BitcoinProof Privacy Policy
Version 1.0 — Last updated 2026-07-29 — Published at bitcoinproof.io/privacy
The specific third parties this policy relies on — our hosting, email, and payment providers, and the default block explorer the desktop application queries — are named in Annex A, which carries its own revision date. Updating Annex A to reflect a change of provider is not a "material change" to this policy under section 11 and does not change the Version above.
This Privacy Policy explains how BitcoinProof processes personal data. It applies to two distinct contexts, which we describe separately throughout: (i) the bitcoinproof.io website, where you can buy a licence and manage your account; and (ii) the BitcoinProof desktop application, which you install on your own computer. The architectural separation between the two is deliberate and material — the desktop application does not send your wallet data, identity fields, or report contents to us.
1. Who we are (Controller)
The data controller is Wenze van Klink, trading as BitcoinProof, a Dutch sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce (KVK) under number 91404983, with business address Snijbiet 11, 2371DR Roelofarendsveen, NL VAT (BTW) number NL004888591B14.
Contact: privacy@bitcoinproof.io
General support: support@bitcoinproof.io
We have not appointed a Data Protection Officer; one is not required under Article 37 GDPR for the processing operations described below. The Dutch Autoriteit Persoonsgegevens (AP) is our lead supervisory authority.
2. The two contexts at a glance
| Website (bitcoinproof.io) | Desktop application | |
|---|---|---|
| What it is | Marketing site, account portal, purchase flow, licence-key delivery, referral programme | Local Bitcoin verification engine installed on your computer |
| Personal data we receive | Email, purchase metadata, IP address, browser user agent, referral attribution | None about you as a person — no wallet data, no descriptors, no UTXO data, no identity fields, no reports |
| Outbound calls from your computer | Standard HTTPS while you browse | (a) script hashes to the public Bitcoin block explorer you select (the shipped default is named in Annex A and shown in the application before any scan); (b) HTTPS GET to bitcoinproof.io/licenses.json for licence validation; (c) HTTPS GET to bitcoinproof.io/version.json for update check |
| Where data is stored | Our hosted infrastructure (EU region; the hosting provider is named in Annex A) | Your local machine only |
The two flows are disjoint. The desktop application does not communicate with us about you. Your email is never sent to the desktop application; the desktop application never sends anything to us tagged with your identity.
3. The website (bitcoinproof.io)
3.1 What we collect, why, and the lawful basis
| # | Data | Purpose | Lawful basis (Art. 6 GDPR) | Retention |
|---|---|---|---|---|
| W1 | Email address | Account authentication, licence-key delivery, receipts, operational notices | Art. 6(1)(b) contract | Active account + 2 years; invoice records for 7 years (Art. 6(1)(c) Dutch Tax Code Art. 52) |
| W2 | Purchase metadata — including EUR amount, payment method, payment-processor reference (the processor is named in Annex A), status timestamps, Quaderno invoice IDs, and (for Business-tier purchases) is_b2b flag, VAT number, VIES consultation number, company name, company address |
Provide the service, issue the invoice, satisfy tax and VAT-compliance record-keeping | Art. 6(1)(b) contract + Art. 6(1)(c) tax law (Dutch Tax Code Art. 52, BTW Art. 35a, CJEU Luxury Trust) | 7 years from end of fiscal year — uniformly across all fields in this row including B2B sub-fields. Never auto-pruned; manual review at year 8. |
| W3 | Magic-link authentication tokens | Authenticate you when you click the magic link | Art. 6(1)(b) contract | 24 hours from issuance (typical actual retention is much shorter — used tokens are deleted on use, unused tokens within ~1 hour of their 10-minute expiry) |
| W4 | Server access logs (IP address, user agent, request path, timestamp) | Operational security, abuse and DDoS detection, availability monitoring | Art. 6(1)(f) legitimate interests | 30 days, then deleted; IP truncated on ingestion where operationally feasible |
| W5 | Referral attribution and Partner records, including (i) referral code, attribution row, commission row, and purchase metadata overlap with W2, and (ii) Partner profile data — name, contact email, payout address, payout method, country (optional), lifecycle state, activated_at, signup path (/refer direct vs. customer-path auto-created), and aggregate commission and payout history |
