C
Credit365 .io
← Back to homepage

Privacy Policy

HOW WE COLLECT, USE, AND PROTECT YOUR INFORMATION

Short version: We collect the minimum information needed to analyze your credit report and generate dispute letters for you. We never sell your data. We keep your credit report data for up to 1 year after your last dispute resolves, then delete it. You can request deletion at any time.

1. Information We Collect

Account Information

When you create a Credit365 account, we collect:

  • Full name
  • Email address
  • Password (stored as a one-way cryptographic hash — we never see or store your actual password)
  • Mailing address, city, state, and ZIP (used as the return address on dispute letters mailed on your behalf)
  • Phone number (optional)

Credit Report Data

When you upload a credit report PDF to the platform, we extract and store:

  • Your name, address, and other identifying information as it appears on the report
  • Account details: creditor name, account number (typically only the last 4 digits are visible in consumer reports), account type, balance, payment history, dispute status
  • Hard inquiries, collection accounts, public records, and negative items
  • Credit scores if present in the report
  • The raw PDF file itself (stored in our secure uploads directory)

⚠ Important: Do NOT upload credit reports containing your full Social Security Number. Consumer credit reports from annualcreditreport.com, Experian.com, Equifax.com, and TransUnion.com redact the SSN to the last 4 digits. If you have a raw report with your full SSN visible, black it out before uploading. Credit365 does not need and should never store your full SSN.

Dispute Letter Content

We store the AI-generated dispute letters we create for you, any edits you make to those letters before mailing, and metadata about each dispute (creditor, bureau, mailing date, LetterStream batch ID, status, tracking number, delivery confirmation).

Payment Information

When you pay for a dispute:

  • Credit card and PayPal account details are handled exclusively by PayPal — we never see or store your actual card number, CVV, or PayPal login
  • We store the PayPal transaction ID, the amount paid, and the date, for accounting and refund purposes

Usage and Technical Data

  • IP address (for security logging and abuse prevention)
  • Browser type, device type, and operating system (for compatibility and support)
  • Pages visited within the dashboard, actions taken, and timestamps (for support and debugging)
  • Error logs (PHP, JavaScript) — may incidentally contain data you entered around the time of an error

2. How We Use Your Information

PurposeWhat We Use
Account authentication and loginEmail, password hash
AI credit report analysisCredit report contents sent to Anthropic's Claude API for processing
Dispute letter generationYour name, address, report data, dispute reason sent to Claude API
Certified mail deliveryYour name, return address, letter PDF sent to LetterStream
Payment processingEmail, dispute details, amount sent to PayPal (we never touch card data)
Dashboard, history, and receiptsAll dispute and payment data stored in our secure database
Customer supportAny information relevant to the support ticket
Security and abuse preventionIP, usage logs, rate limit tracking

3. Who We Share Data With

We share data only with the third-party processors essential to providing the service. We do not sell your data to advertisers, marketers, data brokers, or any other third party.

Essential Processors

  • Anthropic (Claude AI) — processes credit report contents to identify negative items and generate dispute letters. Anthropic's enterprise-grade API does not use your data to train models. See Anthropic's Privacy Policy.
  • LetterStream — prints and mails your dispute letters via USPS Certified Mail. They receive the letter PDF, your return address, and the bureau's destination address. See LetterStream's Privacy Policy.
  • PayPal — processes your payment. They receive your email and the transaction amount. See PayPal's Privacy Policy.
  • Hostinger — hosts our servers and database. They do not access application data in the normal course of business.
  • USPS — the United States Postal Service physically delivers the letters. Your return address and the bureau's address appear on each envelope. USPS is not contractually part of Credit365 but is the final carrier of every mailed letter.

Credit Bureaus

The entire point of the service is to transmit your dispute letters to TransUnion, Equifax, and/or Experian. You are the author and sender of each letter; we just mail them for you. The bureaus receive only what is in the printed letter.

