How we handle your data

Privacy Policy

Last updated: September 2026

This portfolio platform stores only the data needed to provide its features. This page explains anonymous audience measurement on public pages and what we collect if you connect Spotify.

Spotify integration

If you connect Spotify in the admin panel, we store credentials for your own Spotify developer app so the Now Playing widget can show playback on your public portfolio.

What we store

  • Your Spotify app Client ID
  • Your Spotify app Client Secret, encrypted at rest
  • Your Spotify refresh token, encrypted at rest
  • The OAuth scopes granted during authorization

We use this data only to request Spotify playback information on your behalf for visitors to your portfolio. We do not sell or share it with third parties.

You can disconnect Spotify at any time from Admin → Spotify. Disconnecting deletes your Spotify tokens and app credentials from our database immediately.

If you disconnect or ask us to stop processing your Spotify data, we delete it without undue delay and within five days at most, in line with Spotify's developer terms.

Audience measurement

Public pages send a small first-party beacon so the owner can see approximate traffic. This is not advertising or cross-site tracking, and it does not set cookies.

What we store

  • Daily totals of pageviews and session visits, grouped by page path, country, and referrer hostname

What we do not store

  • IP addresses
  • Cookies, fingerprints, or unique visitor identifiers
  • City-level location (country only, from the hosting platform)

We use these aggregates only to show stats on the public /stats page and in the portfolio admin. Data is not sold or shared with analytics vendors.

If your browser sends Do Not Track or Global Privacy Control, we skip the measurement entirely.

Aggregates older than 13 months are deleted.