Perfolio Privacy Policy
Perfolio is a private, individually-owned system designed to capture your work, map it to promotion rubrics, track advocates, and generate promotion packets on demand.
Information Collection & AI Processing
Perfolio is built from the ground up as a private career system. We collect and process only the information required to build and maintain your individual promotion readiness record:
- Career Inputs & BillingWe collect text logs, imported Markdown history, company rubrics, Google SSO authentication, and Stripe billing information.
- Sponsor DataNames of advocates discovered through imports remain inert candidates until explicitly confirmed by you.
- AI Processing & Human Review GateWe use Google Gemini to propose rubric matches. Every AI output is placed behind an accept/reject gate, meaning the AI never writes facts automatically. All AI responses are validated via a Zod schema before database insertion.
Connected Workspaces & Third Parties
You may optionally connect third-party workspaces. We enforce strict, code-level limitations on these integrations to protect your employer's data and your privacy:
- GitHub (Read-Only)Access is limited to merged PRs, reviews, and closed issues. We do not request scopes to write, comment, or push.
- Slack (Search-Only)Access is limited to on-demand searches of public channels. We do not use background monitoring or store message history; we persist only what you explicitly save.
- Service ProvidersWe share infrastructure data strictly to operate the service utilizing Supabase for database and authentication, Stripe for billing, Google Gemini for AI, Resend for transactional emails, and Sentry for error monitoring.
Security & Trust Architecture
Because Perfolio holds candid assessments of your career gaps, privacy is enforced directly in our codebase rather than acting as a compliance afterthought:
- Row-Level Security (RLS)Every user table in our Postgres database applies RLS scoped exclusively to your unique user ID.
- Encrypted TokensOAuth provider tokens are encrypted at rest using AES-256-GCM and stored in a separate table unreachable by the client.
- CSRF ProtectionsOAuth states are HMAC-signed, expiring, and bound to a specific user to defeat account-linking attacks.
Data Ownership & Enterprise Offerings
Perfolio is built primarily for your individual career case:
- Total OwnershipYour data is owned by you and is designed to survive job changes.
- Enterprise Expansion & Opt-In ConsentWhile we may offer manager and organizational tooling in the future, these features will never compromise our core privacy promise. Any B2B surfaces—such as cross-user aggregation, manager share links, or cohort benchmarks—are disabled by default in the individual product. If Perfolio is provided to you by your employer, sharing your private promotion readiness data with management will always require your explicit, opt-in consent.
Questions regarding privacy or data governance?
Contact our privacy team directly with any data inquiries, export requests, or security verifications.