Privacy Policy
Last updated: September 15, 2026
BTC Pact is an instrument for documenting agreements between people about bitcoin. This policy describes what data the service stores, who processes it, how long it is kept, and what happens when you delete your account.
BTC Pact is operated by its owner. For any question about this policy or about your data, use the contact on our support page.
Information we store
Account data: your email address, a hash of your password (passwords are never stored in plain text), your preferred language, and a log of security events on your account: password changes and resets, including the signing key rotation a reset causes, requested and completed email changes, turning two-factor authentication on or off, regenerating or using a recovery code, and revoking every session. Sign-ins themselves are not recorded as events.
Two-factor authentication data: if you enable TOTP, the shared secret is stored encrypted at rest with dedicated keys, and your recovery codes are stored only as one-way hashes. Nobody, including support, can read them back.
Pact content: the documents, proposals, votes, discussion messages, signatures, and related evidence you create, together with the plan drafts and revisions kept for a Pact. Pact content is visible to the other participants of that Pact; that sharing is the point of the product. A plan draft stays private to the member who keeps it until it is committed into the agreement. When you invite somebody who has no account here, the email address you type is stored on that seat so the invitation can be delivered and recognized when they accept.
Operational data: error telemetry and service logs, with sensitive values redacted before they are written, and Bitcoin market price data, which contains no personal information.
AI content: your advisor conversations, turn by turn, with the tool calls made on your behalf and what they returned, and the commentary, analyses and readings the service generates and caches for the surfaces you open. A conversation is private to you. Commentary and analyses generated for a Pact are shown to that Pact's members.
AI processing
AI models are used in these places. While you write a Pact: the conversation that creates a Pact, the starting terms drafted from what you described, and the one line observation shown after each choice you make while composing it.
While you run a Pact: your private advisor, the console on the Pact's instrument, the dashboard analysis, the risk check analysis, the commentary on a chart, the commentary on a timeline entry, the explanation of a term you point at, and the narration of a range you select on the forecast chart.
When the group decides: the Consensus Read that summarizes a split vote, the advisor's reply when a member asks it in a proposal discussion, and the translation of titles, descriptions, discussion messages and vote reasons between English, Portuguese and Spanish.
Each request carries what that feature needs to answer it: the Pact's terms and figures, including its holdings, its loan and its safety lines, the roster with member names, role labels and shares, proposals, votes, vote reasons and discussion messages, the plan you are drafting, and whatever you type into the advisor, including an email address when you ask it to draft an invitation. The size of a request is capped, and daily usage budgets limit how much can be processed.
Requests go through OpenRouter, a routing service that forwards each one to the provider serving the chosen model, so both OpenRouter and that provider process the text a request carries. Text is sent to produce the response you asked for. BTC Pact does not use your content to train models; what a provider does with a request is governed by that provider's own terms.
Advisor conversations are stored with your account. Every turn is kept, including the tool calls the advisor made on your behalf and what they returned, every turn appears in your data export, and all of it stays until the account is deleted. The service offers no way to delete a single conversation earlier. Deleting your account deletes your conversations and your plan drafts; deleting a draft Pact deletes the conversations attached to it. Generated commentary, analyses and readings are cached and deleted on the schedule in the retention section below.
Consensus Read runs only with the consent of the participants whose messages it reads.
Product analytics
We record pseudonymous usage events keyed by a salted identifier to understand how the product is used. There are no advertising trackers and no third-party ad cookies.
Cookies
The service sets a session cookie to keep you signed in, a locale preference, and, while the private beta lasts, a gate-access cookie. All cookies are functional; none are used for advertising.
Service providers
The service runs on infrastructure operated by Vercel (hosting), Neon (database), Upstash (rate limiting), Resend (email delivery), and OpenRouter together with its underlying model providers (AI processing). These providers process data only to run the service.
Bitcoin timestamping
BTC Pact commits cryptographic hashes of Pact evidence to the Bitcoin blockchain through OpenTimestamps. A hash proves a record existed at a point in time; it reveals nothing about the record's content. Document text never leaves the service through timestamping. Hashes written to the blockchain are public and permanent and cannot be deleted by anyone, including us.
Shared links
Dashboard log share links are bearer links: anyone who has the link can view that shared log. You can revoke a share link at any time from the log page. Treat a share link with the same care as the content it reveals.
Retention
Some data is deleted automatically on a schedule:
- Error telemetry: 30 days.
- AI commentary cache: 90 days.
- Bitcoin price snapshots: 365 days.
- AI usage telemetry, dial assessments, and pseudonymous product events: 400 days.
- Records of delivered notification emails: 90 days.
- Email addresses of invited people who never accepted: 30 days after the invitation expires or the seat is withdrawn. Cancelling a Pact withdraws its open seats, so an address typed into a Pact that was cancelled before any invitation went out is deleted 30 days after the cancellation.
Pact documents, proposals, votes, messages, signed evidence, account security records, advisor conversations, and plan drafts are not telemetry. They are kept for as long as your account and your Pacts exist.
Account deletion
You can delete your account from settings once your Pacts are resolved: deletion is refused while you own a Pact, or hold an active seat in one, that is not ended or cancelled. The Terms explain how to resolve each case. Deletion is transactional: your personal data is removed in a single operation. Hashes and signatures that other participants rely on as shared evidence of their Pact are anonymized rather than rewritten, and hashes already committed to the Bitcoin blockchain cannot be removed.
Security
All traffic is encrypted in transit. Passwords and recovery codes are stored as one-way hashes, TOTP secrets are encrypted at rest, and security-critical rate limits fail closed. Support has no way to bypass two-factor authentication.
Questions
If you have a question about this policy or want to exercise control over your data, contact us through the address on our support page.