Last updated: April 9, 2026
The data controller responsible for your personal data is:
Trailbit
Limassol, Cyprus. For the registered address and legal entity details, contact us at contact@trailbit.io.
Email: contact@trailbit.io
For all privacy-related enquiries, data subject requests, or concerns about how we process your personal data, contact us at the email address above.
When you create an account, we collect your email address and display name. When you use Trailbit's analysis tools, we process the Bitcoin transaction hashes and addresses you submit for analysis. We also collect standard usage analytics to improve the platform.
The following table clarifies which data is required to use the platform and which is optional:
| Data | Required? | Purpose |
|---|---|---|
| Email address | Required | Account authentication and transactional notifications |
| Password | Required | Account security |
| Display name | Optional | Profile personalisation |
| AI API key | Optional | Enables AI-assisted features (BYOK) |
| Transaction / address data | Functional | Public blockchain data — not personal data |
Transaction hashes and Bitcoin addresses are publicly available blockchain data. They do not constitute personal data under GDPR in isolation.
We process your personal data only where we have a lawful basis under GDPR Article 6. The table below maps each processing activity to its legal basis:
| Processing activity | Legal basis |
|---|---|
| Account creation and authentication | Consent — Article 6(1)(a) |
| Providing analytics and investigation services | Contract performance — Article 6(1)(b) |
| Payment processing and subscription management | Contract performance — Article 6(1)(b) |
| Platform security and abuse prevention | Legitimate interest — Article 6(1)(f) |
| Error monitoring (Sentry) | Legitimate interest — Article 6(1)(f) |
| Risk screening for financial crime prevention | Legitimate interest in preventing financial crime — Article 6(1)(f) |
Where we rely on legitimate interest, we have balanced that interest against your rights and concluded that our interest does not override your fundamental rights and freedoms.
Your data is stored in a PostgreSQL database hosted by Supabase with Row-Level Security (RLS) enabled — meaning your datasets and analysis results are accessible only to your account. All data is encrypted in transit via HTTPS.
User authentication is handled by Supabase Auth. Payment information is processed and stored exclusively by Stripe — we never see or store your card details.
We do not sell personal data to third parties. We share data only with the following categories of recipients to the extent necessary to operate the platform:
Some of our service providers operate outside the European Economic Area (EEA). We ensure that all such transfers are covered by appropriate safeguards:
| Provider | Location | Safeguard |
|---|---|---|
| Supabase | EU region available | User data stored in EU when configured; Standard Contractual Clauses (SCCs) |
| Vercel | Global (EU presence) | Standard Contractual Clauses (SCCs) |
| Stripe | US-based | EU–US Data Privacy Framework participant; Standard Contractual Clauses (SCCs) |
| Sentry | US-based | Standard Contractual Clauses (SCCs) |
You may request a copy of the applicable transfer mechanisms by contacting us at contact@trailbit.io.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
| Data type | Retention period |
|---|---|
| Account data (email, profile) | Duration of account + 30 days after deletion |
| Billing and payment records | 7 years (tax and legal requirements) |
| Datasets and analysis traces | User-controlled — deleted when you delete them or your account |
| AI conversation history | User-controlled deletion |
| Audit logs | 90 days |
| Error logs (Sentry) | 30 days |
| Invite email addresses | 30 days (automatically expires; purged after expiration) |
As a data subject under the GDPR, you have the following rights:
To exercise any of these rights, email contact@trailbit.io. We will respond within 30 days.
If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:
To exercise these rights, contact us at privacy@trailbit.io. We will respond to verifiable consumer requests within 45 days.
Where we rely on your consent to process personal data, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
You can withdraw consent by:
Trailbit uses automated heuristic analysis to generate risk scores and pattern classifications for Bitcoin addresses and transactions. We disclose the following:
Trailbit analyses publicly available blockchain data only. We do not store, transmit, or have access to private keys. All analysis results are derived from information that is already part of the public Bitcoin blockchain record.
Transaction hashes and addresses you submit are used solely for analysis purposes and are not shared with third parties beyond what is necessary to retrieve blockchain data from public APIs.
When law enforcement agencies apply for platform access, we collect: agency name, country, contact name, role, official email address, agency website, and intended use case. This data is processed under legitimate interest (Article 6(1)(f)) for the purpose of verifying agency identity and managing access. Application data is retained for up to 12 months and deleted after the review process is complete or the application period expires.
We use a theme preference cookie to remember your display settings. Vercel Analytics collects anonymised usage data to help us improve the platform. We do not use advertising cookies or third-party tracking pixels.
If you believe we have not handled your personal data in accordance with applicable data protection law, you have the right to lodge a complaint with the supervisory authority in Cyprus:
Commissioner for Personal Data Protection
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα
Iasonos 1, 1082 Nicosia, Cyprus
Website: dataprotection.gov.cy
We encourage you to contact us first at contact@trailbit.io so we have the opportunity to address your concern directly.
We will notify users of material changes to this policy via email. Continued use of the platform after changes take effect constitutes acceptance of the updated policy. For material changes to how we process your personal data, we will notify you and seek fresh consent where required by applicable law.
For privacy-related questions or requests, contact us at contact@trailbit.io.
Trailbit — Limassol, Cyprus