Privacy Policy

Effective September 10, 2026

We collect only the data required to operate the builder, store saved projects, and process payments. We never sell your personal information.

Data collection

Guest builder usage: Zero data collection. The builder runs client-side in your browser. Project data uploads only when you save to cloud storage, process a payment, or publish models to the public catalog.

Account details: When you register, Clerk manages your email address and authentication identifier.

Portfolio data: Registered users store compressed asset files and project configurations on Supabase.

Payment data: Stripe processes all transactions. We receive transaction confirmations and billing identifiers. We do not store or process payment card details.

Data usage

Data serves only operational needs: authentication, project storage, transaction processing, and support requests. We do not build marketing profiles or serve targeted ads.

Third-party service providers

We use three specialized providers: Clerk for authentication, Supabase for database and asset storage, and Stripe for billing. Each vendor processes data strictly within their service scope.

Data retention

Data remains active while your account is open. Account deletion via the dashboard triggers an immediate sequence: subscription cancellation, deletion of saved portfolios and stored assets, and deletion of your authentication credentials. Stripe retains required transaction records for statutory accounting compliance.

To avoid server storage, export a local .xrfolio file from the builder. Local files remain on your computer.

Free accounts without login activity for 12 months enter automated cleanup. We send an email notice 30 days prior to removing stored assets. Active Pro accounts and projects with models published to the public catalog remain exempt from inactivity pruning.

Cookies

Only what sign-in needs: a session cookie set by Clerk. No advertising or tracking cookies.

Your choices

See or delete your data any time from the dashboard, or email cperos@xrtech.dev and we’ll handle it directly.

Children

PortfolioMaker isn’t directed at children under 16, and we don’t knowingly collect their data.

Changes

If this changes in a way that matters, we’ll update the date at the top of this page.

Contact

cperos@xrtech.dev