Effective date: September 9, 2026
Last updated: September 9, 2026
Contact: creatorfolio.app@gmail.com
1. Introduction
Creatorfolio (“Creatorfolio”, “we”, “us”) provides a service at creatorfolio.app that lets a creator build a public portfolio page showing their own work and the performance of that work. This policy describes how Creatorfolio collects, uses, stores, protects, shares and deletes information when you use the service — including what happens when you voluntarily connect a third-party platform such as YouTube. It applies to creatorfolio.app, its subdomains, and public creator portfolios published at creatorfolio.app/@username.
If you have any question about this policy, or want your data exported or deleted, email creatorfolio.app@gmail.com.
2. Information you provide to Creatorfolio
You give Creatorfolio information directly when you create an account and build your portfolio. In practice this is:
- Account information — your email address and, if you sign up with an email and password, a hashed password. Creatorfolio never stores your password in readable form.
- Sign-in with Google (optional) — if you choose to sign in with Google rather than a password, we receive your name, email address, Google account identifier and profile image URL from Google in order to create and identify your account. This is separate from connecting YouTube (see section 4).
- Username / handle — the handle your public portfolio uses, plus a record of handles you previously used, so old links can be understood and handles are not silently reused.
- Profile information — display name, headline, short bio, profile image you upload, location if you enter one, and the content categories you pick.
- Portfolio information — the posts, links, titles, thumbnails, images, case studies and brand logos you add or keep, the order and layout you choose, and which items you pin or hide.
- Commercial details you choose to add — services and formats you offer, indicative rate range, turnaround, brands you have worked with, a booking link, and a contact email for enquiries.
- Self-entered platform figures — where a platform is not connected, any follower or view numbers you type in yourself. These are labelled as self-reported on your public page; they are never presented as verified.
- Enquiries sent to you — if you enable the contact form, the name, email, brand, budget and message a visitor submits are stored so you can read them.
- Support correspondence — anything you send us by email.
Creatorfolio does not ask for platform passwords, and does not read private messages, drafts or non-public posts on any platform.
3. Information collected automatically
- Technical and log information — our hosting and database providers record standard request data such as IP address, browser and device type, pages requested, timestamps and error traces, in order to serve the site, keep it available and diagnose problems.
- Portfolio view counts — when someone opens a public portfolio, Creatorfolio records a first-party view event containing the time, a coarse referrer, a coarse country and device type, so the creator can see how often their page and media kit are opened. No advertising identifier and no cross-site tracking is involved.
- Session and preference storage — see section 15 on cookies.
Creatorfolio does not run advertising, does not build advertising profiles, and does not use your information to track you across other websites.
4. Google and YouTube Data
Connecting YouTube is entirely optional. If you choose to connect it, Creatorfolio uses Google’s OAuth authorization process and requests read-only YouTube access (the https://www.googleapis.com/auth/youtube.readonly scope). Google shows you exactly what is being requested before you approve it.
Once you have authorized it, Creatorfolio may retrieve the following information through the YouTube Data API, where it is available for your account:
- your YouTube channel ID;
- your channel name / title;
- your channel handle;
- your channel profile image;
- your subscriber count;
- your uploads playlist identifier;
- the video IDs of videos in that uploads playlist;
- video titles;
- video thumbnails;
- video publication dates;
- video duration;
- video URLs / identifiers;
- video view counts;
- video like counts;
- video comment counts (the number of comments, not the comments themselves);
- other read-only information returned by those approved YouTube Data API endpoints where it is necessary for the portfolio functionality described below.
Some of this may not be available. If you hide your subscriber count, disable likes, disable comments, or Google otherwise does not return a value, Creatorfolio stores nothing for that field and shows nothing rather than estimating it. Creatorfolio does not receive private analytics such as watch time, audience demographics or revenue, because the read-only scope above does not provide them.
