Privacy Policy
Effective August 12, 2026
Overview
CreditPath is a free credit education site run by one person on a self-hosted server. There is no company behind it, no ad network, and no analytics trackers. This policy explains what information the site handles, why it is handled, and the choices you have.
CreditPath is an education and self-help tool. It is not a credit repair organization. You review, sign, and mail your own letters. The site never contacts credit bureaus, lenders, or debt collectors for you, and it does not promise any result.
Accounts Are Optional
You can read every lesson and use every tool without an account. If you want to save your progress or keep dispute letters on the server, you can create a free account. To do that, we ask for your name, your email address, and a password.
Your password is never stored as you typed it. It is hashed with bcrypt, a one-way process, before it reaches the database. We cannot see your original password.
With an account, the site also stores what you do on it: which lessons you complete, quiz results, game scores, and badges you earn. That data exists so your dashboard works.
Dispute Letters and Sensitive Details
The dispute letter tool builds letters that can include personal details such as your name, mailing address, the last four digits of your Social Security number, and account numbers.
If you are signed in, you can choose to save a letter to the server. Saved letters are stored in the site's database (MariaDB) along with their status and dates. We treat this data as sensitive. It is used only to show you your own letters and to run the letter tracker, including deadline reminder emails that are sent automatically for bureau letters you save and mark as mailed (when the server has email configured). Deleting a letter stops its reminders. It is never sold, never shared with advertisers, and never given to anyone else unless the law requires it.
Using the Tools Without an Account
You can generate a dispute letter without signing in. In that case, everything you type stays in your browser. Nothing is sent to or stored on the server. When you close the page, that information is gone unless you copied or printed the letter yourself.
Cookies
CreditPath uses exactly one cookie, called cp_session. It keeps you signed in. It is an httpOnly cookie, which means scripts on the page cannot read it. It is set when you sign in and removed when you sign out. If you do not sign out, it expires on its own after 7 days.
That is the whole list. There are no tracking cookies, no advertising cookies, and no third-party cookies of any kind.
How We Use Your Information
Your information is used only to run CreditPath for you: signing you in, saving your progress, storing letters you choose to save, and sending service emails. Dispute-deadline reminders are sent automatically for bureau letters you save and mark as mailed, when the server has email configured. To stop reminders for a letter, delete the letter or record its response; deleting your account stops everything.
Your email address is used for the service itself and nothing else. No marketing lists, no newsletters you did not ask for, no sharing with other companies.
What We Never Do
- We do not sell your data.
- We do not run ads or ad networks.
- We do not use analytics trackers.
- We do not share your information with anyone else, except when the law requires it (for example, a valid legal order).
How Your Data Is Stored and Protected
Your data lives in a MariaDB database on a server we run. Passwords are bcrypt-hashed. Sessions use an httpOnly cookie, so your session token is not exposed to page scripts. Saved letters are scoped to your account: the API only returns data that belongs to the signed-in user.
No system is perfectly secure. Save to the server only what you are comfortable storing. You can always use the letter tool without saving anything.
Deleting Your Data
You are in control of what stays on the server.
- You can delete any saved letter at any time.
- You can delete your entire account. Deleting your account removes all of your data from the database: your profile, lesson progress, quiz results, game scores, badges, and every saved letter.
Saved letters also have an automatic retention limit, because they can hold sensitive details. A letter nobody has touched in about 23 months triggers a warning email (when the server has email configured), and a letter still untouched at 24 months is deleted for good. Opening a letter and saving a note resets its clock. Letters are never deleted without that emailed warning first.
Children
CreditPath is not aimed at children. We do not knowingly collect information from anyone under 13. If you believe a child has created an account, contact us and we will delete it.
Changes to This Policy
If this policy changes, we will update this page and change the effective date at the top. If a change meaningfully affects how saved data is handled, we will also post a notice on the site or email account holders before the change takes effect.
Contact
Questions about this policy or your data? Email [contact email].