Last Updated: January 4, 2019

The security of your data is foundational to everything we do. If you have any questions or concerns, please contact us at

No Access to Private Keys

We never ask for your crypto wallets' private keys.

Coinbase integration is done through Coinbase’s OAuth2 flow. Our Coinbase integration requests read-only access to your Coinbase data.

All other exchanges are integrated with read-access only API keys on the exchange accounts.

We do not store the API keys and will be used only to import and forget.

Application Security

Our website traffic runs entirely over encrypted SSL (https).

We use SQL injection filters and verify the authenticity of POST, PUT, and DELETE requests to prevent CSRF attacks.

We always hash your passwords and never store in plain text. Even our developers can't see your passwords or access your account


You can delete all your account data at any time for any reason. This deletes all your wallets, exchanges, transactions, trade history, and all other linked account information. This action is irreversible.

We will never sell your crypto data to third parties.

Go ahead & Try BearTax

Leave aside your calculator, excel sheets and let the Big Bear take care of it.