Your sensitive credit data — Social Security number, date of birth, account details — is stored in an encrypted vault on our servers. Your vault is encrypted at rest using AES-256-GCM with a key derived from your password — we never store or transmit your key. We hold ciphertext only. If you lose your password, we cannot decrypt your vault.
Account data (stored on our servers): Your email address and a bcrypt-hashed password. We use this to authenticate you and send transactional emails (account confirmation, dispute status updates). We do not store your password in recoverable form.
Vault data (stored on our servers, encrypted): Your full name, address, date of birth, Social Security number, credit report information, and dispute case details. This data is encrypted with AES-256-GCM using a key derived from your password. We store only the ciphertext — our servers never see your data in plaintext. If you lose your password, we cannot recover your vault.
Usage data: We log actions such as the number of letters generated and mail items dispatched for billing quota purposes. These logs contain action types and counts — not the content of your letters or personal information.
LetterStream (certified mail): When you dispatch a physical letter, we send LetterStream your name, mailing address, and the text of your dispute letter. We do not send your SSN, DOB, or financial account numbers to LetterStream. Their privacy policy governs how they handle that data: letterstream.com/privacy.
Stripe (payments): Payment card data is collected and processed directly by Stripe. We store only your Stripe customer ID — never your card number, expiry, or CVV. Stripe's privacy policy: stripe.com/privacy.
Anthropic (AI generation): Dispute letter content is generated using Anthropic's Claude API. When generating letters, anonymized dispute parameters (account type, dispute reason, bureau) may be sent to Anthropic's API. We do not send SSNs or full account numbers. Anthropic's privacy policy: anthropic.com/privacy.
Resend (transactional email): Confirmation and notification emails are delivered through Resend. They receive your email address for delivery purposes only.
We use browser localStorage to store your session token, active profile ID, and app preferences. We do not use third-party tracking cookies or advertising pixels. Your vault is stored on our servers in encrypted form — not in your browser.
Server-side account data (email, password hash, usage logs) is retained as long as your account is active. If you delete your account, this data is purged within 30 days. Mail dispatch logs are retained for 90 days for tracking purposes, then deleted.
Your encrypted vault is stored on our servers. Deleting your vault or account permanently removes it. Because we never store your encryption key, we cannot restore vault contents after deletion.
To request deletion of your account data, email mark@greenwoodstratton.com from the address associated with your account.
Depending on where you live, you may have rights under the CCPA (California), VCDPA (Virginia), or other state privacy laws to access, correct, or delete your personal data, and to opt out of certain data uses. To exercise these rights, contact us at mark@greenwoodstratton.com. We will respond within 30 days.
Your vault is encrypted at rest on our servers using AES-256-GCM with a key derived from your password — we never store or see your key. Server-side passwords are hashed with bcrypt. We use HTTPS for all data transmission. Authentication tokens expire after 30 minutes.
No system is perfectly secure. If you discover a security vulnerability, please report it responsibly to mark@greenwoodstratton.com.
Citely is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has created an account, contact us and we will delete it.
We may update this Privacy Policy periodically. We will notify you by email at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance of the updated policy.
Privacy questions or data requests: mark@greenwoodstratton.com