Privacy Policy
Last updated: August 3, 2026
BTC Pact is an instrument for documenting agreements between people about bitcoin. This policy describes what data the service stores, who processes it, how long it is kept, and what happens when you delete your account.
BTC Pact is operated by its owner. For any question about this policy or about your data, use the contact on our support page.
Information we store
Account data: your email address, a hash of your password (passwords are never stored in plain text), your preferred language, and a log of security events on your account such as sign-ins and authentication changes.
Two-factor authentication data: if you enable TOTP, the shared secret is stored encrypted at rest with dedicated keys, and your recovery codes are stored only as one-way hashes. Nobody, including support, can read them back.
Pact content: the documents, proposals, votes, discussion messages, signatures, and related evidence you create. Pact content is visible to the other participants of that Pact; that sharing is the point of the product.
Operational data: error telemetry and service logs, with sensitive values redacted before they are written, and Bitcoin market price data, which contains no personal information.
AI processing
Translations, commentary, and the Consensus Read feature send the relevant text to AI models through OpenRouter, a routing service that forwards each request to the model provider serving it. Text is sent only to produce the response you asked for, and daily usage budgets limit how much can be processed.
Consensus Read runs only with the consent of the participants whose messages it reads.
Product analytics
We record pseudonymous usage events keyed by a salted identifier to understand how the product is used. There are no advertising trackers and no third-party ad cookies.
Cookies
The service sets a session cookie to keep you signed in, a locale preference, and, while the private beta lasts, a gate-access cookie. All cookies are functional; none are used for advertising.
Service providers
The service runs on infrastructure operated by Vercel (hosting), Neon (database), Upstash (rate limiting), Resend (email delivery), and OpenRouter together with its underlying model providers (AI processing). These providers process data only to run the service.
Bitcoin timestamping
BTC Pact commits cryptographic hashes of Pact evidence to the Bitcoin blockchain through OpenTimestamps. A hash proves a record existed at a point in time; it reveals nothing about the record's content. Document text never leaves the service through timestamping. Hashes written to the blockchain are public and permanent and cannot be deleted by anyone, including us.
Shared links
Dashboard log share links are bearer links: anyone who has the link can view that shared log. You can revoke a share link at any time from the log page. Treat a share link with the same care as the content it reveals.
Retention
Operational data is deleted automatically on a schedule:
- Error telemetry: 30 days.
- AI commentary cache: 90 days.
- Bitcoin price snapshots: 365 days.
- AI usage telemetry, dial assessments, and pseudonymous product events: 400 days.
- Records of delivered notification emails: 90 days.
Pact documents, proposals, votes, messages, signed evidence, and account security records are not telemetry. They are kept for as long as your account and your Pacts exist.
Account deletion
You can delete your account from settings. Deletion is transactional: your personal data is removed in a single operation. Hashes and signatures that other participants rely on as shared evidence of their Pact are anonymized rather than rewritten, and hashes already committed to the Bitcoin blockchain cannot be removed.
Security
All traffic is encrypted in transit. Passwords and recovery codes are stored as one-way hashes, TOTP secrets are encrypted at rest, and security-critical rate limits fail closed. Support has no way to bypass two-factor authentication.
Questions
If you have a question about this policy or want to exercise control over your data, contact us through the address on our support page.