Privacy Policy
This policy explains what Credily collects, why it is used, and the controls you have.
Information you provide
Credily collects the information you enter during sign-in, onboarding, and Settings, such as your email address, name, phone number, and rewards preference.
Credily also stores account status information needed to run the app, including onboarding state, session state, subscription state, and account deletion request state.
Connected financial data
If you connect accounts with Plaid, Credily may receive and store information such as institution details, linked card names, account identifiers, card profile selections, transaction dates, merchant names, descriptions, amounts, currencies, categories, and merchant category codes.
Credily uses this data to show connected cards, compare card rewards, calculate reward-related summaries, label transaction context, and produce recommendations.
When you confirm which saved card profile matches a connected account, Credily may use a keyed, non-readable fingerprint derived from Plaid's institution-provided official account name, together with the institution, account type, subtype, and confirmed catalog card, to improve future account-to-card suggestions for other customers. The shared matching record does not contain the readable account name, mask, Plaid account identifier, transaction data, or your Credily account identifier.
To prevent one underlying account from contributing more than once, Credily also stores a separate keyed, non-readable source-account fingerprint derived from Plaid's persistent account identifier when available, or from the institution and account mask as a fallback. The shared learner does not retain the raw identifier or mask.
Location and nearby recommendations
If you grant location permission, Credily can use location signals to find nearby merchants and recommend which linked card may be best at that location.
If the product analytics and session replay setting is enabled, Credily may send PostHog a limited event when a nearby card recommendation is presented. This event includes a random event identifier and presentation time, but no Credily account, merchant, notification, coordinate, speed, heading, altitude, or address data.
Notifications and device data
If you allow notifications, Credily may store a push notification token issued for your device so the backend can send alerts. Tokens are issued through Firebase Cloud Messaging, which delivers to iOS devices through Apple Push Notification service and to Android devices through Google Play services. Notification preferences and notification history may be stored so the app can show unread counts and route you to the relevant screen.
You can turn notifications off in your Android or iOS system settings or in Credily settings. Some background education or nearby alert behavior depends on those permissions.
Subscriptions and payments
Credily uses RevenueCat to synchronize subscription status and entitlements. Credily stores subscription identifiers, product identifiers, status, period dates, billing issue state, and related entitlement metadata needed to operate the subscription.
Purchases, payment processing, renewal, payment methods, receipts, refunds, and cancellation happen through the store where you subscribed — the Apple App Store on iOS or Google Play on Android. Credily does not receive or store your full payment-card details.
How Credily uses information
- To create and secure your account.
- To send and verify email one-time passcodes.
- To connect cards and account data through Plaid.
- To calculate reward comparisons, summaries, and recommendations.
- To power nearby merchant prompts, notifications, and in-app routing.
- To manage subscription access and billing status.
- To process sign-out, session refresh, account deletion, provider revocation, and operational recovery.
Service providers
Credily relies on service providers to operate the app, including Plaid for account linking, RevenueCat for subscription entitlement synchronization, Apple for App Store purchases and billing on iOS, Google for Google Play purchases and billing on Android, Firebase Cloud Messaging with Apple Push Notification service and Google Play services for push notification delivery, backend hosting and database infrastructure, and email delivery infrastructure for account emails.
These providers process data only for the parts of the product they support. Their own terms and privacy practices may also apply.
Product analytics and session replay
If this account setting is enabled, Credily uses PostHog for product analytics and privacy-protected session replay to understand aggregate or session-level app use and improve the experience. Credily does not send its account identifier to PostHog or create PostHog person profiles; PostHog still assigns anonymous installation and session identifiers and adds device and protocol context to events.
Session replay is limited to selected product surfaces. Credily masks designated dynamic regions and excludes sensitive authentication, profile, financial-detail, payment, third-party, and notification-content surfaces. Rendering and masking can vary, so Credily cannot guarantee that every value is always masked.
Turning the setting off stops future capture by the app, but records already sent, in flight, or queued by the analytics software may not be deleted or retracted and may be uploaded after a later opt-in. Credily minimizes captured content and does not represent this control as a purge of previously collected data.
Storage and security
On iOS, the app stores authentication session tokens in the iOS Keychain. On Android, session credentials are held by the Firebase Authentication SDK in the app’s private, sandboxed storage. API requests are sent to Credily’s backend, and the backend stores the data needed to operate the service.
Credily’s backend schema includes encrypted storage for sensitive transaction text fields such as merchant name, transaction description, and merchant category code. No system can promise perfect security, but the app is designed to avoid casual exposure of sensitive financial context.
Shared card-matching evidence uses keyed fingerprints and a random contributor identifier. The mapping between that contributor identifier and your account is removed when your account is deleted.
Deleting your account and data
You can request account deletion in two ways. In the app, use Settings. Without signing in, use https://credily.prodygyn.com/delete-account and enter the email address stored on the account.
The web request does not require a password or login. Credily emails a one-time link to the address already stored on the account to check that you control it. Opening that link does not delete anything; you still have to confirm on the page, and the link expires.
Once you confirm, Credily removes your account and the data tied to it from its live systems, including profile and contact details, connected-account and card records, transaction and reward data, notification tokens and history, and local subscription records. Credily also requests revocation of the bank connections you linked through Plaid.
Credily keeps a limited record of your legal acceptance and of the deletion request itself, such as an opaque request identifier, status, and timestamps, for legal, security, and fraud-prevention purposes. Credily does not keep this as a usable copy of your account.
A de-identified card-matching contribution may remain after you disconnect Plaid or delete your Credily account. After account deletion, Credily removes the mapping needed to associate that contribution with your Credily account; the retained record contains no readable account name, raw mask, raw Plaid account identifier, transaction data, or Credily account identifier.
Where a provider supports account-linked deletion, Credily sends the required deletion or revocation request; provider schedules vary. Records that are not linked to your account, such as the anonymous analytics and session identifiers described above, cannot be matched to you and are not removed through this request. Store purchase records stay with Apple or Google under their own terms.
Provider cleanup and the removal of copies inside routine backups can lag the deletion of live data rather than happening instantly.
Deletion usually completes within 24 hours and no later than 30 days after you confirm. Credily emails you when the request is received and again when it is complete.
Deleting your Credily account does not cancel an App Store or Google Play subscription. Cancel it separately in your Apple ID subscription settings or your Google Play subscriptions settings, depending on where you subscribed.
If you cannot receive email at the address stored on your account, contact admin@prodygyn.com and Credily will help you complete the request.
Your choices
- You can choose not to continue account creation if you do not agree to these terms.
- You can avoid linking Plaid accounts, though core card recommendation features may not work without connected data.
- You can manage location and notification permissions in your Android or iOS system settings and in Credily settings.
- You can use the single analytics and session replay control in Credily Settings to enable or disable both features. Accounts created before this control was introduced, including incomplete-onboarding and demo accounts, start enabled and can turn it off; new accounts start disabled unless the choice is affirmatively enabled during account creation.
- You can manage or cancel your subscription through the subscription management flow.
- You can sign out, and you can request account deletion from Settings in the app or, without signing in, at https://credily.prodygyn.com/delete-account.