Privacy Policy
What we collect, why, and what we do with it. The short version: we never receive your private keys or seed phrases, and we treat your wallet metadata as sensitive financial data.
Last updated: 21 July 2026
1. Who is responsible for your data
The controller of your personal data is ValueActive Solutions B.V., trading as Keystody.
ValueActive Solutions B.V.trading as Keystody
Amsterdam, Netherlands
Chamber of Commerce (KvK): 97533424
VAT: NL868095898B01
Email: info@keystody.com
For privacy matters specifically, contact info@keystody.com.
2. What we never collect
We never collect, receive, request or store private keys, seed phrases, BIP39 passphrases, or hardware wallet PINs. These must never be entered into Keystody. If any website or person claiming to be Keystody asks you for them, it is not us.
3. What we collect, and why we need each thing
Every category below is listed with the specific reason we need it. If a reason ever stops applying, we stop collecting the data.
Account data
- What:
- Your email address, your name, and authentication data. Sign-in is handled by AWS Cognito.
- Why we need it:
- We need to know who you are so we can give you access to your own vaults and nobody else's, and so we can reach you about your account. Your email is also the address recovery and invitation flows use.
- Legal basis:
- Performance of our contract with you — GDPR Art. 6(1)(b).
Wallet metadata
- What:
- Extended public keys (xpubs), output descriptors, derivation paths, master fingerprints, address indexes, vault configuration and transaction history.
- Why we need it:
- This is what makes the product work. Descriptors and xpubs let us derive your receive addresses, show your balances, and construct unsigned transactions for you to sign. Without them we would have nothing to display and nothing to build a transaction from. None of it can spend your Bitcoin — but it does reveal your balances and activity, so we encrypt it at rest with AWS KMS, restrict and audit access to it, and never write it to application logs.
- Legal basis:
- Performance of our contract with you — GDPR Art. 6(1)(b).
Hardware wallet and device data
- What:
- The manufacturer and model of the hardware wallets you register, and the verification status of each key.
- Why we need it:
- Different devices behave differently, so we need to know what you are using to give you the right signing instructions. Verification status is what lets us tell you which keys have been confirmed on-device and which still need checking — the core of the recovery readiness score.
- Legal basis:
- Performance of our contract with you — GDPR Art. 6(1)(b).
Billing data
- What:
- Subscription status, plan, and invoice history. Card details are handled entirely by Stripe and never reach our servers.
- Why we need it:
- To take payment, to apply the right plan limits, and because Dutch tax law requires us to keep accurate records of what we invoiced and to whom.
- Legal basis:
- Performance of contract — Art. 6(1)(b) — and legal obligation for tax records — Art. 6(1)(c).
Security and audit logs
- What:
- IP address, browser and device information, sign-in events, and a record of significant actions taken in your account.
- Why we need it:
- To detect and investigate unauthorised access to your account, and to give you an audit trail of who did what in a shared vault. In a multi-person vault, being able to see that a co-signer changed something is a safety feature, not surveillance.
- Legal basis:
- Our legitimate interest in operating a secure service, and yours in an account that cannot be quietly tampered with — Art. 6(1)(f).
Service communications
- What:
- The email address we send operational messages to, and a record of what we sent.
- Why we need it:
- To tell you about security events, verification that has fallen overdue, invitations, and changes to the service. These are part of the product — a governance tool that never tells you anything is not doing its job.
- Legal basis:
- Performance of contract — Art. 6(1)(b) — and legitimate interest in keeping you informed about your own security — Art. 6(1)(f).
Marketing email
- What:
- Your email address, only if you have asked to hear from us.
- Why we need it:
- To send you things like product updates or writing about self-custody. This is entirely optional and separate from service communications.
- Legal basis:
- Your consent — Art. 6(1)(a). You can withdraw it at any time, and withdrawing does not affect anything we sent before.
Correspondence
- What:
- What you send us by email, or through a setup call booking.
- Why we need it:
- To answer you, and to keep enough of a record that you do not have to explain your situation from scratch the next time you write.
- Legal basis:
- Legitimate interest in providing support — Art. 6(1)(f).
4. Who processes data on our behalf
We use a small number of processors, each under a data processing agreement:
- Amazon Web Services (AWS) — hosting, database, encryption (KMS), authentication (Cognito) and transactional email (SES). Data is hosted in the EU.
- Stripe — payment processing and subscription billing.
We do not sell your personal data and we do not share it with advertisers.
To show your balances, our servers query Bitcoin blockchain data. Bitcoin transactions are recorded on a public ledger that we do not control and cannot amend or erase.
5. International transfers
We keep personal data in the EU where we can. Where a processor transfers data outside the EEA, that transfer relies on an adequacy decision or on the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures.
6. How long we keep it
Account and wallet metadata: for as long as your account is open, and for a limited period afterwards so you can reactivate or export. Billing records: seven years, as Dutch tax law requires. Security and audit logs: as long as needed for security purposes. Marketing consent records: until you withdraw consent.
You can ask us to delete your account and we will, subject to records we are legally required to keep.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased, where the grounds apply;
- restrict how we process it;
- receive your data in a portable format, and have it transmitted to another controller;
- object to processing based on our legitimate interests; and
- withdraw consent at any time, without affecting processing already carried out.
To exercise any of these, email info@keystody.com. We respond within one month.
You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
8. Security
Wallet metadata is encrypted at rest with AWS KMS. Access to production systems is restricted and logged. Sensitive fields are excluded from application logs. Accounts support two-factor authentication, and we encourage you to enable it.
No system is perfectly secure. The strongest protection in Keystody’s design is structural: because we never hold your private keys, a compromise of our systems cannot move your Bitcoin.
9. Cookies
We use cookies that are strictly necessary to run the service, principally to keep you signed in. We do not use advertising cookies. If we introduce analytics that are not strictly necessary, we will ask for your consent first.
10. Children
Keystody is not intended for anyone under 18 and we do not knowingly collect data from children.
11. Changes to this policy
We may update this policy. If a change materially affects how we handle your data, we will tell you by email. See also our Terms of Service.