CreditMaxerCreditMaxer
The appCard HubLoan HubCredit UnionsCrashcourseStarting creditReports & scoresLimit increasesAZEO
Get started

Privacy policy10 min read

Everything we know, on one page.

CreditMaxer reads your cards and loans so it can coach you, which only works if you trust us with them. This page lists what we hold, where each piece comes from, who else touches it, and how to take it back. Plain English, names named, nothing hidden in a definition.

Effective
September 17, 2026
Applies to
Website · Web app · iPhone app
Operated by
GuardianLive

The route your account data takesRead-only · Liabilities only

Your bankWhere the numbers live
PlaidSigns in, reads, passes on
CreditMaxerEncrypted, per-user rows
YouThe app on your phone
  • CrossesBalances, limits, statement dates, APRs, minimum payments. We request Plaid’s Liabilities product only. We do not request transactions or Plaid’s identity product.
  • Stops hereYour bank login. You type it into Plaid, never into CreditMaxer. Plaid sends us the numbers and an access token, which we encrypt. The password never reaches us.
  • CrossesUtilization, the AZEO plan, due dates, reminders. Coaching computed from the numbers, shown in the app and sent as push notifications you chose.
Fig. 1The route. Your bank’s numbers reach us through Plaid, read-only. Your bank login goes to Plaid and never travels on to us.
On this page
  1. 1What this covers
  2. 2What we hold
  3. 3How we use it
  4. 4Who else touches it
  5. 5The advisory report
  6. 6Your controls
  7. 7Security
  8. 8How long it stays
  9. 9Who it is for
  10. 10Your state rights
  11. 11Changes

1What this covers.

This policy covers the website at creditmaxer.ai, including the Card Hub, the Loan Hub, and the credit-union directory; the CreditMaxer app for iPhone; and the CreditMaxer web app wherever we offer it. Together they are the Service. It is operated by GuardianLive, and the one inbox for anything about your data is admin@creditmaxer.ai.

CreditMaxer is a credit coaching tool. It tracks the cards and loans you connect or enter, plans AZEO timing, reminds you before statements close, advises on limit-increase windows, compares cards and lenders by their numbers, simulates score moves, and writes an optional monthly advisory report. It is not a bank, a lender, a credit bureau, or a credit repair company. It never pulls your credit report and never moves money.

Reading the public site collects nothing beyond what any web server records. Everything else on this page starts when you create an account.

2What we hold.

We keep only what the coaching needs, and we can name all of it. The ledger below is the complete list: each kind of data, where it comes from, and where it sits.

Everything we hold, and where it comes from14 kinds

WhatDetailsFromWhere it sits

  • AccountEmail address, a password (hashed by Supabase, our sign-in provider; we never see it), display name, avatar choice, and time zone. The invite code you sign up with is checked and counted, not stored with your account.YouOur database
  • Phone numberIf you enter one at sign-up or choose SMS as your second factor. Used to send the six-digit code and for nothing else.YouOur database
  • ProfileGoals you pick during onboarding, and the figures you choose to enter: annual income, employment status, housing status, monthly housing payment, and monthly spending estimates for card recommendations.YouOur database
  • Connected accountsFor each card or loan you link: institution name, account name and type, last four digits, credit limit, current and statement balances, statement close and due dates, minimum payment, APR, last payment date and amount; for loans, principal, balance, monthly payment, rate, and opening date.PlaidOur database
  • Cards and loans you add by handThe same fields, as you typed them, plus any correction you make to a synced number.YouOur database
  • Credit snapshotScores you enter yourself: the value, the model, the bureau, the date, and anything you report alongside them such as hard inquiries or derogatory marks. We never pull your credit report.YouOur database
  • Coaching activityThe card you chose for AZEO, reminders and action items, limit-increase requests you log, simulator scenarios you save, and the advisory reports we generate for you.UsOur database
  • Consent choicesThe date and time you turned on each of the three consents: credit score storage, account aggregation, AI features.YouOur database
  • NotificationsA push token for your phone, its platform, device name, and app version; the topics you muted and the hour you want reminders; and a log of each reminder we sent, including its text.Your deviceOur database
  • Sponsored link clicksWhen you use a Sponsored link in the Loan Hub: which lender and product, the time, and your account id if you were signed in. No IP address, no browser details.YouOur database
  • Security trailAn audit log of sensitive events: sign-ins, bank connections, deletions. Sign-in attempts are also counted per IP address to block guessing; those counters are deleted after one day.UsOur database
  • Server logsEvery request to the website and the API leaves the ordinary hosting record: IP address, browser, the page or endpoint, the time. We run no analytics, advertising, or session-replay software.Your deviceHosting logs
  • On your phone onlyYour signed-in session, encrypted with a key in the phone's secure hardware. A snapshot of your last dashboard so the app opens instantly, cleared when you sign out. Your app-lock and appearance settings. Face ID is checked by iOS; the app only learns yes or no.Your deviceYour phone
  • In your browser onlyYour light-or-dark choice, and the inputs you type into the Card Hub calculators. They never leave your browser.Your deviceYour browser
Fig. 2The ledger. “You” means you typed it. “Plaid” means it came from your bank through Plaid. “Your device” means your phone or browser sent it on its own.

