Privacy Policy
This policy explains how MyPortfolioHub processes information when you use Workfolio.
1. Scope
This policy applies to the Workfolio web application, its portfolio, resume, and work-letter tools, account and enterprise workspace features, and public portfolio and resume pages generated by the service. Separate MyPortfolioHub products may have their own privacy terms.
2. Information we process
Account data. We process information such as your name, email address, password hash, connected OAuth provider identifiers, account role, organization membership, preferences, and account timestamps.
Portfolio data. You decide what to place in a portfolio. This can include your professional profile, contact details, skills, career history, projects, education, certifications, external links, custom sections, public URL, theme, and search-indexing preference.
Resume data. You decide what to place in a resume. This can include contact details, employment history, education, skills, projects, certifications, languages, references, links, and formatting preferences.
Work-letter data. You decide what to place in workplace correspondence. This can include sender and recipient details, employer information, dates, job or department information, reasons for requests or notices, workplace facts, and the letter body. Work letters are private account documents and are not assigned public share links by the current application.
Security data. The service may process encrypted two-factor-authentication secrets, one-way recovery-code and account-token digests, email-verification timestamps, password-change timestamps, rate-limit information, security/audit events, request identifiers, coarse device labels, session timestamps, and privacy-preserving network identifiers used to detect abuse and support investigations. Workfolio does not store plaintext verification or password-reset tokens.
Usage and public-view data. When a public portfolio or resume is viewed, the service may record a privacy-preserving visitor hash, the referring site origin, the resource viewed, and the time of access. The current implementation intentionally does not retain the visitor User-Agent for these public-view analytics.
3. How we use information
We use information to provide and personalize the service; authenticate users; save and render portfolios, resumes, and work letters; support organization collaboration; provide public sharing that you enable; maintain auditability; prevent fraud, abuse, and unauthorized access; diagnose failures; enforce service limits; and improve reliability and usability.
5. Public portfolio and resume links
New portfolios and resumes are private by default. If you publish a portfolio or enable a public resume link, anyone who obtains that URL may be able to view the published information until you disable sharing. Portfolio publishing and search-engine indexing are separate controls; indexing remains off unless you explicitly enable it. Search engines, employers, recipients, screenshots, or third parties may preserve information after you make it public. Review the content before publishing.
6. Retention
We retain account, portfolio, resume, and work-letter data while needed to operate the account and provide the service. Security logs, backups, audit records, and organization records may be retained for additional periods when necessary for integrity, recovery, security, dispute resolution, or legal obligations. Production retention periods should be documented in the operator’s internal retention schedule.
7. Security and session cookies
The service uses essential session and remember-me cookies plus a server-side session registry to keep users authenticated, show signed-in devices, and support session revocation. Production cookies are configured with Secure, HttpOnly, and SameSite attributes. The service also uses controls such as password hashing, CSRF protection, security headers, rate limiting, role-based access controls, two-factor authentication for privileged accounts, encrypted TOTP secrets, database constraints, request-size limits, and dependency health monitoring. No system can guarantee absolute security, so users should also protect their accounts and devices.
8. Your choices and rights
You can edit portfolio, resume, and work-letter information; control whether a portfolio or resume is public; control whether a public portfolio may be indexed by search engines; manage supported identity providers and signed-in sessions; export portable account data; request email verification; and, subject to enterprise ownership and administrator safeguards, permanently delete your account from account settings. Depending on applicable law, you may also have rights to request access, correction, deletion, restriction, portability, or other handling of personal information. Requests can be sent to the privacy contact below and may require identity verification.
9. International users and children
Service infrastructure or providers may process information in countries other than your own. Where required, the operator should configure appropriate contractual and technical safeguards. The service is not designed for children who cannot lawfully consent to an online account in their jurisdiction; organizations using the product with minors should establish appropriate authorization and privacy procedures.
10. Policy changes
We may update this policy when product features, providers, legal obligations, or privacy practices change. The current version and effective date appear on this page, and material changes may require renewed consent.
11. Privacy contact
Privacy requests and questions can be sent to privacy@myportfoliohub.online. General service questions can be sent to support@myportfoliohub.online.
Confirm the actual legal entity, hosting regions, subprocessors, retention schedule, age requirements, and procedures for data-subject requests. Have qualified counsel review this policy for the jurisdictions in which you offer the service.