Get Bitculator on Android
Understand how your data is handled
Learn how Bitculator collects, uses, and protects your personal information. We prioritize transparency and privacy across all aspects of the platform.
Last updated: 2026-09-18
Privacy Notice
This notice explains what personal data Bitculator collects, why, who else receives it, how long we keep it and what you can do about it. It covers bitculator.com and everything we run on it: the market pages and tools, accounts and public profiles, membership, the data API, the MCP server, embeddable widgets, the spreadsheet add-ons, alarms, portfolios, the Trading Lab, the AI assistant, the affiliate program, sponsored placements, the shop, the marketplace, our emails and our Discord community.
The data controller - the person responsible for your data - is named at the top of this page. Bitculator is run from Denmark, so Danish and EU data protection law applies. You can reach us about anything in this notice at contact@bitculator.com.
What we collect
When you visit the site, our server records the page, the site that sent you, campaign tags in the link (and only whether an advertising click identifier was present, not its value), your browser's identification string, the site language you use, the country your connection comes from, and what you search for on the site. These visit statistics do not keep your IP address. Three other actions do store one for 90 days: clicking a result in site search, opening a coin's price-history chart, and following one of our tracked links. The server combines your IP address, browser and language with a secret that changes every day and is discarded after two days, and keeps only the resulting code, so we can count visits without recognising you from one day to the next. A small script in the page also reports which page you viewed, how long it was in front of you, how fast it loaded, your screen width in broad steps, and which links to other websites you click. It also records which steps of a purchase you reach: viewing prices, choosing a plan, signing up, and going to and returning from checkout. When you are signed in, these records carry your account number instead of the daily code.
When you create an account, we hold your username, your email address, your password (stored only as a one-way hash), your language and profile settings, anything you add yourself such as a bio or banner, when you last used the site, the date and version of the terms you accepted, and whether and when you agreed to marketing email. If you sign up with a crypto wallet instead of an email address, we store the wallet address and network you connected. If you turn on two-factor authentication, we store its secret and recovery codes encrypted. Every change to your account is logged with the IP address and browser it came from; a change of password or two-factor settings is logged only as having happened.
When you use the platform, we hold what you create: favourites, alarms and how they should reach you, portfolios with their holdings, transactions and notes, friends, quiz answers and results, game rewards, codes you redeem (and the wallet address you give us to receive a crypto prize), your votes on market sentiment, Trading Lab strategies and their simulated trades, and the questions you ask the AI assistant together with its answers.
When you use our developer products - the data API, the MCP server and widgets - we hold your keys (stored only as hashes), when each key was last used, which endpoints were called and from which website, request counts per day, the websites you register, and the webhook addresses you give us with a log of what we sent to them. A widget shown on another website runs our page script, which counts the view and its loading speed as described above, and we record which website it was shown on. A widget sets no cookies of ours and installs no offline cache on that site; if it shows live prices it opens a connection to us for them. Anonymous widget use is counted per visitor with a code derived from the IP address, not the address itself. Our Google Sheets add-on and Excel connector keep your key in your own spreadsheet.
When you buy something, Stripe handles the payment and we never see your card number. Stripe receives your username and email address, plus your account number on one-off purchases, and collects your billing name and address, which tax rules require; for physical goods it also collects the delivery address and phone number. We keep your Stripe customer reference, the card brand and last four digits, what you bought, what you paid and when it renews. For physical goods we also keep the delivery name, address and phone number and the tracking details.
When you join the affiliate program, we hold the wallet address and network your payouts go to, your country, which US tax form applies to you and whether we have confirmed it, and a record of every payout. When someone follows your link, we record the click with a code derived from their IP address and browser, not the address itself, and the page they landed on. If they sign up, their account is linked to yours.
When you advertise with us, we hold your contact email, the creative and link you submit, your budget and the Stripe payment reference.
When you write to us, by email or through the contact form, we keep your message and your email address, and for emails also the full email headers. When you subscribe to the newsletter, we keep your email address, the language, which form you used, and when you confirmed and, if you do, unsubscribed. Some older entries also hold a first name.
In our Discord server, our bot records messages and reactions posted in several channels of our server, with the Discord user and message identifiers, to run community features and giveaways. These records are not linked to Bitculator accounts. A message you delete on Discord loses its text here too.