Calculate and pay referral commissions; surface the partner dashboard at /partner; operate the self-serve signup flow at /refer and the auto-created Partner record described at legal-tos.md clause 11.7 |
Art. 6(1)(f) legitimate interests for the dashboard/operational components AND Art. 6(1)(b) contract for the automatic Partner record created alongside Your customer Account (clause 11.7) + Art. 6(1)(c) where data overlaps the invoice | Until commission settled; invoice component retained per W2. Partner records in pending_activation with no commission history are hard-deleted on User erasure (their existence has no audit obligation since they never paid out). Activated Partner records follow the partner contact-email scrub pattern described in §3.5 below. |
| W6 | Renewal reminders | Remind you before a licence year ceiling is reached | ePrivacy Directive Art. 13(2) "soft opt-in" (existing customer, similar product, opt-out in every message) | Until you opt out |
Country-code derivation. Where we record a country code — Order.country_code, collected at checkout for VAT compliance — it is determined from the billing details you provide at checkout and our VAT provider's assessment at that moment. We do not operate a GeoIP database, we do not derive country from raw IP addresses in our application code, and we do not use any content-delivery-network geo-header for this purpose. Raw IP addresses appear only in W4 server access logs (30 days, truncated where operationally feasible).
Legitimate interests (W4, W5): for the legitimate-interests flows we maintain documented Legitimate Interests Assessments (LIAs) covering purpose, necessity, and balancing. We can summarise them on request.
3.2 Cookies
The website uses only strictly necessary cookies that are exempt from consent under Article 11.7a(3) of the Dutch Telecommunications Act (implementing Article 5(3) of the ePrivacy Directive 2002/58/EC):
sessionid— keeps you logged in after you click a magic link; expires when your session endscsrftoken— protects against cross-site request forgery; expires when your session endsmessages— set only when our framework needs to display a one-time notice (e.g., "your email change has been confirmed") that survives a redirect; deleted automatically as soon as the message is shown
We do not use analytics cookies, advertising cookies, or any third-party tracking. No cookie banner is shown because none is required for strictly necessary cookies.
3.3 Recipients (third parties we share data with on the website side)
We use a small number of third parties to operate the website, in the categories below. The specific provider engaged in each category — its identity, role, jurisdiction, regulator, and the transfer basis where it sits outside the EEA — is listed in Annex A, which is kept current and separately dated. Each provider has its own privacy policy.
- Hosting and managed database — a processor that hosts the application and its database in the EU.
- Transactional email — a processor that delivers licence keys, receipts, and operational notices. Where this provider is outside the EEA, the transfer is governed by the EU Standard Contractual Clauses and supplementary measures as appropriate.
- Payment processing — one or more payment providers who act as independent controllers for the payment leg, not as our processors, because they determine the means and purposes of their own AML, KYC, and payment-compliance processing and are answerable to their own financial regulators. We are not party to the payment transaction and do not receive your wallet address, transaction graph, or any KYC output. Annex A names the currently engaged provider(s), their regulator(s), and any transaction thresholds at which they may apply identity verification.
We do not sell, rent, or trade your personal data.
3.4 International transfers
The hosting region is the EU. Where transactional email is processed by a US provider, transfers occur under the EU Standard Contractual Clauses (SCCs) and supplementary measures as appropriate.
3.5 Data subject rights (website)
You have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erasure ("right to be forgotten"), subject to the 7-year tax-retention legal obligation that applies to invoice records (Art. 17)
- Restrict processing in specified circumstances (Art. 18)
- Data portability — receive your account data (email, purchase history, licence identifiers, referral code) in a structured, commonly used, machine-readable format (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent where processing is based on consent (Art. 7(3))
- Lodge a complaint with a supervisory authority
Exercise any of these rights by emailing privacy@bitcoinproof.io. We respond within one month (Art. 12(3)).
