Privacy Policy
1. Who We Are
CredFlow ("CredFlow," "we," "us," or "our") is a Chrome browser extension and web dashboard that helps users track their AI chat usage limits in real time. CredFlow is an independently operated product, currently run as a sole proprietorship based in Nashik, Maharashtra, India. We are not a registered company at this stage; if that changes, this policy will be updated to reflect the legal entity details.
This Privacy Policy describes how we collect, use, store, and protect information when you use the CredFlow extension, the web dashboard at credflow-dashboard.vercel.app, or the website at credflow.vercel.app.
If you have questions about who is responsible for your data, contact us at hello@credflow.app.
By installing the extension or creating an account, you acknowledge that you have read and understood this policy.
2. What We Collect
2.1 Usage data
When you use the CredFlow extension on a supported platform (currently claude.ai and chatgpt.com), the extension detects when a message is sent and reads two floating-point values that the platform exposes in its session state:
- session_utilization — a decimal value between 0.0 and 1.0 representing your current session usage
- weekly_utilization — a decimal value between 0.0 and 1.0 representing your current weekly usage
We also record the timestamp of each capture. This allows us to display usage history, 7-day trends, and estimated reset times.
The extension is designed so that message content is not collected, stored, or transmitted. We do not intentionally collect message text, conversation history, prompts, or AI responses, and the extension's architecture does not include any mechanism to do so.
2.2 Account data
If you create a CredFlow account, we store your email address and a hashed password managed through Supabase Auth. Passwords are hashed before storage. We do not have access to your plain-text password.
2.3 Waitlist data
If you join our waitlist, we store your email address and the timestamp of your submission. This information is used only to notify you when the extension becomes available. Waitlist data is deleted within 30 days of the final launch notification being sent, or immediately upon your request.
2.4 Technical metadata
To maintain extension reliability, we store the following operational data:
- selector_version — a version identifier for the DOM elements the extension monitors on supported platforms. This changes when a platform updates its interface and helps us detect when the extension needs an update.
- last_sync_at — the timestamp of the most recent successful data sync
- consecutive_failures — a count of consecutive sync failures, used for debugging
- tracking_status — whether the extension is currently active on a supported site
This metadata does not include page content, browsing history, keystrokes, or clipboard data.
2.5 Server and infrastructure logs
When you use the dashboard or the extension communicates with our backend, our hosting provider (Supabase, hosted on AWS) automatically logs your IP address and browser user-agent string as part of standard infrastructure operation. These logs are used for security monitoring and debugging. They are retained for approximately 30 days and are not shared with third parties beyond what is required to operate the infrastructure.
3. What We Do Not Collect
CredFlow is not designed to collect and does not intentionally collect:
- The content of any message you send or receive on any platform
- Your conversation history or prompt text
- Keystrokes or clipboard contents
- Full URLs, query parameters, or path fragments of pages you visit
- Browsing history outside of detecting supported site hostnames
- Device fingerprints or advertising identifiers
- Data from any website other than claude.ai and chatgpt.com
- Payment card numbers or financial account details (handled entirely by Stripe)
4. How We Use Your Data
We use the data we collect only for the following purposes:
- To provide the core service — showing you your session utilization, weekly utilization, and estimated reset times in the popup and dashboard
- To send usage alerts — Chrome browser notifications when you reach configured thresholds (default: 80% and 95%)
- To display usage history — the 7-day bar chart and trend data in the dashboard
- To maintain extension reliability — using health metadata to detect and fix breakages caused by platform interface changes
- To notify waitlist members — a single notification email when the extension is available on the Chrome Web Store
We do not sell personal data. We do not use personal data for advertising. We do not share personal data with third parties for their own marketing purposes.
5. Data Storage and Security
All user data is stored on Supabase, hosted on AWS in the ap-south-1 region (Mumbai, India). Row-Level Security (RLS) is configured on every database table to restrict data access to authenticated users acting on their own records. All communication between the extension, the dashboard, and our backend is encrypted over HTTPS. Passwords are hashed and not stored in plain text.
