Privacy policy

Last updated: 19 September 2026 · Under the Swiss Data Protection Act (DSG) and, for people in the EU, the General Data Protection Regulation (GDPR)

1. Controller

The controller responsible for processing your personal data on bitledger.app is:

Summit Accounting GmbH

Grienmattweg 38, 4450 Sissach, Switzerland

Email for data protection matters: datenschutz@bitledger.app

2. What data we process and why

2.1 Waitlist

If you sign up for the waitlist on the home page, we store your email address, the exchange you selected and the time of sign-up. We use this only to send you a confirmation and, later, your invitation. Legal basis: your request (Art. 6(1)(b) GDPR). We delete the entry as soon as you open an account or ask us to, and at the latest 24 months after you signed up.

2.2 Account and profile

For your account we store your email address and your password (only as a cryptographic hash). You may optionally provide your name, address, tax identification (AHV number or tax ID/tax number), canton or federal state, and tax settings; these appear on your tax reports. Legal basis: contract (Art. 6(1)(b) GDPR).

2.3 Wallets and transactions

The wallet addresses you add and their associated transactions (time, amounts, tokens, counterparty addresses, fees) are retrieved from the data providers listed in section 4 and stored together with prices and classifications. The same applies to data you import from an exchange. This is necessary to calculate your portfolio and tax report. Legal basis: contract.

Blockchain transactions are public. By linking them to your account, however, they become attributable to you; we share this attribution only with the service providers listed in section 4, and only as far as necessary to provide the service.

2.4 Payments

Payments are handled by Stripe. We store only your Stripe customer number and your plan; we do not receive card details. We keep invoicing and accounting records for the statutory period of 10 years (Art. 958f CO).

2.5 Emails

We send emails that are necessary for your account (confirmation, password reset), as well as notifications about completed syncs and finished reports. You can turn the notifications off in the settings. We do not send marketing emails.

2.6 Server logs and error monitoring

When you visit the website, our servers process technically necessary data (IP address, time, requested address, browser identifier) in order to deliver the page, limit abuse (rate limits) and fix faults. These logs are automatically deleted after a short time. If a technical error occurs, we send an error report to Sentry — without IP address, cookies or account data. We do not record sessions. Legal basis: legitimate interest in a secure and functioning service (Art. 6(1)(f) GDPR).

2.7 Support and problem reports

If you report a problem using the “Report a problem” button, we store your message, your email address, the page you were on, your language setting, the id of the last failed request and your browser identification. We need these details to find the event in our logs and to reply to you. No wallet keys and no transaction data are transmitted. Legal basis: handling your request (Art. 6(1)(b) GDPR) and our legitimate interest in a working service (lit. f). We delete reports at the latest 24 months after they are closed, and immediately if you delete your account.

Where we need to look at your account to handle a report, that view is limited to operational details (for example the number of transactions or the status of a sync); the figures in your tax reports are not shown. Every access to an individual account is logged.

3. Cookies and local storage

We use only what is necessary for the website to function, and therefore no cookie banner:

  • Authentication cookies (sb-…-auth-token): keep you signed in and secure the password-reset link. Deleted when you sign out or when the session expires.
  • Language (cookie locale): remembers the language you chose for one year.
  • Appearance (local storage bl-theme): remembers whether you chose the light or dark theme.

We use no analytics, tracking or advertising cookies, and we embed no third-party content (e.g. fonts, videos, social networks).

4. Service providers and transfers abroad

We use the following service providers. They process data only on our behalf and on our instructions (data processing, Art. 9 DSG / Art. 28 GDPR):

ProviderPurposeDataLocation
Supabase Inc.Database, sign-in, storage of tax reportsAll account, wallet and transaction dataServers: London (UK); company: USA
Railway CorporationOperation of the web and API serversAll data transmitted through the app, server logsServers: Amsterdam (EU); company: USA
Resend (Plus Five Five, Inc.)Sending emails (sign-in, password, notifications, waitlist)Email address, email contentSent via Ireland (EU); company: USA
Anthropic PBCAI-assisted tax classification (see section 5)Transaction data without name, email or addressUSA
Covalent (GoldRush)Retrieval of on-chain transactions (EVM chains)Wallet addressesUSA
Helius Labs, Inc.Retrieval of on-chain transactions (Solana)Wallet addressesUSA
Payward, Inc. (Kraken)Import of your Kraken transactions, only if you store an API keyYour Kraken API key (stored encrypted by us)USA
StripePayment processing and subscription managementEmail address, payment data (only at Stripe)Ireland (EU) / USA
Functional Software, Inc. (Sentry)Detection of technical errorsTechnical error data, without IP address and without user dataStorage: Frankfurt (EU); company: USA
Crisp IM SASLive chat inside the signed-in app — loaded only when you explicitly open the chatYour chat messages, email address (if given), IP addressFrance (EU)

We obtain exchange rates from CoinGecko as well as from the Swiss National Bank and the European Central Bank. In doing so we transmit only token symbols and dates, no personal data.

For transfers to the USA we rely, where the provider is certified, on the Swiss-U.S. and EU-U.S. Data Privacy Framework, and otherwise on the European Commission's standard contractual clauses with the adaptations required for Switzerland. For the United Kingdom an adequacy decision is in place. A copy of the safeguards is available on request.

5. AI classification

To classify transactions for tax purposes, we send Anthropic transaction data (hash, time, tokens, amounts and values, transaction type) as well as your tax country. We do not send your name, email address, wallet addresses or home address. Under its commercial terms, Anthropic does not use this data to train its models.

The classification is a suggestion, not a decision with legal effect for you: you see and correct every result yourself before you use a report. It is not tax advice.

6. Retention and deletion

We store your data for as long as your account exists. Under Settings → Delete account you can delete your account yourself at any time. When you do, we immediately delete your profile, all wallets, transactions, classifications, tax reports and your waitlist entry, and end any active subscription. Data disappears from backups as they are overwritten, and at the latest after 30 days. Accounting records that we are required by law to keep are excluded (section 2.4).

7. Security

All connections are encrypted (HTTPS). Access to data is restricted per account in the database, we store passwords only as a hash, and we additionally encrypt any stored exchange API keys.

8. Your rights

  • Access to your data (Art. 25 DSG / Art. 15 GDPR)
  • Rectification of inaccurate data — most of it directly in the settings (Art. 32 DSG / Art. 16 GDPR)
  • Erasure — yourself under Settings → Delete account (Art. 32 DSG / Art. 17 GDPR)
  • Portability of your data in a common format — transactions as CSV directly in the app (Art. 28 DSG / Art. 20 GDPR)
  • Restriction and objection (Art. 18 and 21 GDPR)

Write to us at datenschutz@bitledger.app. We respond within 30 days and, for security, may ask you to prove that you are the account holder.

You may also lodge a complaint with a supervisory authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), and in the EU with the authority of your country of residence (in Germany the state data protection authority, in Austria the Data Protection Authority).

9. Changes

We update this policy when the service changes. The current version at bitledger.app/datenschutz applies. We inform account holders of material changes by email.