Beta

Credily is currently in open beta.

Skip to content
credily
Download for iOS

Privacy Policy

Last updated: July 15, 2026Version privacy-2026-07-15

This policy explains what Credily collects, why it is used, and the controls you have.

Information you provide

Credily collects the information you enter during sign-in and onboarding, such as your email address, name, date of birth, phone number, and rewards preference.

Credily also stores account status information needed to run the app, including onboarding state, session state, subscription state, and account deletion request state.

Connected financial data

If you connect accounts with Plaid, Credily may receive and store information such as institution details, linked card names, account identifiers, card profile selections, transaction dates, merchant names, descriptions, amounts, currencies, categories, and merchant category codes.

Credily uses this data to show connected cards, compare card rewards, calculate reward-related summaries, label transaction context, and produce recommendations.

Location and nearby recommendations

If you grant location permission, Credily can use location signals to find nearby merchants and recommend which linked card may be best at that location.

When nearby recommendation features run, Credily may send app events that include merchant identifiers, day keys, signal source, and distance information. These events help avoid duplicate prompts and improve recommendation behavior.

Notifications and device data

If you allow notifications, Credily may store an iOS/Firebase notification token so the backend can send alerts. Notification preferences and notification history may be stored so the app can show unread counts and route you to the relevant screen.

You can turn notifications off in iOS Settings or in Credily settings. Some background education or nearby alert behavior depends on those permissions.

Subscriptions and payments

Credily uses Stripe for checkout, subscription management, billing portal sessions, and subscription lifecycle webhooks. Credily stores subscription identifiers, status, price identifiers, period dates, billing issue state, and Stripe customer identifiers needed to operate the subscription.

Credily does not need to store your full card payment details in the app because payment collection and management happen through Stripe-hosted flows.

How Credily uses information

  • To create and secure your account.
  • To send and verify email one-time passcodes.
  • To connect cards and account data through Plaid.
  • To calculate reward comparisons, summaries, and recommendations.
  • To power nearby merchant prompts, notifications, and in-app routing.
  • To manage subscription access, billing status, checkout, and customer portal flows.
  • To process sign-out, session refresh, account deletion, provider revocation, and operational recovery.

Service providers

Credily relies on service providers to operate the app, including Plaid for account linking, Stripe for subscriptions and billing, Firebase/APNs for push notification delivery, backend hosting and database infrastructure, and email delivery infrastructure for account emails.

These providers process data only for the parts of the product they support. Their own terms and privacy practices may also apply.

Product analytics and session replay

If this account setting is enabled, Credily uses PostHog for product analytics and privacy-protected session replay to understand aggregate or session-level app use and improve the experience. Credily does not send its account identifier to PostHog or create PostHog person profiles; PostHog still assigns anonymous installation and session identifiers and adds device and protocol context to events.

Session replay is limited to selected product surfaces. Credily masks designated dynamic regions and excludes sensitive authentication, profile, financial-detail, payment, third-party, and notification-content surfaces. Rendering and masking can vary, so Credily cannot guarantee that every value is always masked.

Turning the setting off stops future capture by the app, but records already sent, in flight, or queued by the analytics software may not be deleted or retracted and may be uploaded after a later opt-in. Credily minimizes captured content and does not represent this control as a purge of previously collected data.

Storage and security

The iOS app stores authentication session tokens in the iOS Keychain. API requests are sent to Credily’s backend, and the backend stores the data needed to operate the service.

Credily’s backend schema includes encrypted storage for sensitive transaction text fields such as merchant name, transaction description, and merchant category code. No system can promise perfect security, but the app is designed to avoid casual exposure of sensitive financial context.

Your choices

  • You can choose not to continue account creation if you do not agree to these terms.
  • You can avoid linking Plaid accounts, though core card recommendation features may not work without connected data.
  • You can manage location and notification permissions in iOS Settings and Credily settings.
  • You can use the single analytics and session replay control in Credily Settings to enable or disable both features. Accounts created before this control was introduced, including incomplete-onboarding and demo accounts, start enabled and can turn it off; new accounts start disabled unless the choice is affirmatively enabled during account creation.
  • You can manage or cancel your subscription through the subscription management flow.
  • You can sign out, and you can request account deletion from Settings.