Open the assistant

Privacy Policy

Last updated: 5 October 2026.

Credit Beat (the "Service", at app.creditbeat.ai and on Telegram) helps you understand credit card rewards, points and miles. It is operated by Alphonic Network Solutions Pvt Ltd ("we", "us"). Contact: support@creditbeat.ai.

What we collect

Information you give us: the questions you ask, the cards you add to your portfolio, loyalty programme IDs, tiers and notes you save in your Locker, and your phone number or Telegram ID if you sign in with them. We do not ask for card numbers, CVV, OTPs, SMS access or airline or bank passwords.

Gmail access (optional)

If you choose to connect a Gmail account, Credit Beat asks Google for read-only access (the gmail.readonly scope). Google grants this as access to your mailbox broadly, but we only look for supported card, rewards and loyalty emails, such as points balance and statement emails, from the past 90 days, and then new changes. We cannot send, delete or change your email. We do not process attachments. Raw message bodies are read in memory to extract facts and are not stored as an inbox archive.

We store the extracted facts (for example a programme name, a points balance and a date), your Google account identity and your encrypted OAuth credentials. You review each proposed import before it is saved. Imported values are snapshots from email, not live account balances.

How we use your data

We use your data to answer your questions, show your cards and points, run the weekly email scan you have turned on, and keep the Service secure. If the AI email reader is on, up to 30 candidate email texts per scan may be sent to Google's paid Gemini API to extract structured facts. These are not used for the general chatbot and not used to train general AI models. Google may keep prompts and responses for a limited abuse and safety period and process them internationally.

Google API Services User Data Policy

Credit Beat's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to provide the reward-tracking features you see in the Service. We do not sell it, use it for advertising, creditworthiness or lending decisions, or share it with other users. No humans read your email unless you ask us for support and give consent, it is needed for security or abuse investigation, or the law requires it.

Who we share data with

We do not sell your data. Our providers process it for us: Render (hosting and storage), Google (sign-in, Gmail access and the Gemini API), and Telegram if you use the Telegram bot. We may disclose data if the law requires it.

Storage and security

Your Google identity, encrypted OAuth credentials and imported facts are kept in a persistent database on our Render server. The service can technically decrypt them to sync your account, so they are encrypted at rest but not end-to-end encrypted. We do not claim an independent security certification. Render takes daily encrypted snapshots that are kept for at least seven days.

Retention and deletion

Data stays while your connection is active. If you disconnect a Gmail account in the Connections page, sync stops and that connection's imported facts are removed from active storage immediately, and we revoke our Google access. Deleted data may remain in provider backups until they expire (about seven days). You can also remove Credit Beat's access any time at myaccount.google.com/permissions. To delete your account or any data, write to support@creditbeat.ai.

Your choices

You can disconnect Gmail, turn the AI email reader off, edit or delete Locker and portfolio entries, and ask us for a copy or deletion of your data.

Changes

We will update this page and its date when this policy changes.