DevPortfolio AI
← Home

Privacy Policy

Last updated: July 2026

This policy explains what personal data DevPortfolio AI (“we”, “us”) collects, why, how we protect it, and the rights you have under the EU General Data Protection Regulation (GDPR). By using devportfolioai.dev you agree to this policy.

1. Who we are

DevPortfolio AI is a service that helps you create and publish a developer portfolio. We are the data controller for the personal data described here.

You can contact us about privacy at privacy@devportfolioai.dev.

2. What data we collect

We only collect what we need to run the service:

  • Account: your email address and password (passwords are stored only as a secure hash — we never see them), or, if you sign in with GitHub, your GitHub account identifier and public profile.
  • Profile: username, display name, avatar and short bio that you choose to add.
  • Portfolio content: everything you put into the builder (name, bio, experience, education, projects, skills, testimonials, photos and images). Note that a portfolio you choose to publish is public.
  • GitHub connection (optional): if you connect GitHub to import repositories, we use a temporary access token to read the repositories you allow. The token is stored in a secure, short-lived cookie and is never shown to the browser.
  • Payments (if you subscribe): billing is processed by Stripe. We do not receive or store your card details. We store your subscription status and a Stripe customer identifier.
  • Technical data: basic server logs, IP address and cookies needed for login, security and remembering your language.

3. Why we use your data (legal bases)

  • To provide the service and your account — performance of a contract with you.
  • To generate and improve portfolio text with AI, at your request — performance of a contract.
  • To process subscriptions and payments — performance of a contract and legal obligation.
  • To keep the service secure and prevent abuse — our legitimate interest.
  • To comply with legal obligations (e.g. accounting).

4. AI processing

When you ask the AI to generate or improve content, the text you submit (and, for GitHub imports, public README and code samples) is sent to our AI provider, Anthropic, to produce the result. This data is processed to deliver your request and is not used to train models by default under our API terms.

5. Who we share data with

We do not sell your data. We share it only with the service providers (processors) that operate the platform:

  • Supabase — database, authentication and file storage (hosted in the EU).
  • Vercel — website hosting and delivery.
  • Anthropic — AI text generation.
  • Stripe — payment processing (only if you subscribe).
  • GitHub — only when you choose to connect your account.

6. International transfers

Some providers (e.g. Vercel, Anthropic, Stripe) may process data outside the EU/EEA. Where that happens, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7. Cookies

We use only the cookies needed to run the service — we do not use advertising or tracking cookies:

  • Login/session cookies (Supabase) to keep you signed in.
  • A language cookie to remember EN/PT.
  • A temporary GitHub cookie while you have a repository connection active.

8. How long we keep your data

We keep your account and content for as long as your account exists. When you delete your account, your profile and portfolios are permanently deleted. Some minimal records may be retained where required by law (e.g. billing).

9. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data (you can edit most of it in your profile).
  • Erase your data — you can delete your account at any time in your profile, which removes your data.
  • Restrict or object to certain processing.
  • Data portability — you can download your portfolio as an HTML file at any time.
  • Withdraw consent, where processing is based on consent.

To exercise any right, use your profile page or email us at privacy@devportfolioai.dev. You also have the right to lodge a complaint with your local data protection authority — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD).

10. Security

Data is encrypted in transit (HTTPS) and at rest. Passwords are stored as secure hashes and card data stays with Stripe. Access to the database is restricted to our server. No system is perfectly secure, but we take reasonable measures to protect your data.

11. Published portfolios are public

A portfolio you publish is intentionally public: anyone with the link can view it, and it may be indexed by search engines. Do not include information you don’t want to be public. You can unpublish or delete a portfolio at any time.

12. Children

The service is not intended for children under 16. We do not knowingly collect data from children.

13. Changes to this policy

We may update this policy. We will change the “last updated” date and, for significant changes, notify you in the app.

14. Contact

For any privacy question or request, contact us at privacy@devportfolioai.dev.