Privacy Policy
Last updated 2 August 2026
Privacy Policy
Last updated: 2 August 2026 Who we are: Credda, Inc. ("Credda", "we") Contact: martin@credda.io
In short
Credda builds a reliability score you own and can carry between platforms. To do that we record commitments you make, whether they were kept, and activity from accounts you choose to connect. Your score is calculated by a published formula; no person at Credda can raise or lower it by hand, and no AI decides it either. If something on your record is wrong, you can dispute it, and the score recalculates from the corrected record.
This page explains what we hold, why, who else sees it, and what you can ask us to do.
Where Credda is offered
Credda is offered only to users in the United States and is hosted in the United States. We don't direct the Service at people in the UK, EU or EEA.
Who this covers
- Account holders, people who sign up at credda.io.
- Counterparties, people named on a commitment who confirm or reject it by
- Platform users, where a platform we work with reports events about you. In
What we collect
You give us:
- Account details: email address, username, display name, password (stored only
- Commitments: what you agreed to do, with whom, by when, and its value or
- Anything you write: support messages, comments, attachments, evidence you
- Organization details, if you create or join a team.
You connect:
- When you link GitHub, GitLab, Upwork, Bitbucket, LinkedIn, Google or Stripe,
We generate:
- Your reliability score, its history, and the events behind it.
- Advisory signals for our own review (for example, patterns suggesting
- Advisory AI text: summaries and drafts that help our support team or coach
We do not collect payment card details (Stripe handles those), and we do not buy personal data from data brokers.
Why we use it
| What for | Why |
|---|---|
| Running your account and the service | To provide what you signed up for |
| Calculating and publishing your score | To provide the core product |
| Confirming a commitment with a counterparty | A two-party record is only meaningful if both parties confirm |
| Detecting gaming, collusion and fraud | To keep the network trustworthy |
| Support and service email | To answer you and to tell you about things that affect your account |
| Billing | To take payment where you have a paid arrangement |
| Product improvement | To make the Service better |
We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act, and we do not use it for advertising.
Automated decisions about you: read this one
Your score is produced automatically by a deterministic formula from your recorded events. The formula, its factors and their weights are published at credda.io/trust, and any score can be reproduced from the events behind it.
Platforms may use your score to decide whether to work with you. That is the point of the product, and you should know it. Platforms are contractually prohibited from using it for credit, employment, insurance or housing decisions — see section 8 of the Terms.
Two commitments we make:
- No one can adjust your score by hand, not you, not a platform, not Credda
- If your record is wrong, you can fix the record. Raise a dispute on the
Who else sees your data
You choose what's public. Your public profile, badge, and any credential you share show what you decide to share, and a credential lets you disclose full detail, your score band only, or a minimal proof.
We share with service providers who help us run Credda:
| Who | What for |
|---|---|
| Amazon Web Services | Hosting and database (United States) |
| Anthropic | Advisory AI features: support summaries, reply drafts, coaching |
| Stripe | Payments |
| GitHub, GitLab, Upwork, Bitbucket, LinkedIn, Google | Only where you connect that account |
| Our email delivery provider | Sending service email |
We may also disclose data where the law requires it, or to protect the rights and safety of our users.
How long we keep it
We keep your account data while your account exists. You can delete your account from Settings at any time.
Because a score must be reproducible from the events behind it, and because a commitment is a record belonging to two people, deleting your account does not erase the other party's record of an agreement you made with them. Where we retain events after deletion, we hold them in pseudonymous form; our scoring service is keyed to an internal identifier, not your name or email.
Your rights
You can ask us to: give you a copy of your data; correct it; delete it; or tell you what we've collected and who we've shared it with.
If you live in California, the CCPA gives you these rights specifically, including the right not to be discriminated against for exercising them. We do not sell or share your personal information, so there is nothing to opt out of, but you can still ask us the questions above.
To exercise any of these, email martin@credda.io. We'll respond within 45 days, and we'll tell you if we need longer.
Security
We protect your data with HTTPS everywhere and HSTS, a database that is not reachable from the internet, passwords stored only as bcrypt hashes, scoped API keys, sign-in verification for unrecognised devices, and the ability to end every session on your account at once.
We don't claim any security certification, and we'll say so plainly rather than imply otherwise. If you need a security review before working with us, ask.
If you believe you've found a vulnerability, please tell us at security@credda.io, or see credda.io/.well-known/security.txt.
Children
Credda isn't for under-18s and we don't knowingly collect their data. If you think a child has given us personal information, email us and we'll delete it.
Changes
We'll post changes here and update the date above. For anything significant, we'll tell you directly.
Questions: martin@credda.io
