1. Local-first data model
In the current public beta, dispute cases, drafts, notes, goals, Debt Autopilot balances, strategy settings, locally recorded payment history, and payoff-cycle planning data are stored in browser local storage. Credit-report and evidence files are stored in browser IndexedDB. The beta does not intentionally transmit those report or evidence files to a CredBounce application server.
The Contact form, UPSHIFT+ early-access form, and Debt Autopilot+ Level 2 activation-interest form use a separate protected submission path. Those forms send only the information you intentionally enter so CredBounce can review support requests and beta interest. The Level 2 interest form does not collect bank credentials, creditor credentials, account numbers, funding authorization, or a payment mandate.
Keep sensitive dispute material close to the user while the product remains in self-service beta.
2. Erasing local data
The application includes an erase-local-data control for dispute information. Users should also understand that browser settings, private-browsing behavior, device cleanup tools, or clearing site data can remove locally stored information.
Keep independent originals of credit reports, evidence, correspondence and other records you may need later.
3. Local storage is not a backup system
Device-local storage reduces centralized collection, but it does not make data invulnerable. Anyone with access to an unlocked device or browser profile may be able to access local application data. Device loss, browser corruption, storage quotas, or clearing browser data can cause loss.
4. HTTPS, protected forms, and premium checkout
The public site is delivered over HTTPS. HTTPS protects data in transit between your browser and the website host, but it does not replace normal device security such as a screen lock, current operating-system updates, and safe account practices.
Support, early-access, and Debt Autopilot+ activation-interest forms are submitted through the platform’s server-side visitor form system with session, CSRF, and rate-limit protections. Their submissions are stored in the project’s private lead inbox rather than exposed as public website content.
UPSHIFT+ membership payment is handled on Stripe-hosted checkout. Raw payment-card details are not entered into the CredBounce local workspace. The membership payment flow is separate from any future funding-account authorization used for creditor payments.
5. Information we do not need in this beta
Do not enter Social Security numbers, bureau passwords, bank passwords, authentication codes, full payment-card data, or other credentials into free-text fields. CredBounce does not need those credentials to provide the current self-service workflow.
6. Future accounts, synchronization and payment partners
Debt Autopilot Level 1 remains local planning/tracking and does not move money. Debt Autopilot+ Level 2 is designed around separate premium membership billing and a specialized creditor-payment provider. The current beta keeps live creditor-payment execution locked while provider approval, tokenized funding-account setup, identity verification where required, creditor destination validation, recurring authorization, pause/revoke controls, failure handling, reconciliation, and launch review are completed.
UPSHIFT+ premium membership checkout is active through Stripe. If future versions add user accounts, cloud synchronization, licensed credit monitoring, bank connectivity, identity verification, or live creditor-payment services, the data model and disclosures will be updated before those features are made available. CredBounce should not directly collect raw bank passwords or full payment-card credentials for those integrations.