citely
How It Works What You'll Understand Meet Lex Who It's For Pricing Login
Get Started →
citely

Privacy Policy

Last updated: May 2026  ·  Effective immediately upon account creation

The Short Version

Your sensitive credit data — Social Security number, date of birth, account details — is stored in an encrypted vault on our servers. Your vault is encrypted at rest using AES-256-GCM with a key derived from your password — we never store or transmit your key. We hold ciphertext only. If you lose your password, we cannot decrypt your vault.

What We Collect and Why

Account data (stored on our servers): Your email address and a bcrypt-hashed password. We use this to authenticate you and send transactional emails (account confirmation, dispute status updates). We do not store your password in recoverable form.

Vault data (stored on our servers, encrypted): Your full name, address, date of birth, Social Security number, credit report information, and dispute case details. This data is encrypted with AES-256-GCM using a key derived from your password. We store only the ciphertext — our servers never see your data in plaintext. If you lose your password, we cannot recover your vault.

Usage data: We log actions such as the number of letters generated and mail items dispatched for billing quota purposes. These logs contain action types and counts — not the content of your letters or personal information.

Third-Party Services

LetterStream (certified mail): When you dispatch a physical letter, we send LetterStream your name, mailing address, and the text of your dispute letter. We do not send your SSN, DOB, or financial account numbers to LetterStream. Their privacy policy governs how they handle that data: letterstream.com/privacy.

Stripe (payments): Payment card data is collected and processed directly by Stripe. We store only your Stripe customer ID — never your card number, expiry, or CVV. Stripe's privacy policy: stripe.com/privacy.

Anthropic (AI generation): Dispute letter content is generated using Anthropic's Claude API. When generating letters, anonymized dispute parameters (account type, dispute reason, bureau) may be sent to Anthropic's API. We do not send SSNs or full account numbers. Anthropic's privacy policy: anthropic.com/privacy.

Resend (transactional email): Confirmation and notification emails are delivered through Resend. They receive your email address for delivery purposes only.

Cookies and Local Storage

We use browser localStorage to store your session token, active profile ID, and app preferences. We do not use third-party tracking cookies or advertising pixels. Your vault is stored on our servers in encrypted form — not in your browser.

Data Retention and Deletion

Server-side account data (email, password hash, usage logs) is retained as long as your account is active. If you delete your account, this data is purged within 30 days. Mail dispatch logs are retained for 90 days for tracking purposes, then deleted.

Your encrypted vault is stored on our servers. Deleting your vault or account permanently removes it. Because we never store your encryption key, we cannot restore vault contents after deletion.

To request deletion of your account data, email mark@greenwoodstratton.com from the address associated with your account.

Your Rights

Depending on where you live, you may have rights under the CCPA (California), VCDPA (Virginia), or other state privacy laws to access, correct, or delete your personal data, and to opt out of certain data uses. To exercise these rights, contact us at mark@greenwoodstratton.com. We will respond within 30 days.

Security

Your vault is encrypted at rest on our servers using AES-256-GCM with a key derived from your password — we never store or see your key. Server-side passwords are hashed with bcrypt. We use HTTPS for all data transmission. Authentication tokens expire after 30 minutes.

No system is perfectly secure. If you discover a security vulnerability, please report it responsibly to mark@greenwoodstratton.com.

Children

Citely is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has created an account, contact us and we will delete it.

Changes to This Policy

We may update this Privacy Policy periodically. We will notify you by email at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance of the updated policy.

Contact

Privacy questions or data requests: mark@greenwoodstratton.com

← Back
citely
Privacy Terms FCRA & CROA Disclosure Refund Policy Contact

© 2026 Citely. All rights reserved.