Who we are
Provenfolio is operated from Estonia and is the data controller for the personal data described below. Our processors are listed further down. If you are in the EU or EEA, the GDPR applies to this processing and you have the rights set out at the end of this page.
What we collect
- Account data: name, email address, and a hashed password (bcrypt — we never store your plaintext password).
- Profile / portfolio data: display name, professional title, bio, location, phone (optional), social links, profile and banner images, and an optional CV/resume file.
- Project & CV content: project case studies, images, uploaded engineering files, certifications, experience and education entries.
- Billing data: your plan, subscription state, invoices and payments. Card numbers are entered directly with our payment processor and never reach our servers; we store the processor's identifiers, the amounts and any VAT number you supply.
- AI Project Builder source files: the files you upload into the importer, held privately and temporarily so a draft case study can be built from them. They are not attached to any project, are never publicly reachable, and are deleted automatically once the import is finished. Alongside them we keep the structured metadata extracted from them — file names and folder paths, CAD header fields such as originating system, units and part names, extracted document text, spreadsheet headers and sample values, and image dimensions and capture dates.
- Support messages: what you write to us, the address to reply to, and the plan you were on at the time.
- Email delivery records: which message we sent you, when, and whether it was delivered.
- Transfer counters: a total number of bytes served for your account per day, used for capacity planning and fair-use review. No URL, file name or visitor is recorded.
- Portfolio analytics: aggregated counts of profile views, project-page views, portfolio-variant views, secure-link opens and portfolio PDF downloads, shown only to the portfolio's owner. Visitor IP and user-agent are protected with a secret-keyed hash that changes every day, so a visitor cannot be recognised from one day to the next or across different portfolios; raw visitor IP addresses are never stored. A second hash over a 30-minute window is stored to count sessions. Referrer URLs are reduced to their origin before storage. Views by the portfolio's own owner are not recorded, obvious automated clients are filtered out, and no view is recorded at all for a visitor who has declined analytics.
Why we collect it, and on what basis
- Contract: operating your account, rendering your public portfolio, generating your PDF, taking payment and sending the receipts, deadline notices and security messages that go with it.
- Legal obligation: keeping invoices and tax records for as long as accounting law requires.
- Consent: optional analytics, and optional product email. Both can be withdrawn at any time, and withdrawing changes nothing else about your account.
- Legitimate interests: keeping the service secure and available — rate limiting, scanning uploads for unsafe content, and the fair-use review described in our Fair Use Policy. Also a pseudonymous record of subscription lifecycle events (purchase completed, plan changed, cancellation requested, payment failed) in our analytics tool, keyed to your internal account id only — no device, browser or location data — because these facts reach us from the payment provider, not from your browser.
We do not sell your personal data, and we do not use it to train any model of our own. What a third-party AI provider may do with what we send it is governed by that provider's own terms, which are named in the AI Project Builder section below.
What becomes public
When your profile is set to public, your portfolio page and any project marked Public or Unlisted are visible to anyone with the link, including content in your published resume PDF (which may include the email and phone you add to your profile). Projects marked Private and profiles set to private are not shown to other users. You control this at any time from Settings.
AI Project Builder
AI Project Builder lets you upload an engineering project folder so that a draft case study can be built from it. This section describes what happens to those files.
Source files are temporary and private
Files uploaded into the importer are held in a private area for the purpose of building your draft. They are not attached to any project, have no public address, are not served to anyone else, and do not count towards your storage allowance. They are deleted automatically once the import is finished — approximately 24 hours after your draft becomes available, or immediately if you cancel the import. The only files that survive are the ones you explicitly select to keep with the finished project, which then become ordinary project files subject to everything stated elsewhere in this policy.
What is sent to an AI provider
Your files are not uploaded to the AI provider. What is sent is the structured metadata extracted from them on our servers: file names and folder paths, CAD header fields (originating CAD system, units, part and assembly names, component counts), text extracted from PDFs and word-processing documents, spreadsheet sheet names, column headers and sample values, and image dimensions and capture dates. Separately, a small number of images are sent to an image model so that what is visible in them can be described. No other file content leaves Provenfolio.
This means that where a report, drawing title or part name contains confidential or client-identifying information, that text is sent to the provider named below. If you are under an obligation that prevents this, do not use the importer for that project — creating a project manually involves no AI provider.
Who processes it
AI processing for this feature is carried out by Google (Gemini API) acting as a processor on our behalf. What that provider may do with the content it receives, including whether it is retained or used to improve their models, is governed by their own terms. We do not make claims on their behalf. We do not use your content to train any model of our own.
Drafts are never published automatically
A generated case study is created as a private draft. It is not visible to anyone else and does not appear on your public profile until you publish it yourself. Generated text may be incomplete or wrong, and you are responsible for what you publish — see our Terms of Service.
Processors
- Vercel — application hosting and file/image storage (Vercel Blob).
- Vercel Web Analytics & Speed Insights — cookieless, aggregated traffic and performance metrics. Only active with your consent (see Cookies & consent below).
- PostHog — product analytics and error diagnostics, hosted on PostHog EU Cloud. In your browser it runs only with your consent; separately, the pseudonymous billing events described under “Why we collect it” are recorded server-side.
- Neon — managed PostgreSQL database.
- Stripe — payment processing, invoicing and tax calculation. Stripe is the controller for the card data you enter with them.
- Resend — delivery of the email we send you.
- Google (Gemini API) — AI processing for AI Project Builder. Receives the structured metadata extracted from your source files, and a small number of images, in order to produce a draft case study.
Data is stored in the EU. Where a processor transfers data outside the EEA, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.
Cookies & consent
We set only strictly-necessary cookies (your sign-in session and, if you use one, your active workspace) plus a small cookie that remembers your privacy choice and a coarse EU / rest-of-world region hint. Optional analytics runs only with your consent: PostHog sets one first-party analytics cookie (removed again if you withdraw), and Vercel’s metrics are cookieless. Full details, and a way to change your choice at any time, are in our Cookie Policy and in Analytics and cookie choices.
How long we keep it
Your portfolio content is kept while your account exists and is deleted with it. The operational records alongside it have fixed ceilings, applied by a nightly job:
- Portfolio view records
- 90 days to 3 years, depending on the portfolio owner's plan
- Sent email records
- 180 days
- Daily transfer counters
- 400 days
- Support messages
- 2 years
- Administrator access log
- 3 years
The reasoning behind each window, and how backups are handled, is in our Data Retention Policy.
Your rights
You can exercise the two you are most likely to want without contacting anyone, from Settings → Account:
- Access and portability: Download my data returns everything in your account as a JSON file, immediately.
- Erasure: Delete my account schedules permanent deletion 14 days later. Your portfolio goes offline at once and any subscription is cancelled at once; signing in during those 14 days calls the deletion off. We keep one record of the request itself — the address that asked and when it completed — as proof it was honoured.
- Rectification: edit your profile, projects and CV at any time.
- Objection and restriction: withdraw analytics consent from the footer, and product email from Settings or any email footer.
Write to us at the address below for anything else. We answer within one month. You may also complain to your local supervisory authority; in Estonia that is the Data Protection Inspectorate (Andmekaitse Inspektsioon).
Contact
Questions or requests: privacy@provenfolio.com