Last updated: May 17, 2026 · GDPR Aware CCPA Aware HIPAA Controls
We collect information you provide directly:
Your documents are private by default. We do not read, analyze, sell, or share your documents. Documents marked as "public" can be accessed by anyone with the share link. Blockchain records contain cryptographic hashes of documents only — not document content. Your documents are encrypted at rest using AES-256 encryption.
Free accounts remain active for 365 days from registration. Paid subscriptions remain active for the duration of your current billing period. We send email notifications 30, 7, and 2 days before your account or subscription expires.
After expiry or subscription cancellation, your account enters a 30-day grace period with read-only access. During grace, you may renew your subscription, continue on a free plan (where eligible), or request immediate deletion. Reminder emails are sent at 7, 23, and 28 days into the grace period. If no action is taken by the end of grace, your account and all associated data are permanently deleted.
Important: If you require signed documents, audit trails, or invoices for legal, tax, or compliance purposes, please download them locally before account deletion or before your grace period expires. We cannot restore data once an account has been deleted.
We do not sell your personal data. We share data only with:
All third-party processors are contractually bound to protect your data.
These controls are consistent with HIPAA Technical Safeguard requirements under 45 CFR § 164.312.
If you are located in the European Union, you have the following rights under GDPR:
To exercise any of these rights, contact [email protected]. We will respond within 30 days. For EU data processing details, see our Data Processing Agreement.
California residents have the right to know what personal information is collected, request deletion of personal information, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact [email protected].
Health Information Notice
Credible Documents has implemented security controls consistent with HIPAA Technical Safeguard requirements. However, we are not currently HIPAA certified and do not offer a Business Associate Agreement (BAA). HIPAA certification is on our product roadmap. If you process Protected Health Information (PHI), you are responsible for ensuring compliance with applicable regulations.
Your data is currently stored and processed in the United States. If you are located outside the US, your data will be transferred to and processed in the US. By using the Service, you consent to this transfer. We are working toward EU data residency options as a future product milestone.
We use session cookies for authentication only. We do not use tracking, advertising, or analytics cookies. We do not use Google Analytics or similar third-party tracking services.
The Service is not directed to children under 18. We do not knowingly collect data from minors. If you believe we have collected data from a minor, contact us immediately.
We may update this policy periodically. We will notify you of significant changes via email. Continued use of the Service after changes constitutes acceptance.
Blakiston Peak LLC is the data controller for personal data processed through Credible Documents.
13459 Romford Ave
Port Charlotte, FL 33981
United States
[email protected]