← back to credgle

Privacy Policy

Last updated · 2026-05-11 — DRAFT · This is a working draft. Legal counsel review required before launch.

Credgle takes privacy seriously. This page describes what data we collect, why we collect it, and what you can do with it. Counsel review pending before launch.

What we collect

Why we collect it

Who we share with

We do not sell your personal data. We share only the minimum necessary to operate the service:

Your rights

Subject to your local law (GDPR / CCPA / etc.), you can request export of your data, deletion of your account, correction of inaccurate fields, or opt-out of sale/sharing of personal information. Use the controls on /account/data or email privacy@credgle.com. We respect the Sec-GPC: 1 opt-out signal.

Retention

Active-account data is retained for as long as your account is open. Ledger entries are retained for 7 years to satisfy financial-records obligations even after account deletion; they are anonymised after the deletion grace window.

Security

TLS 1.3 everywhere. Sessions are stateful cookies (no JWT). Passwords are hashed with Argon2id. KYC documents are encrypted with KMS-managed keys. Detailed posture in our security documentation.