What we do not collect

  • Social Security number, date of birth, or postal address. The app never asks, and no table holds them.
  • Transactions. We ask Plaid for balances and terms, not for what you bought.
  • Your bank login. It goes to Plaid and never reaches us.
  • Location, contacts, photos, or an advertising identifier. The app requests none of these permissions.
  • Anything from a tracker. No analytics, advertising, crash-reporting, or session-replay software runs on the site or in the app.

Cookies

The website sets the cookies that keep you signed in, and nothing else. There is no cookie banner because there is nothing to opt out of. Your light-or-dark choice lives in your browser’s own storage.

3How we use it.

Every kind of data in the ledger is used for one or more of these, and for nothing else:

  • Coaching. Computing utilization, building the AZEO plan, showing due dates, working out limit-increase windows, ranking cards and lenders by their value to you, and running the score simulator.
  • Reminders. Sending the push notifications you turned on, at the hour you chose, about the topics you did not mute.
  • The advisory report, once a month, only after you turn on AI features. Part 5 shows exactly what it sees.
  • Keeping your account yours. Signing you in, two-factor codes, blocking password guessing, and the audit trail.
  • Paying for the service. Counting clicks on Sponsored links so a lender can pay us a commission. Which links are sponsored is disclosed where they appear, and payment never changes a ranking.
  • Talking to you. Answering support email, and telling you about security issues or changes to this policy.
  • Improving the product, by looking at how features are used in aggregate, never by reading an individual account for its own sake.
  • The law. Meeting legal obligations and answering valid legal process.
  • We do not sell it

    Not for money, not for anything else, and not for cross-context behavioral advertising as California defines it. No advertiser gets your data.

  • We do not train models on it

    Your data is never used to train a machine-learning model, ours or anyone else’s, including when it is sent for the advisory report.

  • We do not act for you

    Connections are read-only. CreditMaxer cannot make a payment, move money, apply for a product, or change anything at your bank.

4Who else touches it.

We run on other companies’ infrastructure, the way every app does. Each one is under contract to use what it receives only to do its job for us. This is the whole list.

Who else touches it10 companies

  • PlaidAccount aggregationSigns in at your bank on your behalf and reads your card and loan figures. We request its Liabilities product only.Your bank login, typed into Plaid and never seen by us. From us, a random id for your account. We never send Plaid your name, email, or phone. What Plaid collects itself is covered by its policy.Their policy
  • SupabaseSign-in and databaseHolds every row in the ledger above in Postgres, encrypted at rest, and runs sign-in, two-factor, and the confirmation and reset emails.Everything we hold. Your password, hashed. Your phone number if you use SMS codes.Their policy
  • TwilioSMS delivery, via SupabaseCarries the two-factor text message. We do not call Twilio ourselves; Supabase does, as its SMS provider.Your phone number and the six-digit code, only when you use SMS two-factor.Their policy
  • VercelHostingServes the website and the API the app talks to.The ordinary request record: IP address, browser, page or endpoint, time.Their policy
  • AnthropicLanguage model, advisory reportWrites the once-a-month advisory report when you have turned on AI features. See part 5 for exactly what it sees.Your account figures and self-reported finances under an opaque id. Never your name, email, phone, or account numbers.Their policy
  • Microsoft AzureAlternate model providerCan run the same report through Azure OpenAI if we switch providers, with request storage turned off.The same request, and nothing else.Their policy
  • ExpoPush notificationsDelivers reminders to your phone through Apple's push service.A push token, your phone's platform, name, and app version, and the text of each reminder.Their policy
  • AppleApp Store, push, Face IDDistributes the app, relays push notifications to iPhones, and performs the Face ID check on the device.What Apple always sees for an app you install. Face ID never leaves the phone; we only learn whether it passed.Their policy
  • Logo and card-art hostsImagesBank logos load from logo.dev with a DuckDuckGo fallback, and card art from the catalog's image host.The institution's web domain and, like any image request, your IP address. Nothing about your account.Their policy
  • Affiliate networksCJ, Impact, FlexOffersTrack the Sponsored links in the Loan Hub so a lender can pay us a commission. Marked Sponsored wherever they appear.Nothing from us. When you click, you leave for the lender; the network sees the click and may set its own cookie on its own site.Disclosure
Fig. 3The vendor roll. If a company is not here, it does not receive your data. We update this figure before we add one.