For security, Cloudflare's human check on the sign-up forms receives your IP address. Rate limits count requests against your account when you are signed in, and against your IP address when you are not. Most windows are minutes or hours; the API quota and the anonymous widget counter run to the end of the month. Our error log can contain your account number, and if a sign-up or a wallet connection fails, the email address, username or wallet address from that attempt.
Why we use it, and on what basis
To run your account and provide what you use or paid for - signing you in, confirming your email address (with reminders until you do), applying your plan, keeping your portfolios, alarms, keys and conversations, answering your AI questions, paying affiliate commissions, delivering goods, and sending receipts and service notices. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
To keep the service secure and working - filtering bots and attacks, rate-limiting, the account change log and the error log. Legal basis: our legitimate interest in a service that stays available, is not abused and can trace unauthorised changes (Art. 6(1)(f)).
To understand how the site is used - the visit statistics described above, so we know which pages work and can fix slow or broken ones. Legal basis: our legitimate interest in running and improving the site, which we pursue without advertising trackers and without recognising signed-out visitors from one day to the next; when you are signed in, your visits are linked to your account.
To credit referrals - linking a new account to the affiliate whose link brought it. Legal basis: our contract with the affiliate, and our and the affiliate's legitimate interest in paying commissions correctly.
To run sponsored placements fairly - limiting how often a placement is shown and ignoring repeated clicks, using your account number, your session or a code derived from your IP address until the end of the day. We build no advertising profile. Legal basis: our legitimate interest in charging advertisers only for real views and clicks.
To send marketing email - only with your consent (Art. 6(1)(a)), which you can withdraw at any time without affecting earlier emails. If you bought a subscription, we may also email you about features similar to the ones you bought, based on our legitimate interest and the Danish Marketing Practices Act §10(2); you can refuse this at any time.
To tell projects we list about their listing, using the business email address the project publishes. Legal basis: our legitimate interest in keeping listings accurate and in promoting the site.
To run our Discord community and its giveaways. Legal basis: our legitimate interest in a lively community.
To answer your messages. Legal basis: steps taken at your request, our contract with you, or our legitimate interest in replying.
To meet legal duties - bookkeeping, tax and requests from authorities. Legal basis: legal obligation (Art. 6(1)(c)).
To establish or defend legal claims, keeping only what such a claim needs. Legal basis: our legitimate interest.
Where we rely on legitimate interests, we have weighed them against your interests and rights; you can ask us how. We do not sell personal data, we do not build advertising profiles, and we do not use third-party advertising or analytics trackers.
What you have to give us
You can read the site without giving us anything. To open an account we need a username and a password, plus an email address or a crypto wallet; without them we cannot create the account. To buy something, Stripe needs your payment and billing details, which payment networks and tax rules require; without them the purchase cannot go through. Everything else in your profile is optional.
Who else receives it
Service providers process data on our behalf, each under a data processing agreement and only for the job we give them:
Stripe - payments, invoices and receipts.
Mailgun - sending and receiving our email, in its EU region.
Amazon Web Services - stores images such as banners and logos in its Frankfurt region and delivers them to your browser, so it sees your IP address when they load.
Cloudflare - the network in front of the site. Every request passes through it; it filters attacks and bots and runs the human check on the sign-up forms.
OpenAI (OpenAI Ireland Ltd) - receives the question you type into the AI assistant, the conversation so far and public data about the page you are on, in order to answer. Your name, email address and account number are not sent.
Our hosting provider - runs our servers and databases.
Independent recipients receive data for their own purposes, under their own responsibility and privacy policies:
Stripe - also processes payment data for its own fraud-prevention and legal duties.
Your browser's push service (Google, Mozilla, Apple or Microsoft, depending on your browser) - delivers push notifications if you turn them on.
Google - through YouTube, when video preview images or videos load (see Content from other sites), and if you install our Google Sheets add-on, which runs in your own Google account.
Discord - hosts our community server and processes what you post there.
Carriers such as DHL or PostNord - receive the delivery name, address and phone number for physical goods.
Our accountant and the tax authorities - receive purchase records as bookkeeping and tax law require.
Some information is visible to other people by design - see the next section. Beyond that, we disclose data only where the law requires it, where it is needed to investigate fraud or abuse, or to establish or defend a legal claim. If the business were ever transferred, your data would move with it and you would be told first.
No analytics company receives anything. We measure our own traffic with software we built, running on our own servers and storing the counts in our own database. There is no Google Analytics, no tag manager and no third-party measurement anywhere on the site, and no visit data is sold, shared or sent on for analytics.
