Policies
Who can ask, how question credits work, what the assistant reads and stores, and how far to trust its answers.
Asking needs a signed-in account with a verified email address; an account created with a crypto wallet and no email can ask too. No membership is required, and both Quick and Deep are open to every account. Signed-out visitors can type and look around, but sending a question asks them to create an account.
Every answer costs question credits: Quick costs 1, Deep costs 3, and asking again costs the same again. An answer that fails or comes back empty refunds its credits. Credits do not expire.
Accounts without a membership share a daily AI budget. When it is used up, questions are refused until the next day; members are not affected by it.
Answers are written by an AI model from our provider, OpenAI (see the privacy policy). For each question it receives your question, the last 10 messages of the conversation, a short summary of the page you are on, and the names of any coins, exchanges or wallets you @mention.
When a question needs them, the assistant can look up your favourites, portfolios (names, holdings, quantities, costs and values) and alarms, and those results are sent to the model as well. The assistant decides when to look them up; attaching them with the + menu makes it do so. These lookups are read-only and see only your own account.
Your username, email address and account id are never sent.
Conversations - your questions, the answers, their cards and your ratings - are kept until you delete them. Deleting a conversation removes it permanently; archiving only hides it. When you delete your account, its conversations are erased after the 30-day restore window.
For cost control we log the model, token counts and the first characters of each question and answer, without your account; these rows are deleted every day.
The assistant can prepare a price alarm, a favourite, a portfolio holding or a link to a Bitculator tool, but only as a card. Nothing is created or changed in your account until you press Confirm, and you can edit an alarm on its card first.
Bitculator AI can be wrong. Figures on its cards come straight from Bitculator's data and carry a "Data as of" time; the text around them is written by the model and should be checked before you act on it.
It is not financial advice. The assistant declines to say what to buy or sell, to predict prices or to call something a good investment, and lays out the relevant data instead.
Per account: 20 questions a minute, 5 to 500 characters per question, and up to 3 attachments and 3 @mentions per question. Pinning is limited to 3 conversations.
Changes to credit costs, plan allowances, limits and the data the assistant can read are logged in the changelog, dated, before or on the day they apply.
If you believe you have found a security vulnerability in bitculator.com, the Data API, the MCP server or the SDKs, email contact@bitculator.com with the affected URL or endpoint, steps to reproduce and the impact you see. You will hear back within three business days.
Please keep the report private until it is fixed, do not access or alter data that is not yours, and do not run denial-of-service or automated scanning against production. Reports made in good faith under these terms will not be met with legal action. There is no paid bounty programme; credit is given on request.
The same contact is published machine-readably at /.well-known/security.txt (RFC 9116).
Live component status, open incidents and the last 30 days of outages are on the status page and at /status.json.