Read the PortfolioDIY privacy policy to understand what account, draft, payment, and export data we collect, store, and delete when you use the app. Last updated: 1 June 2026
PortfolioDIY is built local-first and collects as little as the product allows. This policy describes what we store, where, and why — in plain language, because a privacy policy you can't read protects no one.
The short version: guest drafts live in your browser for the current session only — they never reach our servers, and they are discarded when you close your browser. We only store data server-side when you create an account to save sites, or make a purchase. We don't sell data, we don't run ad trackers, and your exported site contains no analytics or phoning-home of any kind.
When you build as a guest, your entire draft — content, settings, uploaded images — is kept in your browser's session storage on your device. It never reaches our servers, and it is discarded automatically when the browser session ends. We never have a copy at any point.
This is why a guest draft doesn't follow you to another device, another browser, or your next visit: there is nothing on our side to fetch. Create a free account if you want your sites saved.
We store personal data server-side only in these cases:
Payments are processed by Razorpay or Stripe, depending on which gateway your checkout runs through — you will see which one before you pay. Your card details go directly to that provider and never touch our servers: we receive only a confirmation that payment succeeded, the amount, and a payment reference. Their handling of your payment data is governed by their own privacy policy.
We measure product usage in aggregate — page views and feature usage counts — to understand what to improve. This measurement does not use advertising identifiers and is never joined with your site content.
Cloudflare, our CDN and security provider in front of portfoliodiy.com, may separately collect basic aggregate traffic metrics (page views, approximate location, browser) through its cookieless Web Analytics feature. It sets no cookies and uses no tracking identifiers — it cannot follow you across other sites.
Your exported portfolio contains zero analytics of ours. If you want analytics on your own site, you add them yourself; we will never inject anything into your export.
The portfolio content you write — your name, story, projects, images — is yours. We do not use it to train models, we do not mine it for marketing, and we do not share it with anyone. Synced sites are visible only to your account.
The exported code is entirely yours, watermark or not. See the Terms of Service for the exact license (spoiler: you own it).
Synced sites persist until you delete them from My Sites, which removes the server copy immediately. Deleting your account removes your email, your sites, and your session data. Purchase records are retained as long as accounting law requires.
You can delete your account yourself from Account settings (confirmed with your password, removed immediately), or email [email protected] from your account address and we'll do it for you. Guest drafts on your own device clear themselves when the browser session ends.
Depending on where you live (including under GDPR and similar laws), you have the right to access, correct, export, and erase your personal data, and to object to or restrict its processing. Since we store so little, exercising these rights is usually a single email: [email protected].
If we change this policy in a way that matters, we'll note it in the changelog and update the date at the top of this page. We will never quietly weaken the local-first promise — that would be changing the product's premise, not a policy detail.
Questions about this document? Email [email protected].