Privacy Policy
Last updated: 8 August 2026
This explains what Portfolio Booster collects about you, why, and what you can do about it. Portfolio Booster is run by an independent sole trader based in the United Kingdom, who is the data controller for the purposes of UK GDPR. Contact: git.booster@gmail.com.
What we collect, and why
- Your GitHub profile — username, display name, email address and avatar, received when you sign in. Lawful basis: performance of our contract with you.
- A GitHub access token — encrypted with AES-256-GCM before it is written to our database, and used only to create repositories and commits for you. Lawful basis: performance of our contract with you.
- Billing records — your Stripe customer and subscription identifiers, plan, payment status and invoice history. Card details are held by Stripe and never reach our servers. Lawful basis: performance of our contract, and our legal obligation to keep financial records.
- Product analytics — which onboarding steps you reached, tied to a first-party cookie and to your account once you sign in, plus how you arrived: any campaign tag on the link, the site that referred you, whether you opened it in an app such as TikTok or Instagram, and your country. We do not store your IP address. We use this only to find where people get stuck and which channels work. Lawful basis: our legitimate interest in understanding and improving the service.
- Error logs — when something fails, we record what happened and which account it affected, so we can fix it. Lawful basis: our legitimate interest in a working service.
We do not use your data to train machine-learning models, and we do not sell it.
Cookies
- Session cookie (
authjs.session-token) — keeps you signed in. Strictly necessary; the site cannot work without it. - Analytics cookie (
pb_anon) — a random identifier, valid for one year, that lets us measure how many people get from one onboarding step to the next. It contains nothing about you personally and is never shared.
We use no third-party advertising or tracking cookies. You can delete both cookies in your browser at any time; deleting the session cookie signs you out.
Who else processes your data
- Stripe — payments and subscription management.
- Vercel — hosting.
- Neon — database hosting.
- GitHub — the account you connect, and where your projects are created.
These providers act on our instructions under written data-processing terms. Some are based in the United States, so your data may be transferred outside the UK. Where that happens it is covered by the UK's International Data Transfer Addendum or equivalent safeguards.
How long we keep it
- Account and GitHub data — for as long as your account exists, and deleted when you close it.
- Billing records — six years after the transaction, as UK tax law requires.
- Analytics and error logs — up to 12 months.
How we protect it
GitHub access tokens are encrypted at rest with AES-256-GCM, so the database alone is not enough to use them. All traffic runs over HTTPS. Access to production systems is limited to the operator.
If a breach ever puts your rights at risk, we will tell you and report it to the ICO within 72 hours of becoming aware of it.
Your rights
Under UK GDPR you can ask us to:
- give you a copy of the data we hold about you;
- correct anything inaccurate;
- delete your data (“the right to be forgotten”);
- restrict or object to how we use it, including our analytics;
- send your data to you or another provider in a portable format.
Email git.booster@gmail.com and we will respond within one month. You can also revoke our access to your GitHub account at any time from your GitHub settings, without asking us.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office, the UK's data protection regulator.
Changes
If we change how we use your data in a way that affects you, we will email you. The date at the top always reflects the current version.