What other people can see
Your public profile can be opened by anyone with its link. It always shows your username, avatar, banner and membership plan, and its page data includes your account number. By default it also shows your level, experience, bits balance, member-since date, quizzes passed, bio, number of friends, showcase and badges, and, if you switch it on, how many people you have referred; you can hide each of these in your profile settings. Portfolios are private unless you make one public; a public portfolio always shows its name and number of holdings, and you choose what else it shows. We ask search engines not to index profiles.
Marketplace listings show your username, avatar, plan, location, terms and amounts to everyone. The contact handle you give is shown only to the person you trade with.
If you signed up through an affiliate's link, that affiliate sees a shortened form of your username (at most its first and last two characters), whether your account is verified, when you joined, and, when you buy something, which product it was and the commission it earned - from which the price can be worked out. Affiliates never see your email address.
Payouts to affiliates and crypto prizes are sent on a public blockchain, where the receiving wallet address and the amount are visible to anyone, permanently. Neither we nor anyone else can remove them.
Discord giveaway winners are mentioned by their Discord name in a public channel.
Votes on market sentiment are shown only as totals.
Where your data goes
Our file storage is in Frankfurt and our email provider stores mail in the EU. Some recipients are based in the United States or may process data there: among our service providers Stripe, Cloudflare, Amazon Web Services, Mailgun and OpenAI, and among the independent recipients Google, Discord and the browser push services. Cloudflare runs a global network, so your connection may be handled in a data centre outside the EU. For our service providers, transfers to a US company certified under the EU-US Data Privacy Framework rely on the European Commission's adequacy decision for that framework, and all other transfers rely on the Commission's standard contractual clauses in the provider's data processing terms. Independent recipients transfer data under their own safeguards, described in their privacy policies. You can ask us for a copy of the safeguards that apply to our service providers. If you would rather your questions did not leave the EU, do not use the AI assistant; the rest of the site works without it.
How long we keep it
Your account and what you create in it - until you delete it, or delete an item yourself. A deleted account can be restored for 30 days and is then erased (see Deleting your account).
Visit statistics - page visits and per-minute counts 90 days; sessions, events, searches and bot visits 95 days; page-speed samples 3 days. The daily totals we keep afterwards count visits per page, country and search term, and say nothing about who visited. The secret behind the daily visitor code is discarded after 2 days.
Account change log - 180 days. Activity log - 30 days, removed in a weekly clean-up. Error log - 14 days. Failed background jobs - 7 days. Decisions about trading bots - who started, changed, paused or stopped one - stay as that bot's history, but stop naming the person after the same 30 days.
Records that hold an IP address - clicks on tracked links and QR codes, and the search and page counts behind our trending lists - 90 days.
Referral link clicks - 12 months. Password-reset links - deleted a day after they were issued.
Rate-limit counters - minutes up to an hour; the anonymous widget counter until the end of the month; sponsored-placement limits until the end of the day.
API usage records per endpoint and per day - 12 months. Webhook delivery log - 30 days. Payment event references from Stripe - 30 days.
AI conversations - until you delete the conversation or your account. Questions asked about a coin on its page, and the answers, kept without your account number so the same answer can be reused for anyone who asks something similar - up to 30 days.
Purchase and payout records - five years from the end of the financial year they belong to, as the Danish Bookkeeping Act requires. Once an account is erased, these records no longer name the buyer; after the five years, the delivery address and payout wallet are removed as well, and only the amounts remain in our accounts. Stripe keeps its own records under its own legal duties.
Newsletter - until you unsubscribe. We then keep your address and the fact that you opted out, so we never mail you again by mistake. Addresses that were never confirmed are never mailed.
Emails and contact messages - as long as we need them to deal with the matter and any follow-up. The technical delivery data that comes with an email, including the headers that show the sending server's address, is removed after 90 days.
Discord records - 90 days.
Push subscriptions - until you turn notifications off or your browser's push service reports the subscription as gone.
How we protect it
The site is served over HTTPS only. Passwords are stored as one-way hashes; two-factor secrets and webhook secrets are encrypted; API, MCP and widget keys are stored as hashes and shown to you only once. Card details never reach our servers. The back office is restricted, and changes made there are logged. Traffic is filtered by Cloudflare before it reaches us, and sign-in, sign-up and our APIs are rate-limited. No system is perfectly secure. If a breach is likely to put your rights at risk, we will report it to the Danish Data Protection Agency within 72 hours and tell you without undue delay, as the law requires.
