Back to CertainKey

Privacy Policy

Last updated 31 July 2026

CertainKey produces Bitcoin proof-of-reserves reports for self-managed super funds. This policy describes what we collect, who we send it to, how long we keep it and what we delete. It is written to match what the software actually does. Where a common privacy claim would not be true of CertainKey, we say so rather than leave it out.

The short version

  • You can create an account and produce a report without giving us an email address, a name or a password.
  • Your fund and wallet details are encrypted at rest. We hold the key, so this protects against someone stealing the database, not against us. We are not a zero-knowledge service.
  • Card details never reach our servers. Stripe collects those directly.
  • Everything is deleted 90 days after you sign your report, or immediately if you press "Purge My Data". Your report's verification record is the exception, and it contains no fund or wallet data.
  • We look up your balance on a Bitcoin node we run ourselves. If it is unavailable we stop and ask before sending any address to a public block explorer, and you can decline.
  • We do not sell data, run advertising, or use third-party analytics services.

What we collect

What we do not ask for

Creating an account requires no email address, no username, no password and no personal identification. Accounts are identified by a randomly generated identifier and secured with a passkey. We have no way to email you unless you choose to give us an address.

Your account

  • A randomly generated account identifier. It is not derived from anything about you.
  • Your passkey's public key, credential identifier and signature counter. A passkey's private key stays on your device and is never sent to us.
  • If you use the recovery code option, a SHA-256 hash of that code. We never store the code itself, and we cannot recover it for you.
  • Functional cookies that keep you signed in. They are HttpOnly, Secure and SameSite-strict. We set no advertising or cross-site tracking cookies.

Your fund and wallet information

Once you begin a report we hold, encrypted at rest:

  • Fund name, ABN, trustee type and trustee names.
  • Key holder names and roles.
  • The snapshot period you selected.
  • Your wallet output descriptor, the extended public keys and derivation paths inside it, and addresses derived from them.
  • The challenge message we asked you to sign and the signatures you produced.
  • The wallet balance in bitcoin and satoshis, address counts, and the AUD price applied.

Being precise about the encryption. This data is encrypted with AES-256-GCM before it is written to disk, and the key is held by CertainKey on the server. That protects you if someone obtains a copy of the database file. It does not mean we are technically unable to read your data, and you should not treat CertainKey as a zero-knowledge service. We do not read it in the ordinary course of operating the service, but we are capable of it.

We never ask for and never receive a private key, a seed phrase or a mnemonic. A proof-of-reserves report is produced from public keys and signatures. If any page or person ever asks you for a seed phrase, it is not us.

Payment

No card details reach our servers at any point. If you pay by card, Stripe collects and processes those details directly, under Stripe's own privacy policy. If you pay with bitcoin, the invoice is handled by a BTCPay Server instance we operate ourselves. In both cases the payment processor receives the amount, the currency and your random account identifier, and nothing about your fund or wallet. Bitcoin transactions are recorded on a public blockchain, which is outside anyone's control.

If you ask for help

The signing step offers an optional prompt to leave an email address if you get stuck. It is genuinely optional and your report does not depend on it. If you use it, we store the address, the step you were on and any note you write, and we use them only to help you finish your report. They are deleted with your account.

How the product is measured

We record which step of the report process an account reached, and whether signature verification succeeded or failed. Failures are stored as short reason codes such as "signature did not verify". These records never contain an address, an extended public key, a fund name or any other detail about you or your wallet. We use them to find and fix the steps where people get stuck.

Server logs

Our web server records requests: a masked portion of your IP address, the time, the page requested, the response status and your browser's user agent. IP addresses are truncated before they are written, to the first 24 bits for IPv4 and the first 48 for IPv6, so a full address is never stored. These logs are kept for at most 90 days and are used to understand traffic volume and to investigate faults and abuse.

Who we send information to

Bitcoin address lookups, and an honest caveat

To calculate your balance we query a Bitcoin node that we run ourselves, so in normal operation your addresses are not disclosed to anyone else.

If our node is unavailable, we ask you first. We will not send your addresses to anyone else without your say-so. If our node cannot answer when you generate your report, we stop and show you a choice: continue using the public block explorers blockstream.info and mempool.space, or decline and try again later. Declining costs you nothing except the delay. We ask only when it actually happens, rather than collecting a blanket permission up front for something that is usually never needed.

If you do agree, addresses derived from your wallet descriptor are sent to those services, which are operated overseas and keep their own logs. Your name, fund details and identity are never sent, but a wallet address is linkable to on-chain history by anyone who holds it. Your decision and its timestamp are recorded against your report, and are deleted with your account.

Requests about blocks rather than addresses, such as the current block height, may use those same public services without asking, because they reveal nothing about you or your wallet.

Exchange rates

Historical bitcoin prices come from Bitaroo, with CryptoCompare as a fallback. These requests contain only a date. No personal, fund or wallet information is sent to either service.

Everyone else

Report PDFs are generated on our own server. We do not use third-party analytics or advertising services, we do not embed tracking pixels, and we do not sell, rent or trade personal information. We would disclose information if compelled by Australian law, and we would tell you unless prohibited from doing so.

Overseas disclosure

The recipients above who may hold information outside Australia are Stripe, and, in the fallback case only, blockstream.info, mempool.space and CryptoCompare.

How long we keep it, and what deletion means

Every account is set to expire 90 days after it is created. Signing a report resets that to 90 days from signing. You can also delete everything immediately using "Purge My Data" on your dashboard. Deletion runs automatically each day and requires no request from you.

Deleted when your account is purged

  • Your account record and its random identifier.
  • Your passkey records and your recovery code hash.
  • The encrypted blob holding all fund, trustee, descriptor, signature and balance data.
  • Any remote key holder signing links.
  • Any support email address and note you gave us.
  • The generated report PDF and its working files on our server.

Kept after your account is purged

Two things outlive the account, and neither contains fund or wallet data:

  • A verification record for each report: its reference, issue date, snapshot date, Bitcoin block height and the SHA-256 hashes of the PDF. This is what lets you or your auditor confirm years later that a report is genuine and unaltered, using the verification page. A hash cannot be reversed to recover the report.
  • Anonymised product measurements: the step records described above, with the link to your account removed so they become an untraceable count. We keep them so we can tell whether the service is getting easier to use over time.

Download and keep your report. Once purged, it cannot be recovered or regenerated. We keep no copy.

Security

Accounts are protected by passkeys, so there is no password to guess, phish or reuse. All traffic is served over TLS. Stored fund and wallet data is encrypted at rest as described above. Recovery code sign-in is rate limited with escalating backoff. No service can promise perfect security, and we will tell affected people promptly if we ever become aware of a breach that is likely to cause serious harm, as the Notifiable Data Breaches scheme requires.

Your rights

Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles you may ask what we hold about you, ask us to correct it, or ask us to delete it. Deletion is already available to you directly and immediately through "Purge My Data", which is faster than any request we could process. Because accounts carry no name or email, we may be unable to locate your records unless you are signed in, and we will not ask you to prove your identity by sending us personal documents.

If you are unhappy with how we have handled your information, contact us first at certainkey@dpinkerton.com. If we do not resolve it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

If we change what we collect or who we send it to, we will update this page and the date at the top. Material changes to how existing information is handled will be noted here rather than made quietly.

Contact

certainkey@dpinkerton.com