Privacy · Updated 16 September 2026
Privacy Policy
thatfolio.com helps you create, edit, and publish a portfolio. This policy describes how we handle information when you use thatfolio.com, app.thatfolio.com, and portfolios hosted through our service.
The service is operated under the name thatfolio (“we”, “us”, or “our”). For privacy questions or requests, email joshua.apollo13@gmail.com. Our support page also provides our current support channel. Share account details only in a private conversation.
Information we collect
Account information. Your email address, account identifier, sign-in records, and basic profile information made available by your sign-in provider, such as your name and profile picture. Google sign-in requests basic identity and email information; it does not request access to your Gmail messages, Drive files, or contacts.
Content you provide. Resumes, uploaded PDFs, images, logos, pasted text, profile details, portfolio content, saved designs, and edit history. This can include education, work experience, projects, and contact details you choose to include.
Sources you select. If you provide a GitHub username, we retrieve public profile and repository information, including selected README content. LinkedIn information comes from text you paste into the service.
Service activity. Account and trial status, generation requests, model usage and estimated costs, IP addresses used to enforce generation limits, error and security records, and administrative activity. We also count published portfolio views.
Checkout information. Your account email, checkout identifiers, portfolio identifiers, payment status, and applicable promotion information. Checkout currently uses Stripe sandbox mode. Do not enter real payment details into a test checkout.
Collaboration and support. Where shared editing is enabled, invitations, member roles, comments, edit activity, and presence information; and information you provide when contacting support.
Only provide information you have permission to use. Avoid including identity documents, financial account details, or other sensitive information that is unnecessary for your portfolio.
How we use information
We use information to authenticate you, save and edit your work, generate content when requested, host content you publish, support collaboration where enabled, manage trial and usage allowances, process checkout status, provide support, investigate failures, prevent abuse, and maintain service security.
A verified student email may be used to display a student badge. AI-generated content can be inaccurate; review it before publishing.
AI-assisted generation
When you request AI generation, we send relevant source information to OpenAI. Resume-based generation can include the original PDF and saved profile information. Section regeneration sends relevant profile information for the requested section. An invalid response can result in one repair request.
We disable response storage in our generation requests. This does not guarantee zero retention by OpenAI: processing, security logging, and retention also depend on its applicable terms and our account configuration. Do not submit information you do not want processed for this purpose.
What becomes public
Draft portfolios and source uploads are access-controlled. Publishing makes your published portfolio content and included images available to visitors and search engines. A resume attachment you explicitly include as a download on a published portfolio is public too. Private source resumes are not automatically published as downloads.
Where collaboration is enabled, invited users can access the shared material allowed by their role. Visitors can copy or download public material, and search engines or other services may retain copies after you change or remove it.
Service providers and other recipients
Supabase provides authentication, databases, file storage, and shared-editing infrastructure. Vercel hosts and delivers the site and processes application requests and operational logs.
OpenAI processes source content and instructions for the AI requests you initiate. Google handles Google sign-in when you choose it. Stripe handles hosted checkout and associated records, currently in sandbox mode. GitHub receives requests for public profiles and repositories when you choose it as a source.
Our Telegram support channel and external links are subject to those services’ own privacy terms. Do not post private documents or sign-in links in public support channels.
Authorized administrators may access information needed for support, security, account management, and service operations. Information may also be disclosed where required by applicable law or necessary to investigate abuse and protect the service or its users.
Cookies and browser storage
Cookies maintain sign-in sessions and carry onboarding or invitation context through sign-in. Browser storage can remember theme choices and, where shared editing is enabled, preserve unsynced edits. Clearing browser storage may sign you out or remove locally held unsynced work.
Our portfolio view counter records aggregate counts. Hosting and infrastructure providers may separately process request and security information, including IP addresses. External sites and sign-in providers use their own cookies.
Retention and removal
Trial expiry does not automatically delete your account, saved sources, or portfolio. Registered source PDFs remain stored until removed through the available controls or a deletion process.
You can remove eligible unused source PDFs from your saved-PDF library. A PDF referenced by a portfolio or pending generation must be released from those references first. Removing a source PDF does not remove extracted text, saved profile data, generated content, or published snapshots derived from it. Public attachments and saved history can also prevent file deletion while references remain.
We retain saved work to provide your workspace and published portfolios. Usage, security, audit, and checkout records support abuse prevention, account administration, and transaction reconciliation. These records are not automatically removed when a trial expires or an individual file is deleted. Provider logs and backups follow the applicable provider settings and retention practices.
For access, correction, or deletion requests beyond the controls in your workspace, email joshua.apollo13@gmail.com. We may need to verify your identity before acting. We will explain any information that needs to be retained for security, transaction records, or applicable legal obligations when handling your request. Disconnecting Google sign-in does not itself delete data already saved in thatfolio.com.
Security and international processing
We use access controls and authenticated sessions to protect private account data and files. No online service can guarantee absolute security. Keep sign-in links private and review sharing and publication choices carefully.
Our providers may process information outside your country. Their processing locations and applicable protections depend on the services and account configurations in use.
Your choices and rights
You choose which sources to provide, can edit your portfolio, and decide which content to publish or share. You can disconnect thatfolio.com in your Google Account’s third-party connections settings.
Depending on applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information, or to object to or restrict certain processing. Email joshua.apollo13@gmail.com to make a request or raise a concern.
Changes to this policy
We will update this page and its effective date when this policy changes.