Self-serve data export. If you have an active account, you can also generate your portability export yourself at any time — visit bitcoinproof.io/account, find the "Your data" panel, and click "Download my data." We deliver a JSON file containing your account record, orders, licence keys, downloads, email-log references, attribution (if any), and partner profile (if any). The file includes an export_metadata envelope explaining what is and is not included; some additional data we hold about you is governed by legal obligations (e.g. tax records) and is available via Article 15 access requests but not in the portability export.
When you ask for erasure: we delete your account email and marketing preferences immediately; we move your invoice records to restricted-processing under Article 18 for the remainder of the 7-year tax-retention period (Article 17(3)(b) legal-obligation exception); we purge any server access logs associated with your IPs within the next 30-day rolling deletion cycle; we delete referral linkage once any outstanding commission is settled.
Erasure is implemented as a tombstone procedure. Your account row is not hard-deleted — instead, it is marked erased, your email and account-level personal data are scrubbed, and the invoice and licence-key records that we are legally required to keep for tax purposes remain linked to the tombstoned record. This is the only way to satisfy GDPR Article 17 and Article 17(3)(b) tax-retention simultaneously without breaking the integrity of the invoice audit trail. The erased account cannot be re-used or recovered.
Partner contact-email scrubbing. If You participate in our referral programme as a Partner and You exit the programme — whether by Your own choice via the "Permanently disable referral account" control in /account (legal-tos.md clause 11.6), by founder-initiated lifecycle transition, or as the cascade effect of an account-erasure request — Your partner contact email is scrubbed immediately on exit (replaced with a placeholder address). Your partner name is retained for audit-trail readability against any commissions that vested before exit; Your payout address is retained until any final outstanding payout settles, then scrubbed. This is a privacy-minimisation step beyond what GDPR strictly requires.
Partner records in pending_activation (never-activated). Where Your Partner record was automatically created alongside Your customer Account (legal-tos.md clause 11.7) and You never explicitly activated it — and accordingly no commission ever vested against it — Your Partner record and its referral code are hard-deleted at the time of account erasure. There is no audit obligation to preserve a never-paid-out Partner record, and hard deletion is the cleanest privacy outcome for this case.
4. The desktop application (BitcoinProof software)
4.1 What stays on your computer (and never leaves)
The application is local-first. The following data is stored only on your computer and is never transmitted to us or to any third party:
- Wallet descriptors and extended public keys (xpubs) you enter
- Bitcoin addresses derived from those descriptors
- UTXO data, transaction history, balances
- Identity fields (legal name, address, identifier label and value) you optionally enter on entity profiles
- Generated PDF reports and CSV exports
- Snapshot history, scan history, settings
When you uninstall the application, all of this data is deleted from your computer with it. This is your primary erasure mechanism for application data.
4.2 The three outbound calls the application does make
Although the application is local-first, three categories of outbound HTTPS request occur in the course of normal operation. We disclose all three precisely.
4.2.1 Block-explorer queries (Bitcoin script hashes)
When you scan a wallet, the application contacts a Bitcoin block-explorer service to retrieve transaction history. The application ships with a default endpoint, which is identified in the application before any scan and named in Annex A. You can change it to any Esplora-compatible endpoint in the application Settings — a different public block explorer or your own self-hosted node.
What is sent: Bitcoin script hashes derived from your wallet descriptor (used by the Esplora protocol to look up transaction history without revealing addresses directly), plus your IP address and user agent visible to the HTTPS counterparty.
What is not sent: wallet descriptors in plaintext, extended public keys, raw addresses, identity fields, or report contents.
Lawful basis (where GDPR applies to you): Article 6(1)(b) — performance of the service you requested. The scan only happens when you click "scan."
Recipient role: the block-explorer operator is an independent controller for the data it receives. We do not have, and could not appropriately have, an Article 28 processor agreement with a public block explorer.
