Privacy Policy

Last updated: 6 October 2026

Stackportfolio (stackportfol.io) is a portfolio service for people who work in technology: you show what you have built, and the technologies on your profile are backed by the projects you used them in. It is operated by Stephen Dawson, trading as Stackportfolio, 25 Granary Wharf, Glenbrook, Passage West, Cork T12 VW35, Ireland ("we", "us"). We are the controller of the personal data described here.

This policy explains what we collect, why, who else handles it, how long we keep it and what you can ask us to do with it. We collect only what the service needs, we do not sell personal data, we do not show advertising and we do not use third-party analytics or tracking.

What we collect and why

For each purpose below we name the lawful basis under Article 6(1) of the General Data Protection Regulation (GDPR) that we rely on.

  • Your account. You sign in with GitHub; we do not store passwords. GitHub shares your name, email address, profile picture and GitHub user ID, and gives us an access token that keeps your sign-in linked. We use these to create and secure your account. Basis: performance of our contract with you (Art. 6(1)(b)).
  • Your profile. What you choose to add: username, bio, job title, experience level, company, location, website and social handles, phone number, availability and job preferences (including a preferred salary range if you enter one), or, for recruiters, your company details. Basis: contract (Art. 6(1)(b)).
  • Your projects and contributions. Project descriptions, links, technologies, skills, contribution stories, the people you list as contributors, and the images and video links you add. Technology proficiency on your profile is calculated from this, never entered by hand. Basis: contract (Art. 6(1)(b)).
  • Connections, invitations, access requests and notifications. Who you connect with, the projects you share or are invited to, and the notices we send you about them. Basis: contract (Art. 6(1)(b)).
  • Search. Profiles and projects that your visibility settings allow to be found are copied into a search index that we run on our own servers. Basis: contract (Art. 6(1)(b)).
  • API keys and connected apps. If you create an API key or authorise an app (such as an AI assistant using our MCP server) to act for you, we store the key or authorisation, its permissions and its expiry. We store API keys only in hashed form. Basis: contract (Art. 6(1)(b)).
  • Security and session data. When you sign in we record your IP address and browser user agent against the session, and we apply usage limits per account and per address. We keep a short record of the connection requests each account sends, to enforce a re-request cooldown and spot automated abuse, and a record of which notification emails we sent you, so that we do not send duplicates. Administrative actions are recorded in an activity log. Basis: our legitimate interest in keeping the service and your account secure (Art. 6(1)(f)).
  • Server logs. Our application writes technical logs (for example the error, the page and, where relevant, your user ID) so that we can find and fix faults. Basis: legitimate interest in running a reliable service (Art. 6(1)(f)).
  • Messages to us. If you use our contact form we receive your name, email address and message by email, so that we can reply. The form uses Cloudflare Turnstile to filter out automated spam. Basis: legitimate interest in answering you and protecting the form from abuse (Art. 6(1)(f)).
  • Email. We send emails needed to run your account (such as address verification, and security notices such as a new API key, a connected app or a suspension). We also send notification emails (for example about connection requests, project invitations and shared projects); these are on by default and you can switch them off, all at once or one type at a time, in your settings. Basis: contract (Art. 6(1)(b)); for optional notifications, your choice in settings, which you can change at any time.
  • Legal obligations. Where the law requires us to keep or disclose information, we do so. Basis: legal obligation (Art. 6(1)(c)).

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. The proficiency calculation summarises your own project data and you control what goes into it.

Who can see your information

Your profile visibility can be public, limited to your connections, or private, and you choose separately whether your email address, phone number and location are shown; they are hidden unless you turn them on. New projects start as private. You can change all of this at any time in your settings.

Anything you make public can be seen by anyone, including search engines, and may be copied by others before you change it. Please do not put information on a public profile that you would not want to be public.

Cookies

We use only cookies that are needed for the service or that remember a choice you made. We do not use advertising or analytics cookies, so we do not ask for cookie consent.

  • Session cookies set by our sign-in system, which keep you signed in. A session lasts up to 7 days and is renewed while you use the site.
  • "theme" and "language", which remember your colour theme and language for up to a year.
  • "search_layout", "profile_stack" and "connections_view", which remember how you like those pages laid out.
  • "share_token", which lets a private share link keep working while you browse the shared project (up to 30 days, or until the link expires if sooner), and "flash", which carries a one-off message to the next page and lasts 60 seconds.

Who else handles your data

We use the following service providers. They process personal data on our behalf and under our instructions, or, where marked, as independent providers whose content your browser loads directly.