Plaid, and what connecting a bank authorizes

CreditMaxer uses Plaid Inc. (“Plaid”) to gather your account data from your bank. By connecting an account, you grant CreditMaxer and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from that institution. You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with the Plaid End User Privacy Policy.

Connecting a bank is optional. Plaid’s own screen asks you to agree to that policy before you sign in at your bank, and we link it beside the account aggregation switch and on the bank-linking step of setup. Linking a bank records your account aggregation consent with the date, and unlinking takes the access back (part 6). This page describes what CreditMaxer requests, receives, and keeps. What Plaid itself collects while you connect, from you or from your bank, is set out in Plaid’s policy, not this one.

Two other cases

Legal and safety. We disclose information when the law requires it, in response to valid legal process, or when we believe in good faith that it is needed to protect you, other users, the public, or CreditMaxer from harm.

A change of ownership. If GuardianLive merges, is acquired, or sells the Service, your data can move with it. We will tell you before it becomes subject to a materially different privacy policy, and you can delete your account first.

5The advisory report.

Once a month, if you have turned on AI features, CreditMaxer can write you a report: what moved, what to do next, and why. To write it, a language model at Anthropic (or, if we switch providers, at Microsoft Azure) is shown a summary of your account. It is shown the numbers and nothing that identifies you.

What the model is shownOne report a month · Off by default

Sees

  • Your credit score, its model and bureau, and the projected score
  • Total utilization, and each card’s name, issuer, limit, balance, and APR
  • Each loan’s name, type, balance, payment, and rate
  • The card you chose for AZEO
  • Income, employment status, housing status, and housing payment, if you entered them
  • The goals you picked

Never

  • Your name, email address, or phone number
  • Account numbers, including the last four digits
  • Your bank login or any access token
  • Anything at all, until you turn on AI features
  • Your name, even in the assistant: it sees your first name and nothing else that identifies you
Fig. 4The report’s window. The request carries an opaque id derived from your account, not your account id, and the provider processes it under business terms that do not allow training on it.

The finished report is stored with your account so you can reread it, and is erased with everything else when you delete. Turning AI features off stops new reports.

The in-app assistant works the same way, one question at a time. Each message you send is answered by the same language model, shown the same kind of summary (your accounts, score, inquiries, and the income and housing figures you entered) plus your first name, and nothing else that identifies you. Conversations are stored with your account so you can reopen them: unsaved ones are erased seven days after their last message, saved ones stay until you delete them, and every conversation can be deleted from the app at any time. Nothing you type is used to train a model.

6Your controls.

Most controls are in the app and take effect the moment you use them. The last one is an email.

  1. 1

    Unlink an institution.

    We tell Plaid to revoke its access, delete the encrypted token, and stop syncing. The history you already have stays on your dashboard until you delete it.

    WhereProfile › Connections, or the card’s detail view
  2. 2

    Delete your account.

    Immediate. Every Plaid connection is revoked, then every row tied to you is erased: profile, accounts, scores, plans, reminders, reports, tokens, and push devices. What remains is a dated note that an account was deleted, with nothing personal in it.

    WhereProfile › Edit profile › Delete my account
  3. 3

    Turn a consent off.

    Credit score storage, account aggregation, and AI features are three separate switches. AI features off means no new report is written. The other two record your choice; the data they cover is removed by unlinking the institution, or by emailing us to clear the scores you entered.

    WhereProfile › Privacy & consent
  4. 4

    Choose your reminders.

    Mute any topic, pick the hour they arrive, or switch notifications off for the app in iOS Settings. We send reminders by push only, and we send no marketing email or SMS.

    WhereProfile › Notifications
  5. 5

    Lock it down.

    Every account has a second factor, an authenticator app or SMS, and linking a bank requires it on the current session. Add Face ID lock on the phone so the app opens only for you.

    WhereProfile › Security
  6. 6

    See, fix, or take a copy of your data.