While we implement commercially reasonable technical and organizational measures to protect your data, no method of electronic storage or transmission over the internet is completely secure. We cannot guarantee absolute security, but we will notify affected users and relevant authorities promptly if we become aware of a data breach, as required by applicable law.
5a. International Data Transfers
CredFlow's backend infrastructure is hosted in Mumbai, India (AWS ap-south-1). If you access CredFlow from outside India, your data may be transferred to and processed in India and in other jurisdictions where our service providers operate, including the United States (Vercel, Stripe) and Ireland (Supabase infrastructure). These countries may have data protection laws that differ from those in your country. By using CredFlow, you acknowledge this. Where required by applicable law, we rely on appropriate safeguards to protect your data during such transfers.
5b. Legal Basis for Processing
For users in the European Economic Area, the United Kingdom, and other jurisdictions where a legal basis for processing is required, we process personal data on the following bases:
- Contract performance — processing your account data and usage snapshots is necessary to provide the Service you signed up for
- Legitimate interests — processing technical metadata and infrastructure logs is necessary for security, reliability, and fraud prevention, where those interests are not overridden by your rights
- Consent — for waitlist communications and optional email notifications, where you have provided explicit consent
Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
6. Data Retention
- Free tier — usage snapshots: Retained for 90 days, then deleted automatically.
- Pro tier — usage snapshots: Retained for 1 year.
- Account data: Retained until you request account deletion.
- Waitlist data: Deleted within 30 days of the final launch notification, or on request.
- Infrastructure logs: Retained for approximately 30 days by our hosting provider.
If you downgrade from Pro to Free, usage snapshots older than 90 days will be deleted within 30 days of the downgrade. We may retain limited records where required by law, for fraud prevention, or for resolving disputes.
7. Chrome Extension Permissions
The CredFlow extension requests the following Chrome permissions, and only these:
- storage — to cache your usage data locally in
chrome.storage.localso the popup loads instantly without a network request - tabs — to read the hostname of the active tab (e.g., claude.ai) so the extension knows when it is on a supported platform. We use only the hostname for routing purposes. We do not read, store, or transmit full URLs, page titles, query parameters, or any other tab data.
- notifications — to send you browser notifications when your usage crosses configured alert thresholds
- alarms — to schedule periodic background tasks, including JWT token refresh every 50 minutes and data syncs
We do not request history, bookmarks, cookies, webRequest, or any permission that would allow the extension to read content from arbitrary websites.
8. Your Rights
Depending on where you are located, you may have rights regarding your personal data. Regardless of your location, we honor the following requests:
- Access — you may request a summary of what data we hold about you
- Export — you may request a CSV export of your usage history
- Correction — you may request correction of inaccurate account data
- Deletion — you may request deletion of your account and all associated data. We will action this within 7 days, except where we are required to retain certain records by law.
- Waitlist removal — reply to any waitlist email or contact us directly
- Notification opt-out — disable alerts at any time from the extension popup settings
To exercise any of these rights, contact us at hello@credflow.app. We aim to respond within 48 hours.
If you are located in the EU or UK, you may also have rights under GDPR or UK GDPR, including the right to object to processing and the right to lodge a complaint with your local supervisory authority. If you are located in California, we do not sell your personal information; California residents may request disclosure or deletion of collected data by contacting us at the email above.
9. Third-Party Services
CredFlow uses the following third-party services to operate:
- Supabase — database, authentication, and edge functions. Data stored in Mumbai (AWS ap-south-1).
- Vercel — hosting for the web dashboard and landing site.
- Stripe — payment processing for the Pro tier. CredFlow does not see, store, or have access to your payment card details. All payment data is handled entirely by Stripe and subject to Stripe's privacy policy.
- Google Fonts — font delivery. Standard browser request; no personally identifiable information is sent beyond your IP address.
Your use of CredFlow is also subject to the terms and privacy policies of these providers.
10. Children
CredFlow is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify registered users by email. We encourage you to review this page periodically. Continued use of CredFlow after a policy update constitutes your acceptance of the revised policy.
12. Contact
If you have questions or concerns about this policy, or want to exercise any of your rights, please contact us:
Email: hello@credflow.app
We aim to respond within 48 hours.