Privacy
Last updated: July 2026
What we store
When you create an account we store your email address and, if you sign in with X, your X handle, display name and avatar. When you build a portfolio we store the content you add: the X post links you choose, titles, descriptions, collections, resource links, and any media you upload directly.
When you join the early-access waitlist we store your email address, the time and version of the consent you gave, and — if you reserve one — the Postfolio username you request. We send a one-time verification link that expires after 24 hours, and keep limited abuse-prevention signals to rate-limit sign-ups. We email you only about Postfolio's launch, and you can ask us to remove you at any time.
If someone uses your Work with me contact sheet, we store their name, email, optional company, project details, message, a cleaned referrer, and limited abuse-prevention signals. Contact attempts are short-lived; archived enquiries are removed after 90 days and unarchived enquiries after 24 months.
An enquiry also carries the random browser-tab identifier described above, so the creator can see how that visit reached them and which projects it opened before writing. This links one visit’s path to the person who chose to send that message, and only for the creator they wrote to. It reveals nothing about any other visit, cannot recognise the sender on a later visit or on another portfolio, and disappears with the enquiry when it is deleted.
On the landing page, we use a random per-tab identifier to measure anonymous visits, chapter depth, clicks on the live portfolio, and waitlist sign-ups. We record only the event, an optional chapter or action placement, and an allowlisted source of profile, direct, or other. For these events we do not store email, username, X handle, full referrer URL, user-agent string, or raw IP address.
When someone visits a portfolio we record anonymous counts so the creator can see how their work is doing: page and project views, reaching the work grid, clicks on their calls to action, links and collections, private share and Client Room views, and completed enquiries or follows. Each is stored as a single row holding the event, the portfolio it belongs to, the project or collection where relevant, a reduced traffic source — one of x, search, social, postfolio, direct, or other — and a screen-size band of mobile, tablet or desktop, worked out from the browser window rather than from any device information.
Those rows also carry a random identifier for the browser tab, so a creator can tell one visit from ten rather than only counting page loads. It is generated in the browser, is not derived from anything about you, is held only for as long as the tab is open, and is never sent anywhere else. It cannot recognise you on a later visit or on any other site. We never store the full referring URL, and these events carry no visitor name, email, IP address, user-agent string, persistent device identifier, or cookie. Visitors are not identified and cannot be followed between portfolios or across other sites.
We record the same kind of anonymous milestone for our own product — an account being created, a portfolio published, and a Pro upgrade being started or completed — so we can tell whether Postfolio is working. These are counts tied to an account, not a profile of you.
What we don't do
We don't sell your data, run ads, or track you across other sites. We don't post to your X account, read your DMs, or access anything beyond the public profile information X shares at sign-in. Media in your X posts stays hosted by X; Postfolio displays it from X's own servers.
Cookies
Postfolio uses cookies only to keep you signed in. No third-party or advertising cookies.
Private work links use a short-lived cookie so a secret link can open the shared work without keeping the token in the address bar. These sessions expire after 24 hours and can be revoked by the portfolio owner.
Where it lives
Account and portfolio data is stored with Supabase (hosted in the EU) and the site is served by Vercel. Both act as processors for the data described above. Vercel also provides aggregate page-traffic analytics for Postfolio's own pages; it is cookieless and records no personal data.
When you use AI copy polish, the text of the selected X post is sent to our AI provider (OpenRouter, which routes to the model provider) to generate suggested copy; it is not used to train models.
Contact-sheet email notifications are sent through Resend when the owner enables notification delivery. The enquiry is stored before notification so delivery failures do not lose messages.
Removing your data
Deleting your account from Account in Manage removes your profile, portfolio, works and uploaded media. For anything else, email hello@postfolio.so.