5. How that YouTube information is used
Authorized YouTube information is used solely to provide the portfolio features you asked for by connecting, namely:
- identifying which YouTube channel belongs to you;
- importing your uploaded videos so you do not have to paste links by hand;
- displaying the videos you keep on your Creatorfolio portfolio;
- displaying the performance figures that the API makes available for those videos;
- comparing a video’s performance against your own historical baseline on your own channel;
- identifying your stronger-performing content;
- organising imported content into portfolio sections (“shelves”) such as featured, trending and recent;
- keeping imported content and its available figures up to date through authorized synchronization, so your page does not go stale;
- automatically building and maintaining your portfolio for you.
This information is not used for advertising, is not sold, is not used to train generalised or AI models, and is not used for any purpose unrelated to showing and ranking your own work on your own portfolio.
6. The YouTube integration is read-only
Creatorfolio only requests read-only YouTube access. With the permission requested, Creatorfolio does not and cannot use your connection to:
- upload videos;
- edit videos or their metadata;
- delete videos;
- post comments;
- modify or delete comments;
- send messages;
- subscribe to or unsubscribe from channels on your behalf;
- change your channel, branding or settings;
- publish anything or take any other write action on your behalf.
7. Google OAuth tokens
When you approve the connection, Google issues Creatorfolio authorization credentials — an access token and, where Google provides one, a refresh token. These credentials are exchanged and stored server-side. They are held in a restricted database table that the public browser client cannot read, and they are never sent to the browser, never embedded in your public page, and never published in this or any other document. They are used only to make the read-only YouTube requests described above and, where Google permits, to refresh access so synchronization can continue without asking you to sign in again.
8. Google API Services User Data Policy
Creatorfolio’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. Data storage and security
Creatorfolio runs on managed cloud infrastructure. Data is transmitted over TLS and stored by our hosting and database provider with encryption at rest. Passwords are stored only as hashes by the authentication provider. Access to your rows is restricted at the database level with row-level security so that one creator’s account cannot read another creator’s private data, and plan limits and permissions are enforced on the server rather than only in the interface. OAuth tokens and internal service credentials are kept in server-side storage that browser clients have no read access to, and are only used by server code.
No online service can be guaranteed to be completely secure, and we do not claim otherwise. If we become aware of a security incident affecting your personal data, we will notify you and, where the law requires, the relevant authority.
10. How information is shared
Creatorfolio does not sell personal data, does not share it for cross-context behavioural advertising, and has no advertising partners. Information is shared only with the service providers needed to operate the product, and only to the extent each needs:
| Provider | What it handles |
|---|---|
| Lovable Cloud (Supabase infrastructure) | Application hosting, database, authentication, and file storage for uploaded images |
| Google / YouTube | Optional sign-in with Google, and the read-only YouTube Data API requests you authorize |
| Stripe | Subscription billing if you subscribe to Creatorfolio Live. Card details are handled by Stripe; Creatorfolio stores only plan status and subscription identifiers, never full card numbers |
We may also disclose information where we are legally required to, to enforce our Terms, or to protect the rights and safety of creators or the public. If Creatorfolio were ever acquired, you would be told before your data became subject to a different privacy policy.
It helps to be precise about three different categories:
- Kept private — your email address, password hash, billing identifiers, OAuth tokens, enquiries sent to you, and analytics about your own page.
- Published by you — anything you place on your public portfolio (see section 11).
- Processed by providers — the infrastructure listed above, acting on our instructions.
11. Public portfolios
Creatorfolio exists so you can publish a portfolio. Once you publish, the page at creatorfolio.app/@username is public: anyone with the link can view it, and search engines can index it. Depending on what you add and keep, that page can include:
- your display name and handle;
- your profile image;
- your headline, bio and content categories;
- your location, if you entered one;
- which platforms you are on, your handles there, and follower counts;
- the posts and videos you keep, with their titles and thumbnails;
- the performance figures shown for those posts, labelled by where they came from;
- case studies and brand logos you add;
- your rate range, services, turnaround, booking link and contact option, if you choose to show them.
Your email address, password, billing details, OAuth tokens and enquiry inbox are never part of the public page. You can unpublish your portfolio at any time from the builder.
12. How long information is kept
- Account, profile and portfolio data is kept for as long as your account exists.
- Imported platform content and figures are kept while the portfolio exists and are overwritten by later synchronizations.
- OAuth tokens are kept only while the connection is active. They are deleted when you disconnect the platform or delete your account.