  • Hetzner Online GmbH (Germany): hosts our servers, database and search index. We deploy and run the service on them with Coolify, open-source software we operate ourselves.
  • Cloudflare, Inc. (USA, with a global network): sits in front of the site, provides HTTPS and protection against attacks, and provides Turnstile on the contact form. It handles every request to the site, including your IP address.
  • Backblaze, Inc. (USA; storage in its EU region): stores uploaded images and our nightly database backups.
  • Brevo (Sendinblue SAS, France): sends our emails.
  • GitHub, Inc. (USA): provides sign-in. GitHub also serves the profile pictures it hosts directly to your browser.
  • Google LLC (USA): serves the web fonts on our home and sign-in pages directly to your browser, which means Google receives your IP address when those pages load.
  • YouTube (Google), Vimeo (USA) and Loom (Atlassian, USA): only if a project includes a video. When a video link is saved, our server fetches its thumbnail from the provider and stores a copy; the provider’s player itself loads when you view the video. YouTube videos use its privacy-enhanced (no-cookie) mode.

We do not sell or rent your personal data. We disclose it to others only as described here, at your direction (for example, when you share a project), or when the law requires it, such as a valid court order.

International transfers

Our servers and backups are in the European Union. Some of the providers above are based in the United States or may process data outside the European Economic Area. Where that happens we rely on a European Commission adequacy decision (including the EU–US Data Privacy Framework, where the provider is certified under it) or on the Commission’s Standard Contractual Clauses, as Chapter V of the GDPR requires. You can ask us for details of the safeguard that applies to a given provider.

How long we keep it

  • Account, profile and project data: for as long as your account exists. When you ask us to delete your account, we delete it within one month.
  • Sessions: until they expire (up to 7 days without use) or you sign out.
  • API keys: until they expire (between 30 and 365 days, as you choose) or you revoke them. Authorisations for connected apps: until you revoke them; their access tokens last one hour and their refresh tokens up to 365 days (renewed each time the app refreshes; disconnecting the app or signing out ends it).
  • Server logs: rotated automatically and kept only for a short period; they are not archived.
  • Messages through the contact form: in our mailbox for as long as needed to deal with your request.
  • Backups: deleted data may remain in database backups for up to 30 days until those backups are overwritten. We do not restore it from backups except to recover from a failure.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy of it;
  • have inaccurate data corrected (most of it you can correct yourself on your profile and in settings);
  • have your data erased ("right to be forgotten");
  • restrict how we use your data while a concern is resolved;
  • receive the data you gave us in a structured, machine-readable format and have it sent to another provider (portability);
  • object to processing we carry out on the basis of legitimate interests;
  • withdraw any consent you have given, at any time, without affecting what we did before.

There is not yet a self-service button to delete or export your whole account, so please ask us through the contact form or at [email protected]. Your own profile and project data can also be read through our API. We will answer within one month, may need to confirm it is really you, and will not charge you unless a request is clearly unfounded or excessive.

You also have the right to complain to a supervisory authority. Our lead authority is the Data Protection Commission in Ireland (dataprotection.ie). You may instead complain to the authority where you live or work (list of EU authorities). We would appreciate the chance to put things right first.

How we protect your data

  • All traffic to the site is encrypted with HTTPS.
  • We never handle your password: sign-in goes through GitHub, and session cookies are not readable by scripts on the page.
  • API keys are stored hashed, expire, and carry only the permissions you grant. Connected apps use OAuth 2.1 with PKCE, short-lived access tokens and a consent screen you can revoke.
  • Forms are protected against cross-site request forgery, and usage limits and bot checks slow down abuse.
  • Administrative access is limited to a small number of named accounts, and administrative actions are logged.
  • Data is hosted in the European Union and backed up daily.

No system is perfectly secure. If a breach puts your rights at risk we will notify the Data Protection Commission within 72 hours and tell you without undue delay, as the GDPR requires.

To report a security vulnerability, email [email protected].

Children

Stackportfolio is a professional service for adults. You must be at least 16 years old to use it, and we do not knowingly collect data from anyone younger. If you believe a child has created an account, please contact us and we will delete it.

Changes to this policy

We will update this policy when what we do changes. The date at the top shows the latest version. If a change is significant, we will tell signed-in users on the site or by email before it takes effect.

Contact

Questions about this policy or your data: Stephen Dawson, trading as Stackportfolio, 25 Granary Wharf, Glenbrook, Passage West, Cork T12 VW35, Ireland; email [email protected], or use our contact form.