Legal
Privacy Policy
What Document Portfolio collects, why, where it lives, and the control you have over it.
Last updated: 9 September 2026
1. Introduction
Document Portfolio is a web platform that lets product, UX, UI, visual and graphic designers write case studies, organise their work, choose a visual theme and publish a shareable portfolio page.
This policy explains what information the platform collects, how it is used, where it is stored, when it is shared, and the choices you have.
2. Information we collect
Account information
- Name
- Email address
- Login credentials — a password you choose (stored only as a salted hash by our authentication provider) or a Google sign-in identity
- Chosen username, which forms your public portfolio address
- Optional profile details you enter: job title, short bio, location, links to your social or professional profiles, a profile image and a résumé file
Content you create and upload
- Case studies, project titles, descriptions and written content blocks
- Images, GIFs and videos you upload
- Documents such as PDF or Word files, including a résumé where you add one
- Skills, experience entries, showcase items and portfolio settings
- Theme and publishing preferences
Technical and usage information
- Page views of published portfolios and case studies, recorded on our servers with a random visitor identifier generated in the visitor's browser. We do not store visitor names or email addresses with these events.
- Standard request information handled by our hosting provider while serving the site, which can include IP address, browser and device details.
- Error and diagnostic logs generated when something fails, used to fix problems.
Transaction information
Some visual themes are paid. When you buy one, we store the theme purchased, the amount, currency, order and payment reference identifiers, and the payment status returned to us. Card and banking details are entered with our payment provider and are never received or stored by Document Portfolio.
3. How we use information
- To provide and operate the platform
- To create and manage your account and sign you in
- To store, render and back up your portfolio content
- To publish your portfolio and case studies according to your settings
- To show you view counts for your own published work
- To process theme purchases and record what you own
- To provide support and respond to your requests
- To detect, prevent and investigate abuse, fraud and security incidents
- To fix bugs and improve the product
- To send necessary account and service messages, such as email verification and password reset
- To meet legal obligations that apply to us
4. Public and private content
Draft content is private. A portfolio and its case studies are only reachable by the public once you choose to publish them, and our servers check publication status on every public request — not just in the interface.
Individual case studies can additionally be marked private, in which case they are excluded from your public portfolio even while the portfolio itself is published.
Published pages are open to anyone with the link and may be indexed by search engines, saved by others, or shown in link previews. Unpublishing removes public access to the page going forward, but copies already saved or cached elsewhere are outside our control.
Your email address is never shown on your public portfolio page unless you add it yourself as a contact link.
Please do not publish confidential client, employer or NDA-restricted material without permission.
6. Third-party services we use
- Lovable Cloud (built on Supabase) — application database, authentication and file storage for your account, content and uploads.
- Lovable — hosting and delivery of the application, and delivery of account emails such as verification and password reset.
- Google — optional "Continue with Google" sign-in, the web fonts used by the interface and portfolio themes, and Search Console verification for the marketing site.
- Razorpay — payment processing for paid themes, including the checkout screen where payment details are entered.
Each provider handles information under its own privacy terms and only for the purpose described above.
8. Data security
We apply reasonable technical and organisational safeguards, including encrypted connections, hashed passwords handled by our authentication provider, database access rules that scope private records to their owner, server-side authorisation checks on protected operations, sanitisation of user-authored rich text, upload type and size validation, and private file storage with time-limited links.
No online service can be completely secure. We cannot guarantee absolute security, and you are responsible for keeping your password confidential.
9. Data retention
We keep account information and content for as long as your account exists. When you delete your account, your profile, portfolio, case studies, uploaded files and stored view events are removed from the live systems.
Purchase records may be retained where required for accounting, tax or dispute purposes, and backups or logs may persist for a limited period before rotating out.
10. Account deletion
You can delete your account from your profile page. Deletion is permanent and removes your profile details, portfolio, case studies, uploaded files, stored view events and your login identity, and signs you out of all sessions.
Published pages stop being served once the account is deleted. Copies that search engines or other people already saved are outside our control.
Records we must keep for legal or accounting reasons, such as purchase references, may be retained in a minimised form rather than deleted.
11. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, export or restrict the use of your personal information, to object to certain processing, and to withdraw consent where processing is based on consent. These rights and their limits differ by jurisdiction, and not all of them apply to everyone.
Most of them you can exercise directly: edit your profile and content in the app, or delete your account. For anything else, contact us at support.documentportfolio@gmail.com.
12. Children's privacy
Document Portfolio is intended for working and student designers and is not directed to children. You must be at least [MINIMUM AGE, e.g. 16] years old to create an account. If we learn that an account belongs to someone below that age, we will remove it.
13. Changes to this policy
We may update this policy as the product or applicable law changes. When we do, we will revise the "Last updated" date above, and for material changes we will give notice in the application or by email.
14. Contact
Questions or privacy requests: support.documentportfolio@gmail.com