
Privacy Policy
Effective September 8, 2026
Last updated September 8, 2026
Version 2026-09-08
Your privacy matters to ₿Hold. This Privacy Policy explains what information ₿Hold collects and processes, why we use it, when third-party service providers process information, and what happens when you delete your account.
We aim to collect and retain only the information reasonably necessary to operate ₿Hold and ₿Hold+.
1. Information we store
Account information
When you create a ₿Hold account, we store:
- an internal ₿Hold account identifier;
- a display name, if one is associated with your account; and
- the date your account was created.
₿Hold does not maintain a password database. Authentication is handled through supported sign-in providers.
Authentication information
You may sign in using Google or Key-Rex.
For each sign-in method connected to your account, ₿Hold stores the type of authentication provider and the unique identifier supplied by that provider that is necessary to recognize your account.
Google: Google authenticates your identity and provides information necessary for ₿Hold to verify the sign-in. A Google identity token may include an email address. ₿Hold uses that token only to verify the sign-in and does not store your Google email address in your ₿Hold account record.
Key-Rex: Key-Rex provides the public authentication identifier necessary for ₿Hold to recognize the authentication method associated with your account.
₿Hold does not receive or store passwords used with Google or Key-Rex.
Session information
When you sign in, ₿Hold uses a session cookie to keep you authenticated.
The browser receives an opaque session token. ₿Hold stores a cryptographic hash of that token, together with the information needed to associate the session with your account and determine when the session expires. The raw token is not stored in the account database.
The session cookie is HTTP-only. On the hosted service it is sent only over HTTPS.
Saved decisions
When you choose to save a calculation to My ₿Hold, we store:
- an internal decision identifier;
- the ₿Hold account associated with the decision;
- the purchase or decision name you provide, if any;
- the dollar amount entered;
- the Bitcoin market price used when the decision was saved;
- the selected time horizon;
- the date and time the decision was saved; and
- an internal identifier used to prevent duplicate saves.
Model-generated future Bitcoin prices and future dollar values are recalculated when needed rather than stored as permanent decision values.
₿Hold+ and billing information
If you subscribe to ₿Hold+, Stripe processes the payment.
₿Hold stores only the billing and subscription references necessary to determine and manage your ₿Hold+ access, including:
- whether your account has Free or Plus access;
- your Stripe customer reference;
- your Stripe subscription reference;
- subscription status;
- current billing-period end date;
- the Stripe price associated with your subscription;
- whether cancellation is scheduled at period end; and
- information necessary to manage a scheduled change between Monthly and Annual billing, if you request one.
₿Hold also records identifiers for Stripe webhook events that have already been processed so the same billing event is not processed twice.
₿Hold does not store your full payment-card number or card verification code. Payment-card information is entered into and processed by Stripe.
Legal acceptance
When you affirmatively agree to the Terms of Use and acknowledge this Privacy Policy, ₿Hold retains:
- your ₿Hold account identifier;
- the version of the Terms you accepted;
- the version of the Privacy Policy you acknowledged; and
- the date and time of acceptance.
This allows us to maintain a record of which terms applied to your account. ₿Hold does not store an IP address or device identifier as part of that acceptance record.
2. Why we use this information
We use this information only for purposes related to operating ₿Hold, including:
- creating and maintaining your account;
- authenticating you and maintaining your signed-in session;
- saving calculations you ask us to save;
- providing My ₿Hold and ₿Hold+ functionality;
- processing and administering ₿Hold+ subscriptions through Stripe;
- keeping subscription access consistent with billing status;
- preventing duplicate actions, fraud, abuse, and unauthorized access;
- maintaining records of your acceptance of applicable terms; and
- maintaining, securing, and troubleshooting the service.
₿Hold may also use short-lived request information, such as an IP address, for rate limiting. That information is used in memory for abuse prevention and is not stored in your account record.
3. Service providers
₿Hold uses third-party service providers to operate specific parts of the service.
Stripe processes ₿Hold+ payments, applicable taxes, subscriptions, invoices, and billing-management functions. Information you provide directly during Stripe Checkout is processed by Stripe according to Stripe's own terms and privacy practices.
Google provides an optional authentication method. Google processes information necessary to authenticate your Google account and provides ₿Hold with the information necessary to verify your sign-in.
Key-Rex provides an optional authentication method and provides ₿Hold with the public authentication identifier necessary to recognize your authentication method.
Cloudflare provides infrastructure used to operate ₿Hold, including application hosting and data storage. As an infrastructure provider, Cloudflare may process standard network and request information necessary to deliver, secure, and operate the service.
Coinbase and CoinGecko provide Bitcoin spot-price data requested by ₿Hold's server. Blockchain.com Charts provides Bitcoin market-price history requested by ₿Hold's server. The browser does not call those market-data providers directly.
We do not currently use a separate third-party advertising or product-analytics service. In-product ₿Hold+ insights are calculated from your saved decisions on ₿Hold's servers.
4. Selling personal information and advertising
₿Hold does not sell your personal information.
₿Hold does not currently use personal information for third-party targeted advertising.
If these practices materially change, this Privacy Policy will be updated as appropriate before the changed practices are implemented.
5. Cookies
₿Hold uses a session cookie necessary to keep signed-in users authenticated and protect account access.
We do not currently use third-party advertising cookies.
If additional non-essential cookies are introduced in the future, our disclosures and consent mechanisms will be updated where required.
6. Data retention and account deletion
We retain account information, saved decisions, subscription references, session information, and legal-acceptance records while necessary to operate your active account.
You may delete your ₿Hold account through account settings.
When account deletion is completed, ₿Hold deletes the account data associated with that account from its application database—including the account record, authentication linkages, saved decisions, sessions, billing references, and legal-acceptance records—and invalidates associated sessions.
If an active ₿Hold+ subscription exists, ₿Hold attempts to cancel the associated Stripe subscription before completing account deletion. If the billing cancellation cannot be confirmed, ₿Hold does not complete account deletion so that an active recurring subscription is not unintentionally left behind.
Deleting your ₿Hold account does not necessarily delete records independently maintained by third-party providers such as Stripe. Those providers maintain information according to their own policies and legal obligations.
7. Security
₿Hold uses reasonable technical and organizational measures designed to protect the information it maintains against unauthorized access, disclosure, alteration, or loss.
No Internet service or method of electronic storage can guarantee absolute security. Accordingly, we cannot guarantee that unauthorized access or other security incidents will never occur.
8. Your privacy choices and rights
You can delete your ₿Hold account through account settings.
Depending on where you live and applicable law, you may also have rights concerning personal information associated with you, which may include rights to access, correct, delete, or obtain certain information, or to exercise other privacy choices.
To submit a privacy request or ask a question about your information, contact bholdbtc@gmail.com.
We may need to verify that a request relates to your account before acting on it.
We will not discriminate against you for exercising privacy rights provided by applicable law.
9. Changes to this Privacy Policy
We may update this Privacy Policy when ₿Hold's features, service providers, data practices, or legal requirements change.
Material changes will be identified through an updated effective date or policy version and, where appropriate or required by law, may be presented to account holders for acknowledgment or consent.
10. Contact
For privacy questions or requests: bholdbtc@gmail.com
Related documents: Terms of Use · Refunds & Cancellation · Disclaimer