CreditVector helps you understand your credit reports and prepare disputes. Because that means handling sensitive financial information, we keep what we collect to what the product needs and protect it accordingly.
Information we collect
- Account details you provide — your name, email, and password (stored only as a one-way hash).
- Credit report content you upload or paste, and any documents or attachments you add to disputes and support tickets.
- Support messages you send us.
- Credit scores you record in the Score Tracker. These are numbers you type in yourself — we do not pull them from a bureau and we do not verify them.
- Activity on the product — such as articles you save or like, and comments you post in CreditVector Brief (which appear publicly under your username or first name) — so we can show your saved list, your comments, and how many readers found an article useful.
- Billing is handled by Stripe. We never see or store your full card number.
How we protect it
Uploaded reports, documents, and attachments are encrypted at rest with AES-256 and are only ever served back to you over an authenticated, access-checked connection — never from a public link. Access is scoped to your account (and, for agency-managed clients, to the agency that manages them).
How we use it
We use your information to analyze your reports, generate dispute letters, operate your account, and provide support. We do not sell your personal information, and we do not use your credit data for advertising.
What we send to our AI provider
Reading a credit report and drafting a letter are done with an AI model run by Anthropic, our AI provider. What is sent, and only for that purpose:
- The text of the credit report you uploaded or pasted, when it is read and when the identity check runs.
- The identity details you typed into Settings — your name and mailing address — when you run the identity check, and again if you ask for a personal-information correction letter.
- The account details from your report — creditor, status, balance and dates — when you ask for an action plan.
- When you log a bureau's response: the reply you paste in, together with the dispute letter it replies to, so the next round can be prepared from what they actually wrote. That letter carries the full name and mailing address printed on it, along with the creditor and the masked account number.
- The text of a community question you ask Kai, where the community is switched on.
What is not sent:
- Images of a government-issued ID. If you upload a driver's licence or other ID document it is stored encrypted for your own reference and is not transmitted to our AI provider, and no date of birth is read from it.
- Your password, which we never hold in a readable form at all.
- Your card details, which only Stripe ever sees.
Before credit-report text is sent — on every path that sends it — we mask Social Security numbers that we can recognize in it. That masking is pattern-based: it reduces what is transmitted, and we cannot promise it catches every instance. A credit report can also contain your date of birth, address history and employers, and where those appear in the report text they are sent with it. If that matters to you, remove them from what you paste before you upload.
That masking covers credit-report text and nothing else. A dispute letter and a bureau reply you paste in are sent exactly as they stand — we do not strip the sender block from your own letter before it is analyzed — so treat anything written in them as something that will be transmitted.
Your choices
What you can do yourself today, from inside the product:
- Delete an uploaded report at any time — its analyzed accounts are removed with it. Letters you already generated are kept, so your dispute history survives; those letters still contain the name, address and account details that were on them when you generated them.
- Delete a document or attachment you uploaded, including a government-ID image.
- Update your account email and password from Settings.
- If you have a subscription from before — the consumer product does not have one — view receipts, update your payment method, or cancel it from the Stripe billing portal on your billing page; access continues to the end of the billing period.
What we cannot do yet: there is no self-service way to delete your whole account or to export everything we hold, and we are not going to pretend otherwise. Tooling for both is planned and is not built. In the meantime, contact support with what you want removed and we will tell you honestly what we can do about it and when.
Contact
For any privacy question or request, reach us through in-app support and we'll respond promptly.