Policies
How keys, domains and limits work, what stays stable within a version, and what is logged when a widget loads on your site.
Embed keys are created in the embed console while signed in with a verified email address; accounts created with a crypto wallet are exempt. Free, Starter and Pro allow 2, 5 and 10 keys. A key is shown once, does not expire, and revoking it takes effect on the next load. Pass it as ?embed_key= (?api_key= still works); Data API and MCP keys are refused with 403.
Every load with a key is checked against the domains registered on your account, read from the embedding page's Referer (or Origin). The host is lower-cased and the scheme, path, port, a trailing dot and a leading www. are dropped; any other subdomain needs its own entry. Free, Starter and Pro allow 1, 3 and 10 domains.
A load without a referrer, or from a domain that is not registered, is refused with 403 - keep the browser's default referrer policy on your iframe. A domain you add works at once; removing one can take up to 5 minutes.
Each page load of a widget counts as one request, automated visitors included: Free allows 10,000 a month, Starter 50,000 and Pro 500,000. The month is the calendar month in UTC on Free and runs from your billing day on paid plans. Widgets also work without a key, up to 1,000 loads a month per visitor across every keyless widget on every site.
Over the limit, the widget shows a usage-limit page (HTTP 429) instead of the tool until the next period; there are no overage charges. Upgrades apply immediately; downgrades and cancellations at the end of the paid period, and keys and domains above a lower plan's allowance keep working, though you cannot add more.
The contract is the widget URLs under /{locale}/embed/ in any of the 27 languages, their query parameters - embed_key, compact, theme=dark, and layout and visible on the sectioned widgets - and the bitculator-embed-resize height messages. When a coin's slug changes, its old widget URL redirects with your parameters kept.
Figures are as of page load and do not update live: coin prices are recomputed every minute and fiat rates twice a day. Widgets may be framed by any site and are not indexed by search engines.
These never happen within a version:
layout and visible can name.These can happen at any time and are logged in the changelog:
Removing a widget version or lowering a limit is announced in the changelog and by email to every key owner at least six months ahead, as the terms of service set out.
Every widget carries a "Powered by Bitculator" link to the matching tool on bitculator.com, on every plan. It must stay visible and unaltered.
For each load with a key we count the account, key, embedding domain, widget and billing period, plus a daily total, and keep these counts for 12 months. Keyless loads are counted per domain and widget without the visitor's IP; the per-visitor limit uses a keyed hash of the IP that is dropped at the end of the month.
Widgets set no cookies and register no service worker. They store a visitor's own section arrangement in that visitor's browser, and send Bitculator's own analytics - a page view and page-speed measurements - identified only by a hash that changes daily and kept for up to 95 days.
If you believe you have found a security vulnerability in bitculator.com, the Data API, the MCP server or the SDKs, email contact@bitculator.com with the affected URL or endpoint, steps to reproduce and the impact you see. You will hear back within three business days.
Please keep the report private until it is fixed, do not access or alter data that is not yours, and do not run denial-of-service or automated scanning against production. Reports made in good faith under these terms will not be met with legal action. There is no paid bounty programme; credit is given on request.
The same contact is published machine-readably at /.well-known/security.txt (RFC 9116).
Live component status, open incidents and the last 30 days of outages are on the status page and at /status.json.