- When you delete your account, your account and all data linked to it are deleted from our live systems as part of that request. Copies can persist in routine encrypted backups for a short period until those backups rotate out.
- Billing records that we are legally required to keep for tax and accounting purposes are retained for as long as that law requires, even after account deletion.
- Support emails are kept as long as needed to handle the request and any follow-up.
13. Disconnecting YouTube
You can disconnect YouTube at any time from your Creatorfolio builder, under Platforms, using the “Disconnect” control on the YouTube panel. When you do:
- Creatorfolio asks Google to revoke the token, so the authorization is handed back;
- the stored access token and refresh token are deleted from our database;
- the connection record is removed and no further synchronization happens;
- content that was already imported into your portfolio remains on your portfolio, so your page does not suddenly empty. It simply stops updating. You can hide or delete any of those items individually in the builder, or delete your account to remove everything.
14. Deleting your data
You can delete your Creatorfolio account yourself. Sign in, open your dashboard, and use Delete my account at the bottom of the page. You will be asked to type a confirmation word, and the deletion is immediate and permanent. It removes:
- your account and sign-in identity;
- your profile and public portfolio, which stops being reachable;
- all imported and manually added content, case studies, platform entries and enquiries;
- images you uploaded, including your profile image, brand logos and stored thumbnails;
- any connected-platform records and their stored Google/YouTube tokens — the YouTube grant is revoked with Google as part of the same request.
If you would rather we did it for you, or you want a copy of your data first, email creatorfolio.app@gmail.com from the address on your account and we will handle it. We aim to respond within 30 days.
15. Revoking access through Google
Independently of Creatorfolio, you can review and remove Creatorfolio’s access to your Google account at any time in your Google Account under Security → “Your connections to third-party apps & services”, at myaccount.google.com/permissions. Those settings are controlled by Google, not by Creatorfolio. If you revoke access there, synchronization stops and Creatorfolio’s stored tokens become unusable; disconnecting inside Creatorfolio additionally deletes them from our database.
16. Cookies, storage and analytics
Creatorfolio uses strictly necessary browser storage to keep you signed in (a session stored by the authentication provider) and to remember your light/dark theme choice and your cookie-banner answer. Portfolio view counting, described in section 3, is first-party and aggregated for the creator. No third-party advertising or cross-site tracking cookies are used. If we ever add an optional analytics provider, it will load only after you accept it in the banner, and it will be named in the Cookie Policy.
17. Third-party services
Creatorfolio interacts with third-party services in order to work: the infrastructure providers listed in section 10, and the platforms you connect. Your use of YouTube and your Google account is also governed by Google’s and YouTube’s own terms and policies, including the YouTube Terms of Service and the Google Privacy Policy. Creatorfolio does not control Google, YouTube or any other platform, and cannot change what they collect or how they behave.
18. Children’s privacy
Creatorfolio is intended for creators aged 16 and over and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe someone under that age has created an account, email creatorfolio.app@gmail.com and we will remove the account and its data.
19. Your rights and choices
- Account information — you can view and change your profile details at any time in the builder.
- Public information — you decide what appears on your public page, and you can hide individual items or unpublish the whole portfolio.
- Connected accounts — connecting is optional, and you can disconnect at any time (section 13) or revoke access with Google (section 15).
- Deletion — you can delete your account and its data yourself (section 14).
- Access and portability — email us and we will provide a copy of the personal data we hold about you.
- Correction, objection and withdrawal of consent — email us, or change the relevant setting in the product.
- Marketing — service emails (sign-in, password reset, billing, material changes) are part of running your account; any product news is optional and can be unsubscribed from in the message itself.
Depending on where you live, local law may give you additional rights, including the right to complain to your data protection authority. We do not sell or share personal data as those terms are used in US state privacy laws.
20. Changes to this policy
We may update this Privacy Policy as the product changes. When we do, the “Last updated” date at the top of this page will change, and for material changes we will notify account holders by email before the change takes effect.
21. Contact
Privacy, data access and deletion requests: creatorfolio.app@gmail.com.
Creatorfolio, creatorfolio.app
Effective September 9, 2026.