Legal Requirements

We may disclose information if required by a valid subpoena, court order, or applicable law, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Credit365, our users, or the public.

4. Data Retention

We keep different categories of data for different lengths of time:

CategoryRetention
Account information (name, email, address)Until you delete your account, then 30 days
Credit report uploads and AI analysis1 year after your last dispute on that report resolves
Generated dispute letters1 year after the dispute resolves (for legal recordkeeping)
Mailing receipts (LetterStream batch IDs, USPS tracking)7 years (for accounting and audit trail)
Payment records (PayPal transaction IDs, amounts)7 years (IRS and tax requirements)
Support tickets2 years after ticket closure
Server and security logs90 days

After retention periods expire, data is permanently deleted from production systems. You may request deletion earlier by emailing us (see Section 6).

5. How We Protect Your Data

  • Encryption in transit: All pages and API calls use HTTPS with modern TLS. Your data is encrypted between your browser and our servers.
  • Encryption at rest: Our database and uploaded files are stored on encrypted volumes.
  • Password hashing: Passwords are hashed with bcrypt (one-way). Even Credit365 staff cannot retrieve your actual password — if you forget it, you must reset it.
  • Access controls: Only authenticated users can access their own data. Staff access is restricted to what's necessary to provide support.
  • No third-party tracking cookies: We don't use ad networks, marketing pixels, or third-party analytics that track you across the web.
  • JWT-based sessions: Login sessions use secure JSON Web Tokens, not server-side session cookies.

No system is perfectly secure. If we become aware of a data breach affecting your information, we will notify you by email within the timeframe required by applicable law.

6. Your Privacy Rights

Regardless of where you live, Credit365 honors the following rights for all users:

  • Right to access — you can download your account data, credit reports, and dispute history at any time from the dashboard, or request a full export by email
  • Right to correction — you can update your profile information from the dashboard
  • Right to deletion — you can request deletion of your account and associated data by emailing support@credit365.io. We will delete within 30 days, except where we are legally required to retain (payment records, tax documents)
  • Right to data portability — you can request your data in a machine-readable format (JSON)
  • Right to object — you can object to specific uses of your data, though this may limit our ability to provide service

California Residents (CCPA / CPRA)

If you are a California resident, you have the specific rights granted by the California Consumer Privacy Act and the California Privacy Rights Act, including the right to know what personal information we collect, the right to delete that information, and the right to opt out of "sale" or "sharing" of personal information. Credit365 does not sell or share personal information as those terms are defined by the CCPA/CPRA.

EU/UK Residents (GDPR / UK GDPR)

If you are in the EU or UK, you have the rights granted by the General Data Protection Regulation, including the rights listed above plus the right to lodge a complaint with your national data protection authority. Our legal basis for processing is: (a) performance of a contract (the service you signed up for), (b) your consent (for optional features), and (c) legitimate interests (security, fraud prevention).

7. Children's Privacy

Credit365 is intended for users aged 18 and older. We do not knowingly collect information from children under 18. If you are under 18, please do not create an account. If you believe we have collected information from a minor, contact us and we will delete it.

8. Third-Party Links

Our site may link to third-party websites (annualcreditreport.com, identitytheft.gov, credit bureaus, our processors' policies). We are not responsible for the privacy practices of those sites. Review their privacy policies before providing information to them.

9. Changes to This Policy

We may update this Privacy Policy as laws, our services, or our processors change. The current version always appears at credit365.io/privacy.html. Material changes will be communicated to active users by email and will require re-acceptance before you can continue using the service.

10. Contact Us

Questions, data requests, deletion requests, or privacy concerns: support@credit365.io

Please include "Privacy Request" in the subject line to ensure it reaches the right person quickly.

Last updated: April 14, 2026 · Credit365 by Rhythm Capital
Disclosures · Privacy Policy · Terms of Service · User Guide
© 2026 Credit365 · credit365.io