Your security and privacy are our top priorities at OrangeCat
OrangeCat is built on Bitcoin-first principles, which means we prioritize decentralization, self-custody, and transparency. We never hold your funds, and we design our systems to minimize the data we collect while maximizing security.
Your Bitcoin remains under your control. We facilitate payments but never custody funds.
We collect only the minimum data necessary to provide our services.
All data transmission is encrypted using industry-standard TLS 1.3 protocols. E2E messaging encryption is planned.
We never hold your Bitcoin. You maintain full control over your private keys and funds.
Database-level authorization ensures users can only access their own data.
Hosted on managed cloud platforms (Vercel for the app, Supabase for the database) that handle patching and uptime.
The codebase is public on GitHub, so anyone can read, audit, or report issues.
Uptime and error monitoring are provided by the underlying platforms. We do not currently run a dedicated security operations center.
Page last reviewed: 2026-06-09.