Privacy
Privacy Policy
Last updated: April 16, 2026
Mifolio (“we,” “us,” or “the service”) is a sole proprietorship operated by Dev Gadde that provides an AI-powered portfolio website generator at mifolio.online. This policy explains what data we collect, how we use it, who we share it with, and your rights.
1. What we collect
We collect only the data needed to build and host your portfolio site:
- Account data — when you sign in with email or Google, we store your email address, a hashed password (if applicable), and a Supabase user ID. For Google sign-in we also receive your name and profile photo URL.
- Resume content — when you upload a PDF/DOCX or paste text, we extract the plain text server-side and store it long enough to generate your portfolio. The parsed structured data (roles, education, skills) becomes part of your saved site.
- Site content — the HTML of any portfolio you publish, keyed to your chosen URL slug.
- Payment metadata — when you purchase, we record a Stripe session ID and a paid-at timestamp. We never see or store your card number.
- Operational logs — standard request logs (timestamps, IP address, user agent) via our hosting provider, retained briefly for debugging and abuse prevention.
2. How we use it
- Generate, store, and serve your portfolio site.
- Authenticate you and manage your account.
- Process one-time payments via Stripe.
- Prevent abuse, detect fraud, and debug issues.
- Improve the product — aggregate, anonymized patterns only; we do not sell personal data.
3. Who we share it with
We use a small number of third-party services to run Mifolio. Each receives only the data needed for their specific function:
- Supabase — database + authentication. Stores your account, sites, and session data.
- Anthropic— AI models that generate your portfolio. Your resume text is sent to Anthropic's API for processing; Anthropic's policy prohibits training on customer API inputs.
- Stripe — payment processing. Handles all card data; we never touch it.
- Vercel — hosting + CDN.
- Google — OAuth sign-in only. Google returns your name, email, and profile photo; we do not access any other Google account data.
We do not sell your data. We do not share it with advertisers. We only disclose data to third parties in response to valid legal process (court order, subpoena) or to protect the safety of our users.
4. Your rights
You can at any time:
- Access your data — view your sites on your dashboard.
- Delete your data — email us at devgadde6@gmail.com and we'll permanently delete your account and all associated sites within 7 days.
- Export your data— request a copy of everything we hold; we'll send a JSON export within 14 days.
- Correct your data — you can edit your portfolio content directly from your dashboard; for account-level corrections, email us.
California residents (CCPA) and EU/UK residents (GDPR) have additional rights including the right to know, right to delete, right to opt out of “sales” (we do not sell data), and the right to non-discrimination. To exercise any right, contact us at the email above.
5. Data retention
- Published site content is retained as long as your account exists.
- Pending checkout data is deleted within minutes of a successful or cancelled payment.
- Request logs are retained for up to 30 days.
- Upon account deletion, all personal data is removed within 7 days; backup copies may persist up to 30 additional days.
6. Cookies
We use only essential cookies required for authentication and session management (set by Supabase). We do not use tracking or advertising cookies. We do not embed third-party trackers on published portfolio sites.
7. Security
All traffic is encrypted over HTTPS. Database access is restricted via row-level security; passwords are hashed by Supabase. Payment processing is PCI-compliant via Stripe. We cannot guarantee absolute security — no system can — but we follow current industry best practices.
8. Children
Mifolio is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we'll delete it.
9. Changes to this policy
We'll update this page if our practices change. The “Last updated” date at the top will reflect any revision. For material changes, we'll email registered users.
10. Contact
Questions or requests: devgadde6@gmail.com.