    Most of it you can read and edit in the app. For a machine-readable copy of everything, or a correction you cannot make yourself, email us. There is no export button yet; we will send the file by hand.

    Whereadmin@creditmaxer.ai

7Security.

Credit data is sensitive, so the protections are specific rather than a promise to take it seriously.

  • Encrypted in transit and at rest. Every connection uses TLS, and the database is encrypted on disk.
  • Bank tokens are locked twice. Plaid access tokens are encrypted with AES-256-GCM under a key the database never sees, in a table no app session can read. They are held server-side only and never sent to a phone or browser.
  • One user, one set of rows. Row-level security in Postgres means one account cannot read another’s data even if application code has a bug.
  • Two-factor before a bank. Linking an institution requires a second factor on your session.
  • Your session stays on your phone, encrypted with a key kept in the iPhone’s secure hardware, and optionally behind Face ID.
  • An audit trail. Sign-ins, bank connections, and deletions are logged so unusual activity can be seen.

No system is perfectly secure. If a breach is reasonably likely to harm you, we will tell you without undue delay and as the law requires. Security researchers can write to admin@creditmaxer.ai; we will not pursue a good-faith report.

8How long it stays.

As long as your account is open, and no longer. There is no quiet archive: deleting your account is the retention policy.

Sign upHeld while your account is openUnlink an institutionSame minutePlaid access revoked, token deletedDelete your accountSame minuteEvery row erasedAfterBackups roll off
Fig. 5The retention rail. Unlinking cuts off new data at once and keeps what you already have. Deleting erases everything at once.
  • Open account. Accounts, scores, plans, reminders, reports, and the notification log stay until you remove them or delete your account.
  • After deletion. Your rows are gone from our live database in the same minute. Our database provider keeps encrypted backups for a short rolling window, after which they are gone there too.
  • What survives. A dated record that an account was deleted, with no personal data in it, and Sponsored-click rows with your account id removed. Both exist so we can answer for what happened.
  • Short-lived on its own. Sign-in attempt counters per IP address are deleted after one day.
  • Where the law says longer. If a legal obligation requires us to keep something, we keep that and only that, for as long as required.

9Who it is for.

CreditMaxer is for adults in the United States. You must be 18 or older to have an account. We do not knowingly collect information from anyone under 18; if you believe we have, write to admin@creditmaxer.ai and we will delete it.

The Service is built around U.S. credit scoring and U.S. institutions. Our providers are U.S. companies and process data primarily in the United States. If you use it from elsewhere, you do so on your own initiative and your data is handled here.

10Your state rights.

Several states give residents specific rights over their personal information: California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and a growing list of others. Wherever you live, we give you the same set:

  • Know what we hold about you, which is the ledger in part 2, and receive a copy.
  • Correct anything inaccurate, in the app or by email.
  • Delete it, in the app, at once.
  • Opt out of sale, sharing, and targeted advertising. We do none of these, so there is nothing to opt out of, and we honor the request regardless.
  • Not be treated differently for exercising any of these.

To exercise a right we cannot serve in the app, email admin@creditmaxer.ai from the address on your account. We will verify it is you, respond within the time your state allows, and never charge for it. An authorized agent can act for you with written permission. If we decline a request, we will say why, and you can appeal by replying.

11Changes.

This page describes what the product does today, so it changes when the product does. For a material change, such as a new company on the vendor roll or a new kind of data in the ledger, we will email every open account and post a notice here at least 30 days before it takes effect. The effective date at the top is always the current version.

A person reads every message.

Questions, requests, complaints, or a security report: one inbox, answered by someone who can act on it.

admin@creditmaxer.ai

CreditMaxer is an educational coaching tool. Nothing on this site, in the app, or in this policy is legal, financial, tax, or investment advice, and we do not guarantee any credit score outcome. Our Terms of service and Advertiser disclosure are the other two pages that govern the Service.

CreditMaxer

Learn how the credit system works, then make it work for you: the right card, the right payoff order, and the right moment to ask for more.

Features
  • Card Hub
  • The app
  • Credit Crashcourse
  • Starting your credit journey
  • Limit increases
  • AZEO, explained
  • Reports & scores
  • Loan Hub
  • Credit unions
Company
  • About
  • Contact
  • Create account
Trust
  • Privacy policy
  • Terms of service
  • Advertiser disclosure
  • How we handle data
© 2026 CreditMaxer · Educational tools, not financial advice.
PrivacyTermsContact