Privacy Policy
What we collect, why, and what we do with it. The short version: we never receive your private keys or seed phrases, and we treat your wallet metadata as sensitive financial data.
Last updated: 21 July 2026
1. Who is responsible for your data
The controller of your personal data is ValueActive Solutions B.V., trading as Keystody.
ValueActive Solutions B.V.trading as Keystody
Amsterdam, Netherlands
Chamber of Commerce (KvK): 97533424
VAT: NL868095898B01
Email: info@keystody.com
For privacy matters specifically, contact info@keystody.com.
2. What we never collect
We never collect, receive, request or store private keys, seed phrases, BIP39 passphrases, or hardware wallet PINs. These must never be entered into Keystody. If any website or person claiming to be Keystody asks you for them, it is not us.
3. What we collect, and why we need each thing
Every category below is listed with the specific reason we need it. If a reason ever stops applying, we stop collecting the data.
Account data
- What:
- Your email address, your name, and authentication data. Sign-in is handled by AWS Cognito.
- Why we need it:
- We need to know who you are so we can give you access to your own vaults and nobody else's, and so we can reach you about your account. Your email is also the address recovery and invitation flows use.
- Legal basis:
- Performance of our contract with you — GDPR Art. 6(1)(b).
Wallet metadata
- What:
- Extended public keys (xpubs), output descriptors, derivation paths, master fingerprints, address indexes, vault configuration and transaction history.
- Why we need it:
- This is what makes the product work. Descriptors and xpubs let us derive your receive addresses, show your balances, and construct unsigned transactions for you to sign. Without them we would have nothing to display and nothing to build a transaction from. None of it can spend your Bitcoin — but it does reveal your balances and activity, so we encrypt it at rest with AWS KMS, restrict and audit access to it. The current application is configured not to write descriptors or xpubs to application logs.
- Legal basis:
- Performance of our contract with you — GDPR Art. 6(1)(b).
Hardware wallet and device data
- What:
- The manufacturer and model of the hardware wallets you register, and the verification status of each key.
- Why we need it:
- Different devices behave differently, so we need to know what you are using to give you the right signing instructions. Verification status is what lets us tell you which keys have been confirmed on-device and which still need checking — the core of the recovery readiness score.
- Legal basis:
- Performance of our contract with you — GDPR Art. 6(1)(b).
Billing data
- What:
- Subscription status, plan, and invoice history. Card details are handled entirely by Stripe and never reach our servers.
- Why we need it:
- To take payment, to apply the right plan limits, and because Dutch tax law requires us to keep accurate records of what we invoiced and to whom.
- Legal basis:
- Performance of contract — Art. 6(1)(b) — and legal obligation for tax records — Art. 6(1)(c).
Security and audit logs
- What:
- IP address, browser and device information, sign-in events, and a record of significant actions taken in your account.
- Why we need it:
- To detect and investigate unauthorised access to your account, and to give you an audit trail of who did what in a shared vault. In a multi-person vault, being able to see that a co-signer changed something is a safety feature, not surveillance.
- Legal basis:
- Our legitimate interest in operating a secure service, and yours in an account that cannot be quietly tampered with — Art. 6(1)(f).
Service communications
- What:
- The email address we send operational messages to, and a record of what we sent.
- Why we need it:
- To tell you about security events, verification that has fallen overdue, invitations, and changes to the service. These are part of the product — a governance tool that never tells you anything is not doing its job.
- Legal basis:
- Performance of contract — Art. 6(1)(b) — and legitimate interest in keeping you informed about your own security — Art. 6(1)(f).
Marketing email
- What:
- Your email address, only if you have asked to hear from us.
- Why we need it:
- To send you things like product updates or writing about self-custody. This is entirely optional and separate from service communications.
- Legal basis:
- Your consent — Art. 6(1)(a). You can withdraw it at any time, and withdrawing does not affect anything we sent before.
Correspondence
- What:
- What you send us by email, or through a setup call booking.
- Why we need it:
- To answer you, and to keep enough of a record that you do not have to explain your situation from scratch the next time you write.
- Legal basis:
- Legitimate interest in providing support — Art. 6(1)(f).
Website analytics
- What:
- On our marketing site only: which page was viewed, the site or campaign that linked to it, the country, the browser and device type, which outgoing links were clicked, and the fact that the setup-call form was submitted — what you typed into it is not sent to the analytics provider, only that a submission happened. No cookies are set and nothing is stored on your device. The one thing the script reads from your device is an opt-out flag, which exists only if you set it yourself. Nothing follows you to any other website, and visits are not linked together across days.
