Privacy Policy
Last updated: [DATE]
This policy explains what Portfolio Booster collects and why. The controller is [LEGAL ENTITY NAME], [ADDRESS].
What we collect
- GitHub profile — your username, display name, email address and avatar, received when you sign in.
- A GitHub access token — encrypted with AES-256-GCM before it is written to our database, and used only to create repositories and commits for you.
- Billing records — your Stripe customer and subscription identifiers, plan, and payment status. Card details are held by Stripe and never reach our servers.
- Product analytics — which onboarding steps you reached, tied to a first-party cookie and to your account once you sign in. We use this to find where people get stuck.
Cookies
We set a session cookie to keep you signed in, and a first-party analytics cookie (pb_anon) that gives your browser a random identifier so we can measure drop-off. We do not use third-party advertising or tracking cookies.
Who we share it with
Our processors are Stripe (payments), [HOSTING PROVIDER — e.g. Vercel] (hosting) and [DATABASE PROVIDER — e.g. Neon] (database). We do not sell personal data.
How long we keep it
For as long as your account exists. Deleting your account removes your profile, tokens and projects; billing records are retained where required for accounting purposes.
Your rights
You can request access to, correction of, or deletion of your data, and you can revoke our GitHub access at any time from your GitHub settings. Email [EMAIL] and we will respond within 30 days.