International transfer: the endpoint the application queries is the one you have selected. Where you leave the shipped default in place, its operator, corporate seat, and the Article 45 GDPR adequacy basis for that transfer are stated in Annex A. Where you select a different public endpoint, the choice of counterparty — and therefore the destination of the transfer — is yours. A self-hosted endpoint involves no transfer to a third party at all.
Notice on script-hash personal-data classification: under the Breyer (C-582/14) line of CJEU case law, reaffirmed in EDPS v SRB (C-413/23 P, September 2025), the combination of your IP and a Bitcoin script hash may constitute personal data because chain-analysis and exchange-KYC correlation are not "disproportionately difficult" means of re-identification. We treat this transfer as personal-data processing, which is why it is disclosed to you here in detail.
4.2.2 Licence validation pings
The application periodically retrieves https://bitcoinproof.io/licenses.json to validate licence keys.
What is sent (intentionally): the request itself — no licence key, no email, no wallet data is transmitted in the request body.
What is auto-logged on our server: your IP address, user agent, and timestamp.
Lawful basis: Article 6(1)(f) legitimate interests — operational security, abuse prevention, availability monitoring. Breyer establishes that server-side IP logging for security is a permitted legitimate interest and Recital 49 GDPR expressly recognises this.
Retention: 30 days, then deleted (see W4 in section 3.1 above).
Note: the desktop application supports a 30-day offline grace period, so brief network outages or extended offline use do not invalidate your activated licence keys.
4.2.3 Version checks
The application periodically retrieves https://bitcoinproof.io/version.json to check for updates.
The disclosure mirrors 4.2.2: nothing identifying about you is sent intentionally; our server auto-logs IP, user agent, and timestamp; the lawful basis is Article 6(1)(f) legitimate interests for operability of the update endpoint; retention is 30 days.
4.3 No telemetry, no analytics, no crash reporting
The application does not contain any telemetry, analytics, or crash-reporting components. We do not know which features you use, how long you use the application for, or how many entities or descriptors you have. We do not collect crash reports.
4.4 Erasure for the desktop application
Because all application data is local, you erase it by uninstalling the application and deleting any reports or exports you generated. The three outbound calls described in section 4.2 leave server-side access-log traces that are subject to the 30-day rolling deletion. To purge server logs for your IPs sooner, email privacy@bitcoinproof.io.
5. Tor and proxy support
The application's block-explorer client supports an optional SOCKS5 proxy URL, allowing you to route block-explorer queries through Tor or another proxy of your choice if you wish to obscure your IP from the block-explorer operator. This is a privacy enhancement we make available; we do not collect, log, or process any data about whether you use it.
6. Children
The website and the application are not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@bitcoinproof.io and we will delete it.
7. Norway (EEA)
Norway implements GDPR via the Personopplysningsloven; no separate Norwegian privacy notice is required. The supervisory authority is Datatilsynet (datatilsynet.no). You have the same rights described in section 3.5 and may complain to Datatilsynet directly.
8. Switzerland
Switzerland is not in the EEA, but the new Swiss Federal Act on Data Protection (revFADP / nFADP, in force 1 September 2023) is GDPR-aligned. The Swiss supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC) (edoeb.admin.ch). Swiss-resident data subjects have rights substantially equivalent to those in section 3.5. Cross-border transfers from Switzerland to the EU are recognised under Swiss adequacy lists. You may complain to the FDPIC directly.
9. Australia
The Australian Privacy Act 1988 (Cth) jurisdictionally reaches us where we sell to Australian users. We rely on the small business operator exemption in section 6C of the Privacy Act (annual turnover ≤ AUD 3 million; this exemption was not repealed by the Privacy and Other Legislation Amendment Act 2024 and remains in force as at the date this policy was last updated). The exemption is preserved by two design choices: (a) we monitor and remain below the AUD 3M turnover threshold; and (b) the referral programme provides referrers with aggregated attribution data only ("your code generated N sales totalling X EUR"), never identifiable customer data — preventing any "trade in personal information" disqualification under section 6D.
If we ever exceed the AUD 3M threshold, or if the exemption is repealed by future amendment, this policy will be updated to add a full Australian Privacy Principles (APPs) section in advance of the change.