- Why we need it:
- To know which of our writing is actually read and which channels bring people here, so we spend our effort where it helps. This is aggregate counting, not profiling: there is no profile, no cross-site tracking, and nothing tied to your account. What we see is how many people read a page, not who. Everything behind sign-in carries no analytics at all.
- Legal basis:
- Our legitimate interest in understanding how our own website is used — Art. 6(1)(f).
4. Who processes data on our behalf
We use a small number of processors, each under a data processing agreement:
- Amazon Web Services (AWS) — hosting, database, encryption (KMS), authentication (Cognito) and transactional email (SES). Data is hosted in the EU.
- Stripe — payment processing and subscription billing.
- NameHero — email hosting for our own mailboxes.
- Calendly — scheduling, if you book a setup call.
- Plausible — website analytics for our marketing site only. An EU company, servers in Germany. Cookieless, and it never receives anything about your account or your vaults.
We do not sell your personal data and we do not share it with advertisers.
To show your balances, our servers query Bitcoin blockchain data. Bitcoin transactions are recorded on a public ledger that we do not control and cannot amend or erase.
5. International transfers
We keep personal data in the EU where we can. Where a processor transfers data outside the EEA, that transfer relies on an adequacy decision or on the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures.
6. How long we keep it
Account and wallet metadata: for as long as your account is open, and for a limited period afterwards so you can reactivate or export. Billing records: seven years, as Dutch tax law requires. Marketing consent records: until you withdraw consent.
Operational logs are deleted after 90 days. These are the ones that contain Bitcoin addresses, alongside account and vault identifiers, request metadata and transaction ids. Ninety days is the window an incident reported well after the fact needs in order to be investigated at all.
Authentication events — sign-ins and sign-in failures — are deleted after 90 days, and are held separately from the logs above. Infrastructure build and access logs are deleted after 7 days.
Administrative and security records — who changed a permission, who was invited to a vault, who removed a member — are kept in your account’s audit history for as long as the account exists, because they are a record you can inspect and may need. They are erased when you ask us to erase your account.
One limit worth stating plainly. When you ask us to erase your data, we remove it from our database and scrub your audit history immediately. Entries already written to operational logs cannot be removed individually — that is a property of how log storage works, not a choice — so they are deleted on the 90-day clock above rather than on request.
We previously described all of this as “as long as needed for security purposes”, which is not a defined period and is weaker than you are entitled to.
Aggregate website statistics — how many visits a page, referrer or country produced — are kept for as long as they are useful to us. They are counts, not records about a person, and there is nothing in them to trace back to you.
You can ask us to delete your account and we will, subject to records we are legally required to keep.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased, where the grounds apply;
- restrict how we process it;
- receive your data in a portable format, and have it transmitted to another controller;
- object to processing based on our legitimate interests; and
- withdraw consent at any time, without affecting processing already carried out.
To exercise any of these, email info@keystody.com. We respond within one month.
You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
8. Security
Wallet metadata is encrypted at rest with AWS KMS. Access to production systems is restricted and logged. Sensitive fields are excluded from application logs. Two-factor authentication is required on every account — the API refuses requests until you have enrolled an authenticator.
No system is perfectly secure. The strongest protection in Keystody’s design is structural: because we never hold your private keys, a compromise of our systems cannot move your Bitcoin.
9. Cookies and analytics
We use cookies that are strictly necessary to run the service, principally to keep you signed in. We do not use advertising cookies, and we do not use cookies for analytics.
Our marketing site uses Plausible, a cookieless analytics tool run by an EU company on servers in Germany. It sets no cookies and stores nothing on your device, which is why you are not being asked to accept anything. It counts page views, clicks on links leading off the site, and form submissions — all in aggregate. It does not build a profile of you, does not follow you to other websites, and does not store your IP address. Everything behind sign-in — the application itself — carries no analytics at all.
An earlier version of this policy said we would ask before introducing analytics that were not strictly necessary. That sentence was written with cookie-based tracking in mind. Nothing here is placed on your device. The one thing the script reads from it is an opt-out flag, which exists only if you set it yourself — reading that is how your choice is honoured, not how you are counted. The commitment still stands for anything that does: if we ever adopt analytics that store something on your device, we will ask you first.
10. Children
Keystody is not intended for anyone under 18 and we do not knowingly collect data from children.
11. Changes to this policy
We may update this policy. If a change materially affects how we handle your data, we will tell you by email. See also our Terms of Service.