What we keep, what we don't
Last updated September 14, 2026. Shorter than most, because we collect less than most.
What we collect, and why
- Email + password hash — to operate your account. We never store the password itself. Your email address is verified with a one-time code before the account exists, and a one-time code is emailed at sign-in unless you've marked the device trusted (that's your two-factor authentication).
- Your app setup — which cards you hold, credit and offer states, your fee-anniversary months, category rules, and any point-value overrides you set — so it follows you between devices.
- If you link a bank: transaction history and balances via Plaid, read-only. The access token is encrypted (AES-256-GCM) before storage. We never see or store your bank credentials — those go to Plaid, not us. Plaid's own handling of your data is described in the Plaid End User Privacy Policy.
- If you upload a CSV or PDF statement: nothing. It's parsed in your browser and never transmitted.
- Sign-in security log — each sign-in attempt records the email, outcome and IP address, kept for 90 days and then deleted automatically. This exists to detect attacks on accounts, nothing else.
- Trusted-device token — if you tick "trust this device", a random token in a cookie lets that browser skip the sign-in code for 30 days. It identifies the device to us and nobody else, and dies when you change your password.
- Aggregate counters — page counts (day, page, referrer site) and in-app conversion-step counts (e.g. "signup started", "bank linked" — the event name and day, nothing else), both kept 13 months. No cookie, no visitor ID, no IP, no user agent — none of it can identify you, which is why there's no consent banner to click.
- Cloudflare Web Analytics — a small script from Cloudflare, which already hosts this site, that measures real page loads: the page, the referring site, browser and device type, country, and how fast the page loaded. Cloudflare states that it sets no cookie and does not fingerprint visitors, so it cannot follow you to other sites or tell us who you are. We added it on September 14, 2026, because our own counters cannot tell a real visitor from an automated one.
Email we send
Transactional: verification and sign-in codes, and password-reset links. Optional, all controlled by one switch: a monthly note on statement credits expiring and annual fees about to post; a weekly recap when there's something new in your numbers; a reminder before each quarter for cards with categories to activate; a year in review on 1 December; a plan for the year in early January; an email when a card you hold changes or a welcome offer you chose to watch goes up; and reminders when a welcome bonus deadline, a quarterly bonus limit, points that can expire, or a certificate you added is close. Reminders use totals the app saved from your last visit (for example, how much you've spent on a new card), never individual charges. They're on by default and off with one click in Settings or via the unsubscribe link in every one. That's the whole list; there is no marketing list.
The browser extension
The "Which card should I use here?" extension needs no account and sends nothing about your browsing to us. When you open it, it reads the address of the tab you are on, in your browser, to guess the store. The cards you add and any spending you record toward a bonus limit are kept in your browser's own extension storage and never leave the device. At most once a day it downloads our public card catalog from creditupside.com. That request carries no personal data, though like any web request it reaches Cloudflare with your IP address and browser type. It asks for two permissions, the active tab and storage, and can only reach creditupside.com.
What we don't do
- No selling or sharing of your data with advertisers or data brokers. Ever.
- No advertising networks, social-media pixels or cross-site trackers. The one outside script is Cloudflare Web Analytics, described above.
- No Social Security numbers, no credit pulls, no card numbers.
Who touches your data
Three processors, each boring and necessary: Cloudflare hosts the service and the database and measures page loads as described above, Plaid provides bank connections if you choose to link one, and Resend delivers our email (it sees your address and the message, nothing more).
Deletion & your rights
Settings → Delete account. This revokes bank access at Plaid, erases your rows from our database (including the sign-in log for your account), and invalidates your session — in one action, immediately. There is no soft-delete limbo. Copies of your rows in our nightly backups age out within 30 days, and we never restore a deleted account from them. CSV data was never on our servers, so there's nothing to delete. If your state's privacy law (California, Colorado, Virginia and others) grants you access, correction or deletion rights, the Delete button and the email below are how you exercise them — we honor the same requests for everyone regardless of state.
Questions
Write to admin@creditupside.com — it reaches the founder directly. Credit Upside LLC, 3535 Route 66, Building 2 Suite 2, Neptune City, NJ 07753.