the database layer (row-level security).

Access isolation

Row-level security at the database layer: your records are readable by your authenticated account and no one else's — enforced by the database, not by application code alone.

Guardian safeguards

Guardian activation is staged, logged, and reversible until final. Guardians receive access to instructions you wrote — never to keys, because there are none to receive.

Guardian activation

Six stages. Fully reversible until the last.

Guardian activation does not trigger on a single event. It requires sustained inactivity, confirmed across three escalating stages — and remains cancellable at every point until the portal token is generated at Day X+37.

Stage When What happens Cancellable?
Setup Day 0 Guardian assigned. Plan activated. Yes
Owner Active Ongoing Regular check-ins reset the countdown timer. Yes
Inactivity detected Day X No login detected. Countdown begins silently. Yes
Warning sent Day X+14 Account owner notified by email. Cancel window open. Yes
Guardian notified Day X+30 Guardian receives notice that activation is pending. Yes
Portal token created Day X+37 Portal access is granted — only at this stage, never before. Final

Portal access is created only at Day X+37 — never before. Every prior stage is cancellable by the account owner.

Your data, your call

Control that doesn't require asking nicely

Continuity planning is personal. The data you put into BitCare stays under your control for as long — and only as long — as you want it there.

  • Export — download your data whenever you want it
  • Delete — permanently remove your account and every record with it
  • No lock-in — your plans are yours; leaving BitCare never puts them at risk
  • Swiss data discipline — engineered to Swiss privacy standards (DSG) and GDPR
Security research

Responsible disclosure

Found something? We want to know, and we take reports seriously.

Report security issues to our security contact. Include enough detail to reproduce the issue. We confirm receipt, keep you informed while we fix it, and credit researchers who report in good faith. Please do not access other users' data while testing.

Trust is earned in the details

Read how the framework works, or start with the free assessment and see the data boundaries for yourself.

Legal documents: Privacy Policy · Terms of Service