Deliberately boring. Verifiably careful.
This page is written for the skeptical reader. No marketing, no superlatives — just what BitCare stores, what it never touches, and how it is protected.
Non-custodial by architecture
BitCare never holds Bitcoin, keys, or the means to move funds. This is not a policy that could change — it is an architecture that has nothing to hold. There is no wallet inside BitCare, no signing capability, and no field anywhere in the product that accepts a seed phrase. If any screen ever asks you for one, it is not ours.What BitCare never collects
The framework works on how your custody behaves, not on what it contains. That means whole categories of data simply never enter the system.
- Seed phrases — never asked, never accepted, no input field exists
- Private keys — in any form, including encrypted
- Wallet addresses — your plans reference devices and places, not addresses
- Balances and amounts — BitCare does not know how much Bitcoin you have
- Exchange accounts or API keys — no integrations that touch funds
What we store, and why
We store the plan, not the treasure map. Every record exists to run your continuity journey — nothing more.
| Data | Why it exists | Who can read it |
|---|---|---|
| Account email | Sign-in, and the notifications you choose | You; BitCare systems for delivery |
| Assessment answers | Compute your health score and recommendations | Only your account |
| Plans you write (recovery, legacy, setup notes) | Your continuity documentation, available on every device | Only your account — row-level security enforced |
| Guardian contact details (Legacy plan) | Invitation and activation of the guardian you choose | You and, after activation, your guardian |
| Subscription state | Unlocking the features of your plan | You; payment processors see only their own transaction |
How your data is protected
Encryption
Every connection is encrypted in transit with TLS (1.2+). AES-256 encryption at rest. Access to plan content is enforced at the database layer (row-level security).
Access isolation
Row-level security at the database layer: your records are readable by your authenticated account and no one else's — enforced by the database, not by application code alone.
Guardian safeguards
Guardian activation is staged, logged, and reversible until final. Guardians receive access to instructions you wrote — never to keys, because there are none to receive.
Six stages. Fully reversible until the last.
Guardian activation does not trigger on a single event. It requires sustained inactivity, confirmed across three escalating stages — and remains cancellable at every point until the portal token is generated at Day X+37.
| Stage | When | What happens | Cancellable? |
|---|---|---|---|
| Setup | Day 0 | Guardian assigned. Plan activated. | Yes |
| Owner Active | Ongoing | Regular check-ins reset the countdown timer. | Yes |
| Inactivity detected | Day X | No login detected. Countdown begins silently. | Yes |
| Warning sent | Day X+14 | Account owner notified by email. Cancel window open. | Yes |
| Guardian notified | Day X+30 | Guardian receives notice that activation is pending. | Yes |
| Portal token created | Day X+37 | Portal access is granted — only at this stage, never before. | Final |
Portal access is created only at Day X+37 — never before. Every prior stage is cancellable by the account owner.
Control that doesn't require asking nicely
Continuity planning is personal. The data you put into BitCare stays under your control for as long — and only as long — as you want it there.
- Export — download your data whenever you want it
- Delete — permanently remove your account and every record with it
- No lock-in — your plans are yours; leaving BitCare never puts them at risk
- Swiss data discipline — engineered to Swiss privacy standards (DSG) and GDPR
Responsible disclosure
Found something? We want to know, and we take reports seriously.
Trust is earned in the details
Read how the framework works, or start with the free assessment and see the data boundaries for yourself.
Legal documents: Privacy Policy · Terms of Service