Privacy Policy

Effective date: January 1, 2025 · Last updated: January 1, 2025

DebtHarassed is built for people in vulnerable situations — dealing with debt harassment is stressful enough without worrying about how your data is used. This policy explains clearly what we collect, why, and how you control it.

1. Information we collect

When you use DebtHarassed, we collect information you provide directly:

Account information: When you sign in with Google, we receive your name and email address. We do not store your Google password.

Case data: Incident descriptions, violation analysis results, generated letters, complaint narratives, and case notes you create within the platform.

Usage data: Pages visited, features used, and timestamps — used to improve the product. We use this data in aggregate only.

Payment information: If you upgrade to Pro, Stripe processes your payment. We store only your Stripe customer ID — never your card number, CVV, or full payment details.

2. How we use your information

We use your information to:

• Provide the DebtHarassed service — analyzing incidents, generating letters, matching attorneys • Send transactional emails — account confirmation, analysis results, referral updates • Process payments and manage your subscription via Stripe • Improve the product through aggregate usage analysis • Respond to support requests

We do not sell your personal information to any third party. We do not use your case descriptions to train AI models. Each analysis is independent and ephemeral — your incident descriptions are processed by Claude (Anthropic) and not stored by Anthropic under our enterprise agreement.

3. Data sharing

We share your information only in the following circumstances:

Attorney referrals: If you request a referral, we share your case summary (violation count, incident types, potential damages) with the matched attorney. We share your contact information only if you explicitly authorize it.

Service providers: We use Supabase (database), Stripe (payments), Resend (email), Vercel (hosting), and Anthropic (AI analysis). Each operates under their own privacy policy and data processing agreements.

Legal requirements: We may disclose information if required by law, subpoena, or to protect the safety of users.

We do not share your data with debt collectors, credit bureaus, or financial institutions.

4. Data security

Your data is encrypted in transit (TLS) and at rest (AES-256 via Supabase). We use row-level security to ensure users can only access their own case data.

Case descriptions and violation reports are sensitive. We treat them accordingly: • Database access is restricted to authenticated application connections • No employee has routine access to individual user case content • Stripe handles all payment data under PCI DSS compliance • We use Vercel's edge network which provides DDoS protection and secure key management

5. Your rights

You have the right to:

Access: Request a copy of all data we hold about you (email privacy@debtharassed.com). Correction: Update inaccurate information via your account settings. Deletion: Delete your account and all associated data from the Settings page. This is immediate and irreversible. Portability: Export your cases, letters, and violation reports as a JSON file from Settings. Opt-out: Unsubscribe from non-transactional emails at any time via the unsubscribe link.

CCPA (California): California residents have additional rights under the California Consumer Privacy Act. We do not sell personal information. Contact us to exercise your CCPA rights.

GDPR (EU): EU residents have rights under GDPR including right to erasure and right to object to processing. Contact privacy@debtharassed.com to exercise these rights.

6. Data retention

We retain your data as long as your account is active. If you delete your account, all personal data and case content is permanently deleted within 30 days. Anonymized, aggregate analytics data (no personal identifiers) may be retained for product improvement.

Stripe may retain transaction records for up to 7 years as required by financial regulations.

7. Cookies

We use only essential cookies:

Session cookie: Required for authentication — expires when you close your browser or sign out. CSRF token: Security token to prevent cross-site request forgery.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not use Google Analytics or similar tracking services.

8. Children

DebtHarassed is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have collected information from a minor, contact us immediately at privacy@debtharassed.com and we will delete it promptly.

9. Changes to this policy

We may update this policy as the product evolves. We will notify you of material changes via email or a prominent notice on the platform at least 30 days before they take effect. The effective date at the top of this page will always reflect the most recent update.

10. Contact

For privacy questions, data requests, or to report a concern:

Email: privacy@debtharassed.com Response time: Within 5 business days

DebtHarassed does not provide legal advice. This privacy policy does not create an attorney-client relationship.