Even where the small business operator exemption applies, the statutory tort for serious invasions of privacy (in force 10 June 2025) and Australian anti-doxxing offences continue to apply. Australian users may contact us at privacy@bitcoinproof.io with concerns; the Office of the Australian Information Commissioner (OAIC) is the relevant authority.
10. Security
We apply technical and organisational measures appropriate to the risk, including: HTTPS for all website traffic; magic-link authentication (no passwords stored); encrypted database storage at the hosting layer; access controls on production systems; minimum-data architecture (we do not collect what we do not need); 30-day rolling deletion of server access logs; and the local-first architecture of the desktop application, which keeps wallet data off our infrastructure entirely.
We notify the Dutch AP and affected data subjects of any personal data breach within the timelines required by Articles 33 and 34 GDPR.
11. Changes to this policy
We may update this policy. This policy applies from the moment it is published here — the "Last updated" date at the top of the document changes whenever we amend it, and the previous versions are archived at bitcoinproof.io/privacy/history. Material changes are notified to registered account holders by email at least 30 days before they take effect.
12. Complaints
If you believe we have processed your personal data unlawfully or you are dissatisfied with our response to a rights request, you may complain to:
- The Dutch Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl — our lead supervisory authority
- Or the supervisory authority of your country of habitual residence (in Norway, Datatilsynet; in Switzerland, the FDPIC; in Spain, the Agencia Española de Protección de Datos; in Australia, the OAIC)
You may also bring a complaint to a court of competent jurisdiction.
Annex A — Named third parties and transfer bases
Annex revision: 2026-07-29. The body of this Privacy Policy is Version 1.0; this annex is dated and revised independently of it.
This annex is the single home for the identity of the specific third parties that the rest of this policy — and the EULA (clause 5.1(a)) and the Terms of Service (clauses 1.4, 1.5, and section 6) — refer to by category. Because those documents name providers only by category and rely on this annex for the specific party, updating this annex to reflect a change of provider does not alter the operative text of the Privacy Policy, the EULA, or the ToS, is not a "material change" under section 11, and does not require you to re-accept the EULA or ToS. Each named provider has its own privacy policy.
A.1 Website — processors and payment providers
| Category | Currently engaged | Role | Jurisdiction | Transfer / regulator basis |
|---|---|---|---|---|
| Hosting and managed database | Railway | Processor | EU (deployment region) | No transfer — EU region |
| Transactional email | Postmark (Wildbit, LLC) | Processor | US | EU Standard Contractual Clauses + supplementary measures |
| EUR payment (Business tier) | Mollie B.V. | Independent controller (payment leg) | Netherlands (EU) | No transfer — EU; regulator De Nederlandsche Bank (DNB) |
| Bitcoin payment | None currently engaged — Bitcoin payment is not offered at this time | Independent controller (payment leg), once engaged | — | On engagement, this row records the provider, its home regulator, its MiCAR / payment authorisations, and the cumulative-value threshold at which it applies identity verification (KYC) |
Bitcoin payment is unavailable pending selection of a payment provider. Until a provider is engaged and named in the Bitcoin-payment row above, the Bitcoin-payment mechanism described in the Terms of Service section 6 is dormant. The specifics that belong in this row — regulator, authorisation numbers, and KYC threshold — are recorded here on engagement rather than in the operative text of any document, so that engaging or changing the provider is an edit to this annex alone.
A.2 Desktop application — default block explorer
| Item | Value |
|---|---|
| Shipped default endpoint | Blockstream.info |
| Operator | Blockstream Corporation |
| Corporate seat | Canada |
| Transfer basis | Article 45 GDPR adequacy decision (Canada) |
| Purpose | Retrieving Bitcoin transaction history via Esplora script-hash queries |
You may change this endpoint at any time in the application Settings. If you do, the transfer analysis in section 4.2.1 follows your selection rather than the default above, and a self-hosted endpoint involves no transfer to a third party.
End of Privacy Policy.