Content from other sites
Pages that show YouTube videos - video tutorials, the video tabs of coins, exchanges and wallets, and some articles - display preview images that load directly from YouTube as soon as they appear on screen, so Google receives your IP address and browser details at that moment. The video itself loads only when you press play, after which YouTube may set its own cookies under Google's privacy policy. When you connect a crypto wallet, the connection runs through your wallet software. Links to other websites are not covered by this notice; read theirs.
Emails we send
Service emails go to every account holder because the service needs them: confirming your email address (with reminders after 1, 7 and 30 days until you do), password resets, security notices, receipts and messages about your purchases and alarms. You cannot switch these off while you have an account.
Marketing emails - newsletters, offers and news - are sent only if you asked for them: by ticking the box when you signed up, or by confirming a newsletter subscription through the link we email you. An address that has not been confirmed is never mailed.
If you bought a subscription, we may now and then email you about features similar to the ones you bought. You can refuse these at any time by writing to contact@bitculator.com, and every such email will carry an unsubscribe link.
If you run a project we list, we may email the business address your project publishes to tell you about the listing and ask for a link back. Reply that you do not want this, and we will remove the address from our records.
Every marketing email tells you how to opt out, and opting out is free.
Your right to object to marketing
You can object at any time to our use of your data for direct marketing, including the customer and project emails described above. When you object, we stop - without asking for a reason and free of charge. Use the unsubscribe link in the email, switch off Email preferences in your profile if you turned it on, or write to contact@bitculator.com.
Automated decisions
We do not profile you for advertising. Two things happen automatically and can affect you: Cloudflare's human check can stop a sign-up it considers automated, and if a subscription payment fails and Stripe confirms it is still unpaid, your plan drops to the free tier until the payment goes through. Both are needed to keep the service secure and to perform the contract. If either affects you, write to us: a person will review it, and you can explain your side and contest the result.
Your rights
Under the GDPR you have the right to:
- access the data we hold about you and receive a copy;
- have it corrected;
- have it erased;
- restrict what we do with it;
- receive the data you gave us in a machine-readable format and have it passed to another provider (portability);
- object to processing we base on our legitimate interests - we then stop unless we have compelling grounds or need the data for a legal claim;
- withdraw consent at any time, without affecting what we did before.
To use a right, write to contact@bitculator.com from the email address on your account, or give us your username and wallet address. We may ask you to confirm your identity before we act. We answer within one month; if a request is complex, we may extend that by two further months and will tell you why within the first month. Using your rights is free, unless a request is manifestly unfounded or excessive.
Deleting your account
You can delete your account yourself in your profile settings. We ask for your password, cancel any subscription so you are not billed again, end your paid plans, sign you out and hide your profile straight away.
For the next 30 days you can change your mind: sign in and choose Restore account. Paid plans do not come back, but you can subscribe again.
After 30 days we erase your personal data for good: your email address, username, password, two-factor settings, profile, banner and payout details, your portfolios, alarms, favourites, friends, quiz results, AI conversations, API, MCP and widget keys, webhooks, push subscriptions, referral clicks, the history of changes to your account and your activity log. Changes you made to other records stay in their history without your name or IP address. Your visit statistics are detached from your account.
What remains is an account number that no longer identifies anyone. Purchase and payout records stay attached to it for the bookkeeping period described above, and so do records that mean nothing without you, such as game items, rewards, votes and Trading Lab strategies. Stripe keeps its own record of your payments. A newsletter subscription is separate from your account: unsubscribe with the link in any newsletter.
You can also ask us to delete your account by writing to contact@bitculator.com from the email address on it.
Complaints
If you think we are handling your data wrongly, tell us first at contact@bitculator.com and we will try to put it right. You can also complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, www.datatilsynet.dk. If you live in another EU or EEA country, you may complain to the supervisory authority there instead.
Children
Bitculator is not intended for children. Our terms require account holders to be at least 18, and we do not knowingly collect data from anyone younger. If you believe a child has given us data, write to contact@bitculator.com and we will delete it.
Changes to this notice
We update this notice when what we do changes - a new service provider, a new feature, a different retention period. The date at the top of the page shows which version you are reading. If a change materially affects you, we will announce it on the site and email account holders before it takes effect.
Contact
Questions about this notice or about the data we hold on you: contact@bitculator.com. Our name and postal address are at the top of this page. We have not appointed a data protection officer, as the law does not require one for an operation of our size and kind, so your message reaches us directly.