DebtStrike
Back to Home
Legal Document

Privacy Policy

Your privacy is critically important to us. This policy explains what data we collect, how we use it, how we protect it, and what rights you have.

Last Updated: March 20, 2026
Effective Date: March 20, 2026
DebtStrike ("we," "us," or "our") operates the DebtStrike platform (debt-strike.vercel.app). This Privacy Policy governs the collection, use, storage, sharing, and protection of personal information provided by users ("you" or "your") of our website and services. By using DebtStrike, you consent to the practices described in this policy.

1. Information We Collect

Account Information. When you create an account, we collect your full name, email address, and a securely hashed password. If you sign up via a third-party provider (e.g., Google), we receive your name, email, and profile photo from that provider.

Uploaded Content. When you submit audio or video recordings of debt collection calls for review, those files are stored in our encrypted cloud infrastructure. We also collect the metadata you provide, such as file titles and descriptions.

Usage Data. We automatically collect standard log data when you interact with our platform, including your IP address, browser type, operating system, referring URLs, pages visited, and timestamps. This data helps us maintain security and improve our services.

Communications. If you communicate with our team through the in-app messaging system or via email, we retain the content of those messages to provide you with support and maintain service quality.

2. How We Use Your Information

Service Delivery. We use your uploaded recordings and account data to provide our core service: expert analysis of debt collection calls for potential FDCPA (Fair Debt Collection Practices Act) violations.

Account Management. Your email and credentials are used to authenticate your identity, secure your account, and communicate important service updates.

Platform Improvement. Aggregated, anonymized usage data helps us understand how users interact with our platform so we can improve functionality, performance, and user experience.

Legal Compliance. We may use your information as necessary to comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

We will never sell, rent, or trade your personal information to third parties for marketing purposes.

3. Data Storage & Security

All data is stored on industry-leading cloud infrastructure provided by Supabase (backed by Amazon Web Services). Your uploaded recordings are stored in private, access-controlled storage buckets that are not publicly accessible.

We employ the following security measures:

Encryption in Transit — All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS).

Encryption at Rest — Database records and stored files are encrypted using AES-256 encryption at the storage layer.

Row-Level Security (RLS) — Our database enforces strict access policies ensuring users can only access their own data. Administrative access is restricted to verified personnel.

Secure Authentication — Passwords are hashed using bcrypt. Session tokens are managed via secure, HTTP-only cookies.

Access Controls — Administrative functions require verified admin credentials. Service role keys are never exposed to the client.

4. Data Sharing & Third Parties

We do not share your personal data or uploaded recordings with any third party except in the following limited circumstances:

Service Providers — We use trusted infrastructure providers (Supabase, Vercel) to host and deliver our platform. These providers are bound by their own privacy policies and data processing agreements.

Expert Reviewers — Authorized DebtStrike reviewers access your recordings solely to identify FDCPA violations and provide expert analysis. Reviewers are bound by strict confidentiality obligations.

Legal Requirements — We may disclose information if required by law, subpoena, court order, or governmental regulation, or if we believe disclosure is necessary to protect the rights, property, or safety of DebtStrike, our users, or the public.

We will never share your recordings with debt collectors, creditors, or any party that could use the information against your interests.

5. Your Rights & Choices

You have the following rights regarding your personal data:

Access — You may request a copy of the personal data we hold about you at any time.

Correction — You may update your account information through your dashboard or by contacting us.

Deletion — You may request the deletion of your account and all associated data, including uploaded recordings. We will process deletion requests within 30 days, except where we are legally required to retain certain information.

Data Portability — You may request your data in a structured, commonly used, machine-readable format.

Withdraw Consent — Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at the email address provided below.

6. Data Retention

We retain your account data and uploaded recordings for as long as your account is active or as needed to provide you services. If you request account deletion, we will remove your personal data and recordings within 30 days, unless retention is required by law.

Anonymized, aggregated analytics data (which cannot identify you) may be retained indefinitely for the purpose of improving our platform.

7. Cookies & Tracking

We use essential cookies only — specifically, session authentication cookies required to keep you logged in securely. We do not use advertising cookies, tracking pixels, or third-party analytics scripts that follow you across the web.

Your browser settings allow you to manage or delete cookies at any time. Disabling essential cookies may prevent you from logging in to your account.

8. Children's Privacy

DebtStrike is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a user is under 18, we will promptly delete their account and associated data.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify registered users via email or an in-app notification and update the "Last Updated" date below.

We encourage you to review this policy periodically. Your continued use of DebtStrike after changes are posted constitutes your acceptance of the updated policy.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@debtstrike.com

Response Time: We aim to respond to all privacy-related inquiries within 5 business days.

© 2026 DebtStrike. All rights reserved.

← Return to Homepage