Custodial vs non-custodial, plainly
In a custodial setup, a provider holds your crypto on your behalf and you rely on them to move it when you ask. In a non-custodial setup, transactions are signed using keys or a passkey tied to your own device, and the provider never has the ability to move your funds without you.
What 'you hold the keys' means in practice
It means the signature that authorises a transaction is generated on your own device, not by the platform. GEF One's own non-custodial wallets, for example, use passkey-based signing so that sends are authorised locally rather than by GEF One acting on your behalf.
The trade-off involved
Non-custodial control comes with personal responsibility: there is no central account-recovery process the way there is with a bank password reset if the device or passkey securing your wallet is lost and no backup was set up. That trade-off is the actual price of not depending on a custodian.
Practical security habits
Keep the device holding your passkey secure and updated, be deliberate about backup and recovery options a wallet provider offers, and always verify a receiving address carefully before sending — non-custodial transactions generally can't be reversed once broadcast.
How GEF One fits in
GEF One's Bitcoin, Dogecoin, TRON and XRP sends are passkey-wallet based and non-custodial: transactions are signed client-side and broadcast directly, with GEF One providing the interface and reporting layer rather than holding the underlying assets itself. See the Security Centre for more on how account and device security work together.