PortfolioBuild

Privacy Notice

Last updated 6 August 2026

How PortfolioBuild handles your personal data, who else processes it, and what you can ask us to do with it.

1. Who is responsible

Ayoub Boukyoud, a sole individual based in Morocco, trading as PortfolioBuild, is the controller of the personal data described here. Contact: support.portfoliobuild@gmail.com.

2. What we collect

Account data. Your email address and name. If you register with a password we store only a cryptographic hash of it, never the password itself. If you sign in with Google we receive your email address, name and profile picture from Google.

Content you upload. CV files, portfolio text, project descriptions and images. A CV can contain a lot about you — employment history, education, phone number, photograph — and it is processed as described in section 3.

Subscription data. Your plan, its status, and a record of payments received including amount, currency and our payment provider’s identifiers. We never receive or store your card number, expiry or security code.

Technical data. Server logs of requests, including IP address, for security and debugging. If you connect a custom domain we store that domain and perform DNS lookups to verify it.

3. How CV import works, and what leaves our servers

When you import a CV, the file is sent to Google’s Gemini API, which reads it and returns structured fields we use to fill in your portfolio. This means the contents of the CV you upload are transmitted to and processed by Google, under Google’s terms for that service, on infrastructure outside Morocco. If you would rather this did not happen, do not use CV import — every field can be entered by hand instead.

If Google’s service is unavailable we fall back to a parser that runs entirely on our own server.

Detecting and cropping a portrait photograph out of a CV is done locally on our server. That step sends no image anywhere.

4. Why we process it, and on what basis

To provide the service you asked for — creating your account, building and publishing your portfolios, importing a CV — on the basis of performing our contract with you.

To take payment and keep records of it, on the basis of our contract and our legal obligations.

To keep the service secure, prevent abuse and diagnose faults, on the basis of our legitimate interests in operating it safely.

5. Who else processes your data

Paddle.com Market Limited — sells subscriptions as Merchant of Record and processes payments, including card details, directly.

Google — the Gemini API for CV extraction (section 3), and Google Sign-In if you use it.

Oracle Cloud Infrastructure — hosts the servers and the database where your account and content are stored.

We do not sell your personal data, and we do not use it to train machine-learning models of our own.

6. What is public

A portfolio you publish is public: its content, including any photograph and contact details you put in it, can be read by anyone with the address and may be indexed by search engines. Publishing is always your choice, and you can unpublish at any time — though material already copied or cached elsewhere is outside our control.

Portfolios set to unlisted are excluded from our sitemap but remain reachable by anyone who has the link.

7. How long we keep it

Account and content data is kept while your account exists. When you delete your account, your portfolios are removed from publication and your content is deleted.

Records that money moved are kept after account deletion, with the account no longer linked to them, because we need them for accounting and tax. Server logs are kept only as long as they are useful for security and debugging.

8. Your rights

You can ask us for a copy of your data, to correct it, to delete it, or to restrict or object to how we use it. Where processing relies on consent you can withdraw it. Email support.portfoliobuild@gmail.com and we will respond within 30 days.

If you are in the European Union or United Kingdom you also have the right to complain to your national data protection authority.

9. Cookies and local storage

We store a sign-in token in your browser so you stay logged in. It is necessary for the service to work and is not used for advertising or tracking. We do not use analytics or advertising cookies.

When you open a checkout, our payment provider’s script may set its own cookies; those are governed by Paddle’s privacy notice.

10. Changes

We may update this notice; the date at the top shows the current version. Material changes affecting how we use data you have already given us will be notified by email. See also our Terms of Service.