Privacy policy
What we keep, what we don't
Last updated August 24, 2026. Shorter than most, because we collect less than most.
What we collect, and why
- Email + password hash — to operate your account. We never store the password itself.
- Your app setup — which cards you hold, your point valuations, offer and credit states — so it follows you between devices.
- If you link a bank: transaction history and balances via Plaid, read-only. The access token is encrypted before storage. We never see or store your bank credentials — those go to Plaid, not us.
- If you upload a CSV: nothing. It's parsed in your browser and never transmitted.
What we don't do
- No selling or sharing of your data with advertisers or data brokers. Ever.
- No third-party analytics or tracking scripts on this site.
- No Social Security numbers, no credit pulls, no card numbers.
Who touches your data
Two processors, both boring and necessary: Cloudflare hosts the service and the database, and Plaid provides bank connections if you choose to link one. Password-reset email, when enabled, is delivered by a transactional email provider that sees only your address and the reset link.
Deletion
Settings → Delete account. This revokes bank access at Plaid, erases your rows from our database, and invalidates your session — in one action, immediately. There is no soft-delete limbo. CSV data was never on our servers, so there's nothing to delete.
Questions
Write to privacy@creditupside.com (placeholder — goes live with the custom domain's email routing).