What we keep, what we don't
Last updated September 2, 2026. Shorter than most, because we collect less than most.
What we collect, and why
- Email + password hash — to operate your account. We never store the password itself. Your email address is verified with a one-time code before the account exists, and a one-time code is emailed at sign-in unless you've marked the device trusted (that's your two-factor authentication).
- Your app setup — which cards you hold, credit and offer states, your fee-anniversary months, category rules, and any point-value overrides you set — so it follows you between devices.
- If you link a bank: transaction history and balances via Plaid, read-only. The access token is encrypted (AES-256-GCM) before storage. We never see or store your bank credentials — those go to Plaid, not us. Plaid's own handling of your data is described in the Plaid End User Privacy Policy.
- If you upload a CSV or PDF statement: nothing. It's parsed in your browser and never transmitted.
- Sign-in security log — each sign-in attempt records the email, outcome and IP address, kept for 90 days and then deleted automatically. This exists to detect attacks on accounts, nothing else.
- Trusted-device token — if you tick "trust this device", a random token in a cookie lets that browser skip the sign-in code for 30 days. It identifies the device to us and nobody else, and dies when you change your password.
- Aggregate counters — our only analytics: page counts (day, page, referrer site) and in-app conversion-step counts (e.g. "signup started", "bank linked" — the event name and day, nothing else), both kept 13 months. No cookie, no visitor ID, no IP, no user agent — none of it can identify you, which is why there's no consent banner to click.
Email we send
Transactional: verification and sign-in codes, and password-reset links. Optional: a once-a-month digest of statement credits expiring on your cards and annual fees about to post — on by default, off with one click in Settings or via the unsubscribe link in every such email. That's the whole list; there is no marketing list.
What we don't do
- No selling or sharing of your data with advertisers or data brokers. Ever.
- No third-party analytics or tracking scripts on this site.
- No Social Security numbers, no credit pulls, no card numbers.
Who touches your data
Three processors, each boring and necessary: Cloudflare hosts the service and the database, Plaid provides bank connections if you choose to link one, and Resend delivers our email (it sees your address and the message, nothing more).
Deletion & your rights
Settings → Delete account. This revokes bank access at Plaid, erases your rows from our database (including the sign-in log for your account), and invalidates your session — in one action, immediately. There is no soft-delete limbo. CSV data was never on our servers, so there's nothing to delete. If your state's privacy law (California, Colorado, Virginia and others) grants you access, correction or deletion rights, the Delete button and the email below are how you exercise them — we honor the same requests for everyone regardless of state.
Questions
Write to admin@creditupside.com — it reaches the founder directly. Credit Upside LLC, 3535 Route 66, Building 2 Suite 2, Neptune City, NJ 07753.