Minimize what you put in.
Use BitTwelve as a pointer system. Describe locations and order of operations without copying the underlying secrets into the map. Less sensitive content means less consequence if anything ever goes wrong.
BitTwelve was built around a small recovery roadmap: where to look, who to contact, and what to do next. The safest map contains no passwords, wallet seeds, private keys, legal originals, or other access credentials.
Use BitTwelve as a pointer system. Describe locations and order of operations without copying the underlying secrets into the map. Less sensitive content means less consequence if anything ever goes wrong.
The recovery roadmap is encrypted in the browser with AES-256-GCM before the hosted encrypted package is stored. The twelve-word code is used locally to derive the encryption material and storage locator.
BitTwelve uses the familiar BIP39 English vocabulary but rejects generated twelve-word sequences that pass the BIP39 checksum. During recovery, a valid 12-word BIP39 wallet mnemonic is refused locally before a package request is made.
your beneficiary account · your wallet seed · your password · your private key · your legal originals
Each update creates a new immutable encrypted version under the same recovery locator. A current-version manifest is authenticated with key material derived locally from the twelve words, so the client can reject an arbitrary substituted hosted envelope. Hosted infrastructure is still trusted for availability and freshness, which is why the independent offline recovery file remains important.
The completed product design keeps membership identity separate from recovery data. When enabled, membership uses an email address and Stripe subscription record to authorize creation and hosted-map updates. The encrypted package is designed not to contain the membership email, payment card, or Stripe customer record, and the twelve-word code is not intended to be sent to Stripe or Resend.
The product was designed so opening an existing hosted BitTwelve would not require an active membership. The downloadable offline recovery file provides an independent path with no network connection capability. Operational recovery is currently disabled on the live site while the project is in private development.
Stripe, Resend, Cloudflare, your ISP, browsers, and other network infrastructure may process ordinary data required to provide payment, email, and website delivery. BitTwelve does not promise network anonymity.
BitTwelve explains how its recovery system is designed, what it is intended to protect, and its important limitations. The production source repository is private for now. Transparency is not a security guarantee: a compromised device, browser extension, software defect, malicious deployment, or future cryptographic weakness could still defeat the intended model. Keep independent recovery materials and test them.
The principle is simple.