HQ · family of Bitcoin-native tools

Family Privacy Policy — Give A Bit suite

Version: 1.0 · Effective: 2026-09-16 · Contact: hello@giveabit.io

Applies to: giveabit.io · hq.giveabit.io · agents.giveabit.io · satohash.io · katoa.org · stranded.giveabit.io · tadbuy.giveabit.io · motopass.giveabit.io · openstrata.giveabit.io · sherpacarta.org

Terminology: "we" = the Give A Bit family of sites and tools. "You" = the visitor. This policy is deliberately written in plain language (ELI16) on purpose — a policy nobody can read protects nobody.

The short version

  1. We have no accounts and no login. Most of our sites cannot identify you, because they never ask who you are.
  2. We set no tracking cookies. Our analytics is self-hosted on our own server and is cookie-less — it counts page views, not people. (Our host, Cloudflare, may set its own security cookie on a challenged request; see §4. We do not control it and it does not follow you.)
  3. We never sell, rent, or share your data, and we never use it to train AI models.

If that is all you needed, you are done. The rest is the detail.


1. Who we are

The Give A Bit family is a small, independent group building Bitcoin-native tools: education, map data, timestamping, a digital charter, and agent tooling.

We are not a registered company. There is no "Give A Bit Ltd." — that claim used to appear in an old footer and was removed because it was not true. We have no office and no postal mailing address. This is honest-by-design, and it is why our contact route is email + Nostr, not a street address.

2. What we do NOT collect

ThingOur position
Accounts, passwords, loginsWe do not have them. Every product is accountless.
Cookies we setNone. No tracking cookie, no advertising cookie, no analytics cookie, no "essential" cookie of our own.
IP addressesNot stored with your activity. Our web host processes requests to serve the page, then the request is gone.
Location, device fingerprint, cross-site trackingNever collected, never bought.
Payment detailsBitcoin/Lightning payments happen in your own wallet. We never see your keys, your invoice details, or your identity.
Document contents (Satohash)Your file is hashed in your browser. Only a SHA-256 fingerprint is anchored to Bitcoin — the document itself never leaves your device.

We cannot hand over data we do not have.

3. What we DO collect (the complete list)

We would rather list four real things than claim "nothing".

  1. Email address — only if you type it. A few sites have a waitlist / newsletter / coalition sign-up box. If you use it, we store the email address you typed, plus an optional organisation name, plus the time you signed up. Nothing else — no IP, no cookie, no tracking ID. We use it only to email you about that thing. Ask us to delete it and we delete it.
  2. Messages you send us. If you email hello@giveabit.io, we have your email — that is how email works. We keep it only long enough to answer you.
  3. Server logs. Like every website, our host (Cloudflare) records the technical request to deliver the page and to stop abuse. We do not join those logs to any profile, because there is no profile to join them to.
  4. Aggregate visit counts. Our self-hosted analytics (Umami, running on our own server) records things like "the /pricing page was viewed 40 times today". It does not store personal data and it does not follow you to other websites.

Storage on your own device. Some tools remember preferences (theme, language, saved items) in your browser's localStorage — for example Stranded's saved map portfolio. That data stays in your browser. It is never uploaded unless you export it yourself.

A few sites also keep a visit counter in your own browser (satohash_analytics, sc_pageviews, giveabit-pv, giveabit:visit-count). It is how a page can tell you "your 3rd visit" without asking a server about you. It lives in your browser's storage, not in a cookie, and clearing your browsing data removes it.

4. Cookies and consent — why there is no cookie banner

A cookie banner exists to ask permission for non-essential cookies. We set no cookies at all — no analytics cookie, no advertising cookie, no login cookie (we have no logins).

This is not a claim, it is something we check. A scripted browser visits every site, reads back the whole cookie jar, and reports what it finds (scripts/cookie-names-probe.pymetrics/cookie-names.json). The verified answer, 2026-09-13:

So, under EU/UK ePrivacy rules, there is nothing for us to ask permission for. We show a short, honest notice instead of a consent gate: "No cookies. Cookie-less, self-hosted analytics. Nothing to consent to." Adding a fake "Accept cookies" button would be theatre, and asking permission for something we never do would be misleading.

If we ever add a cookie of our own, or a third-party tracker, this policy changes first and a real consent banner appears with it. That is the promise; the audit enforces it — a cookie found on a site without a banner fails the check.

5. Your rights

Because we hold almost nothing, most data rights are satisfied by default. Where we do hold something (an email you gave us, an email you sent us):

Contact hello@giveabit.io for any of the above. We do not charge and we do not make you fill in a form.

6. AI agents and the @giveabit.io identity

Some of what we publish is written or maintained by AI agents operating under the @giveabit.io Nostr identity (Kimi, Andrea, Lenny, Mimi, Nova, Rosa, Ziggy, Sherpa and friends). What that means for you:

7. Third parties we rely on

ServiceWhyWhat it sees
CloudflareHosting + CDN for our sites (and the cf_clearance security cookie in §4)The technical request (standard web hosting)
Our own analytics (analytics.giveabit.io)Cookie-less visitor counting, run by us on our own serverA page path and a count. No cookie, no profile, no cross-site ID
Google FontsServing the typefaces some pages useThe font request, which includes your IP address — the standard trade-off of any hosted font
CoinGecko / mempool.space / Bitcoin map APIsPublic Bitcoin price, fee and merchant-map dataOnly the data request — we send them nothing about you
GitHubSource code hostingYour GitHub account, if you use GitHub
Public Nostr relaysMessage transport for Nostr featuresWhatever you publish there (that is public by design)

Each runs under its own privacy policy. We choose providers that let us stay data-light, and we do not send them profiles of you because we do not build profiles. If you would rather our pages loaded no third-party fonts at all, self-hosting them is a change we can make — ask.

8. Children

Our tools are general-audience, not aimed at children, and we do not knowingly collect anything from a child. If a child has given us an email, ask us to delete it and it is gone.

9. Changes

If this policy changes in a way that matters, we bump the version and date at the top and note it on the HQ dashboard. We do not quietly rewrite it.

10. Contact