φPHIMINDFLOW

Privacy Policy

Last updated: April 28, 2026

This Privacy Policy explains how PHIMINDFLOW ("we", "us") collects, uses, stores, and protects your personal and financial information when you use the credit-restoration tools at phimindflow.com/credit (the "Service").

1. Information We Collect

  • Account information: name, email, password (hashed), phone, mailing address.
  • Credit-restoration data: credit scores you log, negative items you track, dispute letters you draft, and credit reports / IDs / proof-of-address documents you upload.
  • Sensitive identifiers (optional): date of birth and last 4 digits of SSN — used only to populate dispute letters at your direction.
  • Usage data: standard server logs (IP, user-agent, page accessed) for security and abuse prevention.

2. How We Use Your Information

  • To provide the Service: store your dashboard data, generate dispute letters, hold your uploaded documents.
  • To communicate with you about your account (password resets, security alerts, important updates).
  • To comply with legal obligations and respond to lawful requests.

We do not sell your personal information. We do not share it with third parties for advertising.

3. How We Protect Your Information

  • Encryption in transit (HTTPS) on every page.
  • Encryption at rest on the database and file storage layer (Supabase + AWS infrastructure).
  • Per-user row-level security: each account can only read or write its own data — verified at the database level.
  • File uploads stored in a private bucket scoped to your user folder. Files are not publicly addressable.
  • Passwords stored as hashes (we cannot read your password).

4. Subprocessors

  • Supabase (auth, database, storage)
  • Vercel (web hosting and serverless functions)
  • Stripe (payment processing for paid tiers; we never see or store your card numbers)
  • Resend (transactional email delivery)
  • LetterStream (when you opt in to mailed dispute delivery)

5. Your Rights

You can: export your data, correct it, or delete your account at any time by emailing franckydelissaint@gmail.com. We will permanently remove your data within 30 days of a deletion request, except where retention is required by law.

California residents (CCPA) and New York residents (SHIELD Act) have additional rights — including the right to know, the right to delete, and the right to non-discrimination for exercising those rights.

6. Data Retention

We retain your data while your account is active. If you delete your account, we permanently delete your dashboard data and uploaded files within 30 days. Backups are retained for an additional 7 days then permanently destroyed.

7. Children

The Service is not directed at people under 18. We do not knowingly collect data from minors.

8. Changes

We will post changes to this policy on this page with a new "last updated" date. Material changes will be communicated by email.

9. Contact

Questions: franckydelissaint@gmail.com