Debt Defender

Privacy Policy

Effective date: August 18, 2026

1. What we collect

Account information: the email address and password you use to sign in. Passwords are stored only in hashed form by our authentication provider.

Records you enter: debts, disputes, incidents, phone logs, notes, and letters. This information is sensitive financial information, and we treat it that way.

Basic technical data: logs necessary to operate and secure the service, such as request timestamps and error reports.

Usage measurement: we use Google Analytics to understand how the service is used. It records the pages visited, roughly where in the world the request came from, and details of the browser and device. It is set up for measurement, not advertising, and we do not use it to build advertising audiences.

2. How your information is used

To operate the service: storing your records, showing them to you, and tracking deadlines you create.

To draft a letter: when you generate a dispute letter, the records for that dispute are sent to our AI model provider to produce the letter you requested. For a letter proposing a payment, a settlement, or a hardship waiver, your employment status is included, because that letter argues from your circumstances. No other part of your personal information is sent.

To check a call you log: when you save a phone log that includes a summary, that summary is sent to our AI model provider to identify conduct that may not be permitted. Only the summary is sent. The time of a call, and how often you have been called, are checked inside the application and are never sent anywhere.

Records are sent for processing only, and only when you take one of the actions above. Debt Defender has no AI chat, and your records are never sent to a model for any other purpose.

We do not sell your information. We do not share your records with debt collectors, creditors, or data brokers.

3. Where your information lives

Your records are stored in a managed Postgres database with row-level access controls, so your records are readable only by your account. The application and database are hosted on infrastructure in the United States.

4. Cookies

Cookies keep you signed in, and Google Analytics sets its own cookies to recognise a returning browser and to measure how the service is used. There are no advertising cookies, and nothing here is used to target ads to you elsewhere.

Analytics runs on every page, including the pages you see once you are signed in. That means Google receives the address of the page, which for a record you are viewing includes its identifier. It does not receive the contents of your records, your name, your email address, or anything you have typed. You can stop it entirely with any browser setting or extension that blocks analytics, and the service will work exactly the same.

5. Retention and deletion

Your records are kept for as long as your account exists. Deleting a record removes it from the application. You can delete everything you have entered at once from the Settings page, which is immediate and cannot be undone. Your sign-in account is held by our authentication provider and is removed on request: contact us and we will delete it. Deleted rows may persist in encrypted database backups until those backups age out on the provider's retention schedule.

6. Security

All traffic is encrypted in transit. Database access is restricted by row-level security policies tied to your authenticated session. No method of storage is perfectly secure, and we cannot guarantee absolute security, but we design the service so that your records are accessible only to you.

7. Children

The service is not directed to children under 13, and we do not knowingly collect information from them.

8. Changes to this policy

If we make material changes to this policy, we will post the updated policy with a new effective date.

9. Contact

Questions about this policy or requests to delete your data may be sent to the operator of this service through the contact information provided in the application.