BitProofPrivacy Policy
Back to site

Privacy Policy

BitProof, a vbounds project · Last updated 3 August 2026 · Contact platform@vbounds.com

This describes what BitProof actually stores, not what a generic policy would allow it to store. If something below does not match what you observe in the product, that is a bug and we want to hear about it.

1. Who is responsible

vbounds is the controller for account data and for the customer data you enter into the console. Where you use BitProof to process personal data belonging to your own customers, you are the controller and we are a processor; a data-processing addendum is available on request from platform@vbounds.com.

2. What we store

AccountEmail address, display name if you give one, and the authentication record held by Firebase Authentication. Passwords are never visible to us.
WorkspaceWorkspace name, owner, and the list of member user ids.
AI systemsName, base model, use case description, deployment tier, target standard, and the endpoint URL if you supply one.
Assessment runsScenario, timestamps, the domain result map, the engine result and its signed receipt, and an error message if a run failed.
Evidence packsA snapshot of the run above, the gap list, and the tokens of links issued from it.
Share linksThe token, the relying party's name as you typed it, the expiry, the revocation state, and a read-only copy of the pack.
UploadsDocuments you upload to a workspace (policies, DPAs, incident logs), capped at 20 MB per file and restricted to pdf, txt, md, json, png and docx.

3. What we never store

4. Cookies and local storage

Firebase Authentication keeps your session in the browser's local storage (IndexedDB) so you stay signed in. We also store one preference key, bitproof:theme, for light or dark mode. Nothing else is set, and none of it is read by anyone but this site.

5. Who can read your data

6. Processors and where data lives

BitProof runs on Google Firebase: Hosting, Authentication, Cloud Firestore and Cloud Storage. Google is our sole infrastructure processor and data is held in Google Cloud regions. There is no other third party in the path — no analytics vendor, no CRM sync, no email marketing platform. Transfers outside the UK/EEA rely on the Standard Contractual Clauses in Google's terms; the DPA we sign with you names Google as the only sub-processor and we will give you 30 days' notice before adding another.

7. How long we keep it

8. Your rights

If you are in the UK or the EEA you have the right to access, correct, delete, restrict, object to and port your personal data, and to complain to a supervisory authority (in the UK, the ICO). Email platform@vbounds.com and we will respond within 30 days. We do not make automated decisions with legal effects about individuals.

9. Security

Authorization is enforced by Firestore and Cloud Storage security rules on the server, not by the browser, and every rule has an automated test with a positive and a negative case. See the security page for the detail, including how to report a vulnerability.

10. Breach notification

If personal data you entrusted to us is exposed, we will tell affected account holders and, where required, the relevant supervisory authority within 72 hours of becoming aware, with what we know at the time rather than waiting for a complete picture.

11. Children

BitProof is a business tool and is not directed at anyone under 18.

12. Changes

We post the updated date at the top of this page and email account holders about any change that materially affects them.