Privacy Policy
Information handled
The platform may process account details, user-provided credit documents, extracted report information, progress data, and billing status needed to provide the service.
How information is used
Information is used to operate accounts, secure report access, provide user-requested analysis and document tools, maintain workflow history, prevent abuse, and support billing. Payment card details are handled by Stripe rather than stored by this application.
Safeguarding and sharing
EZKredit AI uses administrative and technical safeguards designed to protect the confidentiality and security of customer information. Uploaded reports are kept in private, account-restricted storage and are not made public or sold. Access is limited to the user and the systems and service providers needed to deliver requested features, prevent abuse, maintain security, and comply with law. No online system can guarantee absolute security.
Credit-report retention
Uploaded credit reports expire after 365 days by default. EZKredit AI securely disposes of customer information no later than two years after its most recent use to serve the customer unless a documented legal requirement, legitimate business need, or technical feasibility exception applies.
AI processing
Before report text is sent to OpenAI, EZKredit AI removes high-risk identity fields and limits the submitted text. API responses are requested with provider-side response storage disabled. OpenAI states that API data is not used for model training by default and that abuse-monitoring logs may be retained for up to 30 days unless a qualifying zero-data-retention configuration applies.
Analytics and campaign attribution
Essential storage supports security and account operation. Optional analytics activates only after the visitor chooses to allow it. The growth system is designed to record a random session identifier, page path, general campaign labels, referral host, and bounded interaction categories for no more than 90 days. It does not send credit-report contents, account emails, form entries, or identity-verification information to analytics. Advertising storage and personalization remain disabled unless a separately reviewed and consent-controlled integration is approved.
Deletion and export
A signed-in user can export account records, permanently delete an individual report and its linked analysis, or permanently delete the entire account and private report files from Privacy & Account settings.
Operational records
Security audit records avoid raw report contents and are retained for 365 days. Payment, tax, fraud-prevention, or legal records held by service providers may follow separate required retention periods.
