Privacy Policy
This describes what BitProof actually stores, not what a generic policy would allow it to store. If something below does not match what you observe in the product, that is a bug and we want to hear about it.
1. Who is responsible
vbounds is the controller for account data and for the customer data you enter into the console. Where you use BitProof to process personal data belonging to your own customers, you are the controller and we are a processor; a data-processing addendum is available on request from platform@vbounds.com.
2. What we store
| Account | Email address, display name if you give one, and the authentication record held by Firebase Authentication. Passwords are never visible to us. |
| Workspace | Workspace name, owner, and the list of member user ids. |
| AI systems | Name, base model, use case description, deployment tier, target standard, and the endpoint URL if you supply one. |
| Assessment runs | Scenario, timestamps, the domain result map, the engine result and its signed receipt, and an error message if a run failed. |
| Evidence packs | A snapshot of the run above, the gap list, and the tokens of links issued from it. |
| Share links | The token, the relying party's name as you typed it, the expiry, the revocation state, and a read-only copy of the pack. |
| Uploads | Documents you upload to a workspace (policies, DPAs, incident logs), capped at 20 MB per file and restricted to pdf, txt, md, json, png and docx. |
3. What we never store
- Model weights. The verification engine runs in your browser; tensors are not uploaded.
- API keys, tokens or passwords for your systems. There is no field for them. The console rejects an endpoint URL that carries a credential in its userinfo or query string.
- Prompts and completions from your production traffic. BitProof does not sit in your inference path.
- Advertising or cross-site tracking data. There are no third-party analytics, advertising or session-replay scripts on this site, and no cookie banner because there is nothing to consent to beyond the sign-in session itself.
4. Cookies and local storage
Firebase Authentication keeps your session in the browser's local storage (IndexedDB) so you
stay signed in. We also store one preference key, bitproof:theme, for
light or dark mode. Nothing else is set, and none of it is read by anyone but this site.
5. Who can read your data
- Members of your workspace, enforced by server-side security rules — membership is a list on the workspace document and only its owner can change it.
- Anyone holding a share link you issued, for as long as it is live: they see the pack snapshot, the system description, the relying party's name and the issue and expiry dates. They do not see your other systems, runs, packs or uploads. Do not put anything in a system description that you would not show a relying party.
- vbounds staff, only where necessary to operate or support the service.
6. Processors and where data lives
BitProof runs on Google Firebase: Hosting, Authentication, Cloud Firestore and Cloud Storage. Google is our sole infrastructure processor and data is held in Google Cloud regions. There is no other third party in the path — no analytics vendor, no CRM sync, no email marketing platform. Transfers outside the UK/EEA rely on the Standard Contractual Clauses in Google's terms; the DPA we sign with you names Google as the only sub-processor and we will give you 30 days' notice before adding another.
7. How long we keep it
- Account and workspace data: while the account is open.
- Runs, packs and share documents: until you delete the system they belong to. Deleting a system removes its runs, its packs and the share links issued from them.
- After you ask us to close an account: deleted within 30 days, except where we must keep billing records for statutory periods.
8. Your rights
If you are in the UK or the EEA you have the right to access, correct, delete, restrict, object to and port your personal data, and to complain to a supervisory authority (in the UK, the ICO). Email platform@vbounds.com and we will respond within 30 days. We do not make automated decisions with legal effects about individuals.
9. Security
Authorization is enforced by Firestore and Cloud Storage security rules on the server, not by the browser, and every rule has an automated test with a positive and a negative case. See the security page for the detail, including how to report a vulnerability.
10. Breach notification
If personal data you entrusted to us is exposed, we will tell affected account holders and, where required, the relevant supervisory authority within 72 hours of becoming aware, with what we know at the time rather than waiting for a complete picture.
11. Children
BitProof is a business tool and is not directed at anyone under 18.
12. Changes
We post the updated date at the top of this page and email account holders about any change that materially affects them.