← Back

Credstree — Privacy Policy

Last updated: April 2026

1. What We Collect

We collect only what is necessary to operate the service:

  • Account data: email address, username, password (hashed)
  • Profile data you voluntarily enter in the dashboard (name, bio, experience, etc.)
  • Payment data: handled by our payment processor — we never store card numbers
  • Pro tier analytics: daily page view counts for your CV (aggregate only, no visitor PII)

2. What We Do NOT Collect

Your public CV page has no contact forms, no tracking pixels, and no cookies placed on visitors.

Visitors who view your published CV are not tracked, profiled, or identified in any way. The only data collected from a CV page view is an anonymous page view count (Pro tier only), which contains no personally identifiable information about the visitor.

3. How We Use Your Data

  • To operate and display your CV/portfolio
  • To manage your subscription and billing
  • To send transactional emails (account creation, password reset)
  • We never sell or share your data with third parties for marketing

4. Data Storage & Security

Your data is stored in a PostgreSQL database hosted on Supabase with encryption at rest. Profile images are stored in Supabase Storage. All data transfer uses HTTPS/TLS. Passwords are never stored in plaintext.

5. Your Rights (GDPR)

You have the right to:

  • Access all data we hold about you
  • Correct inaccurate data via your dashboard
  • Delete your account and all associated data at any time
  • Export your data on request

To exercise any right, delete your account from the dashboard Settings page, or contact us at privacy@credstree.app

6. Cookies

We use only essential session cookies required for authentication. No advertising, tracking, or analytics cookies are used. Pro password-protected CVs use a single httpOnly cookie to remember an authenticated PIN session.