diff --git a/blog.html b/blog.html index 03e1ef9..3f31a50 100644 --- a/blog.html +++ b/blog.html @@ -207,6 +207,23 @@ footer .built{font-size:13px;color:var(--muted);margin-top:8px} date (machine-readable in the datetime attribute), title, standfirst. -->
+ +
+ +

What can a Will-Executor actually see? Privacy in the BAL protocol

+

A Will-Executor holds one signed, time-locked transaction — and nothing + else. Exactly what it can see (a few addresses, amounts, a date), what + it cannot (who you are, what else you own, who your heirs are), and why + that protection comes from the protocol's architecture, not from a + privacy policy.

+ Read the article → +
+
+ +
+
+ +
+
+
+ Blog +

What Can a Will-Executor Actually See? Privacy in the BAL Protocol

+ +
+
+ +
+
+A blue shield bearing the Bitcoin symbol covers an eye in front of a document — what a Will-Executor can and cannot see +
+ +

When you hand something to a third party — even an automated one — the first question a careful Bitcoiner asks is: what do they learn about me?

+

It's the right question. Traditional inheritance is a privacy disaster by design: a notary learns your identity, your family structure, your assets, and your heirs' identities, and all of it ends up in records that can be subpoenaed, leaked, or — in many jurisdictions — made public after probate. Custodial services are worse: they hold your coins and your data.

+

Bitcoin After Life was built to need no third party at all. But it does involve Will-Executor servers, so let's answer the privacy question precisely, without marketing fog: here is exactly what a Will-Executor can see, and what it cannot.

+ +

What a Will-Executor holds

+

A Will-Executor stores one thing: your signed, time-locked inheritance transaction. Nothing else travels to the server — no identity, no email, no account, no documents. The BAL plugin doesn't ask who you are, because the protocol doesn't need to know.

+

From that transaction, an executor — like anyone who inspects a raw Bitcoin transaction — can technically observe:

+
    +
  • The inputs: the specific UTXOs your inheritance will spend, and therefore the amount they contain.
  • +
  • The outputs: your heirs' addresses, their shares, and the executor fee.
  • +
  • The locktime: the delivery date after which the transaction becomes valid.
  • +
+

That is the complete list. Let's now look at the much longer list of what remains invisible.

+ +

What a Will-Executor cannot see

+

Your identity. There is no account system, no KYC, no registration. To a Will-Executor you are a transaction, not a person. Bitcoin addresses are pseudonymous by design — the server sees strings of characters, not names.

+

The rest of your wallet. The transaction reveals only the UTXOs it spends. Your other addresses, your total holdings, your transaction history beyond those specific coins: none of it is exposed by the protocol. The executor sees the inheritance, not your wealth.

+

Your heirs' identities. Heirs appear as addresses. A name, a face, a relationship — none of that is in a Bitcoin transaction, and none of it is in what BAL sends.

+

Your activity and your lifetime. Executors cannot tell whether you're alive, active, traveling, or simply quiet. The Check Alive mechanism that postpones your delivery date works through your own wallet — the server doesn't track you, ping you, or monitor you. There is no surveillance built into the protocol, because there is no need for any.

+

Any way to profit from what it sees. This is the crucial point. Even the limited information above is useless for abuse: the transaction is already fully signed, so it cannot be altered; it is time-locked, so it cannot be broadcast early; and its outputs are fixed, so not a single satoshi can be redirected. A Will-Executor that tried to front-run, censor, or manipulate would gain nothing — and would lose its fee, which is only paid when the inheritance executes exactly as written.

+ +

Privacy by architecture, not by policy

+

Most services protect your data with a privacy policy — a legal promise that can change with an acquisition, a subpoena, or a new CEO. BAL protects it with architecture: the protocol was designed so that the sensitive data never exists on the server in the first place.

+
+ + + + + + + + + + + +
What traditional inheritance exposesWhat BAL exposes
Your legal identityNothing — no accounts
Full inventory of your assetsOnly the UTXOs in the transaction
Heirs' names and relationshipsHeirs' addresses only
Family structure, stored in public recordsNothing — no records exist
Protected by: a privacy policyProtected by: protocol design
+
+

You cannot leak what you never collected.

+ +

Optional hardening for the privacy-conscious

+

The protocol's defaults are already strong, but Bitcoin hygiene adds another layer:

+
    +
  • Use fresh addresses for your heirs. Electrum generates new addresses freely; an address that has never appeared on-chain carries no history to analyze.
  • +
  • Consider multiple executors. Splitting your will across several Will-Executors from the WeList is primarily a redundancy feature — but it also means no single server is your only counterparty.
  • +
  • Review before you send. The plugin always lets you inspect the generated transactions before anything is transmitted. Verify the outputs yourself; trust is not required.
  • +
+ +

The honest summary

+

A Will-Executor sees one signed transaction: some addresses, some amounts, a date. It does not know who you are, what else you own, or who your heirs are — and the cryptography guarantees it can do nothing harmful even with what little it sees.

+

Compare that with the alternative: a folder in a lawyer's cabinet containing your name, your family's names, and the full list of what you own.

+

Inheritance used to require giving up your privacy to be safe. We built BAL so you could keep both.

+ +

Want the technical detail? The full protocol walkthrough is in the manual, and both the plugin and the server are open source — verify, don't trust.

+
+ + +
+ + + + + +