Privacy Policy

Last updated: September 2026

1. Overview

ImDeveloper.link ("the Service", "we", "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, how we store it, and your rights regarding your personal information. By using the Service, you agree to the practices described in this policy.

2. Data We Collect

2.1 Account Information

When you register, we collect:

  • Email address
  • Username (chosen by you)
  • Display name (optional)
  • Profile avatar (optional)
  • Bio text (optional)
  • Hashed password (if using credential-based login)

2.2 OAuth Data

If you sign in via Discord, Google, or GitHub, we receive your public profile information (name, email, avatar) from the provider. We store only the data necessary to authenticate your session. We do not receive or store your OAuth provider password.

2.3 Portfolio Content

All content you create — section text, project descriptions, links, images, custom CSS, theme preferences — is stored in our database and served publicly at your chosen URL when your portfolio is published.

2.4 Usage & Analytics Data

  • Page view counts and timestamps for published portfolios
  • Referrer URLs (where visitors came from)
  • Browser user-agent strings (anonymized for analytics display)
  • Country-level geolocation derived from IP addresses (IP addresses are not stored)

2.5 Payment Data

Subscription payments are processed by Stripe. We store your Stripe customer ID, subscription ID, and billing period dates. We do not store your credit card number, CVV, or full billing address. All payment data is handled directly by Stripe under their Privacy Policy.

2.6 Contact Submissions

If a visitor submits a message through your portfolio's contact form, we store the sender's name, email, and message body so that you can view and respond to it.

3. How We Use Your Data

  • To operate the Service — authenticate you, render your portfolio, process payments, and deliver features tied to your subscription plan.
  • To provide analytics — show you view counts, referrer data, and geographic breakdowns of your portfolio traffic (Pro and Business plans).
  • To send transactional emails — account verification, password resets, billing receipts, and security notifications. We will never send marketing emails without your explicit opt-in.
  • To improve the Service — aggregate, anonymized usage data may be used to identify bugs, improve performance, and guide feature development.
  • To enforce our Terms — detect and prevent abuse, spam, and unauthorized access.

4. Data Storage & Security

Your data is stored in encrypted databases hosted on secure infrastructure. Passwords are hashed using bcrypt with a cost factor of 12 and are never stored in plaintext. Sessions use signed JWT tokens with configurable expiration.

We implement industry-standard security practices including HTTPS encryption for all traffic, CSRF protection, rate limiting on authentication endpoints, and input sanitization. While no system is 100% secure, we take reasonable measures to protect your data from unauthorized access, disclosure, or destruction.

5. Data Sharing

We do not sell, rent, or trade your personal data. We share data only in these limited cases:

  • Stripe — payment processing (name, email, subscription details).
  • OAuth Providers — authentication handshake only (Discord, Google, GitHub). No portfolio data is sent back.
  • Legal Compliance — we may disclose data if required by law, court order, or government request.
  • Portfolio Visitors — content you publish on your portfolio is publicly accessible by design. This includes text, images, links, and any information you choose to display.

6. Cookies & Local Storage

We use session cookies to authenticate logged-in users. These are strictly functional — we do not use advertising cookies, tracking pixels, or third-party analytics scripts. Your browser may store a JWT session token and UI preferences (theme, sidebar state) in local storage. You can clear these at any time through your browser settings.

7. Your Rights

You have the right to:

  • Access — request a copy of all personal data we hold about you.
  • Correct — update inaccurate information through your account settings.
  • Delete — request permanent deletion of your account and all associated data.
  • Export — download your portfolio data in JSON format through the Export page.
  • Restrict — unpublish your portfolio at any time to remove it from public access.
  • Withdraw Consent — revoke OAuth connections or email preferences at any time.

To exercise any of these rights, contact us at [email protected] or use the relevant controls in your account settings.

8. Data Retention

  • Active accounts — data is retained for the lifetime of your account.
  • Deleted accounts — all personal data, portfolio content, and analytics are permanently deleted within 30 days of account deletion. Anonymized, aggregate statistics (total platform view counts) may be retained.
  • Backups — encrypted backups may retain deleted data for up to 90 days before automatic purging.
  • Contact submissions — messages sent to your portfolio are deleted when you delete them or when your account is deleted.

9. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact us immediately and we will delete the account and associated data.

10. International Users

If you are accessing the Service from outside the United States, your data may be transferred to and processed in the United States. By using the Service, you consent to this transfer. We comply with applicable data protection laws including, where relevant, the General Data Protection Regulation (GDPR) for users in the European Economic Area.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes that affect how we handle your personal data, we will notify you via email or an in-app announcement before the changes take effect.

12. Contact

For privacy-related questions, data requests, or concerns, contact us at [email protected].

© 2026 ImDeveloper.link