This Privacy Policy describes how CredAware ("we," "us," or "our") collects, uses, and protects information when you use the CredAware service ("Service"). We take your privacy seriously.
Account information: When you register, we collect your email address, name (optional), and a hashed password. We never store your password in plain text.
Microsoft Entra credential metadata: When you connect a Microsoft Entra tenant, we fetch and store only credential metadata via Microsoft Graph read-only APIs: application names, service principal names, credential display names, types (client secret or certificate), and expiration dates. We never retrieve, transmit, or store secret values, private keys, certificate private material, tokens, or any data that would grant access to a protected resource.
Billing information: Payments are processed by Stripe. We store your Stripe customer ID and subscription status but never store your full payment card details.
Usage and log data: We collect server logs including IP addresses, timestamps, and API endpoints accessed. Logs are retained for 90 days for security and debugging purposes.
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
Report history is retained based on your subscription plan (30 days for Starter, 90 days for Pro, 365 days for Business). Reports older than your plan's retention window are automatically deleted. Your account data is retained while your account is active and deleted within 30 days of account closure.
CredAware integrates with Microsoft Entra ID through delegated read-only permissions. The specific Graph API permissions we request are limited to reading application and service principal metadata. We act as a data processor for the Microsoft tenant data you provide access to. You may revoke our access at any time by removing the CredAware enterprise application from your Microsoft Entra tenant.
We use the following third-party processors:
We use industry-standard measures to protect your data, including encrypted storage, TLS in transit, bcrypt password hashing, and time-limited tokens for sensitive operations. No system is perfectly secure; please use a strong, unique password for your account.
You may access, correct, or delete your account data at any time through the account settings in the app. To request a copy of your data or to exercise any other privacy rights, contact [email protected].
The portal app uses your browser's local storage (not cookies) to store your session token. We do not use advertising or tracking cookies in the app.
The marketing website (credaware.com) uses Google Analytics 4, which sets analytics cookies (_ga, _ga_*) only if you consent via the cookie banner on your first visit. You can withdraw consent at any time by clearing your browser's site data for this domain, or opt out globally via Google's opt-out tool.
The Service is intended for business users and is not directed at children under 13. We do not knowingly collect data from children.
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice before they take effect. Continued use of the Service after the effective date constitutes acceptance.
Questions about this Privacy Policy? Email [email protected].