Privacy policy
What Vitafolio collects, why, who sees it and the rights you have over it.
Last updated 5 October 2026
1. Who is responsible
Vitafolio is run by Isaac Adjei, who is the data controller for the personal data described here under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You can contact the controller at contact@isaacadjei.me or through the contact page.
2. What we collect
Information you give us
- Account details: your name, email address and a password stored only as a secure one-way hash. If you turn on two-factor authentication, its secret and recovery codes are stored encrypted. Passkeys store only a public key; your fingerprint, face or PIN never leaves your device.
- Profile: your handle, photo, headline, bio, pronouns, location, university, availability and links.
- CVs: everything you add to a CV, such as its sections, skills, projects, images, videos, uploaded files and LaTeX source.
- Messages and reports: what you write when you contact us, message a CV owner or report a CV.
Information from sign-in providers
If you sign in with Google, GitHub, Microsoft or LinkedIn, we receive your name, email address, profile photo address and an identifier for your account with that provider. We never receive your password for that provider. We never post anything on your behalf.
Information collected automatically
- Sign-in records: a session cookie keeps you signed in. Failed sign-in attempts are counted for a short time against your email and network address to stop password guessing.
- Visit counts: see section 4.
- Error reports: if something breaks, a technical report of the error is recorded. These reports are set up to leave out personal details such as your email address.
- Site analytics: where enabled, Cloudflare Web Analytics counts page visits without cookies and without identifying you.
3. Why we use it and our legal bases
| Purpose | Legal basis |
|---|---|
| Providing your account, profile and CVs to you and to the people you choose | Contract: it is the service you signed up for |
| Sending account emails such as verification, password resets and messages from visitors | Contract |
| Keeping the site secure, preventing abuse and moderating reported content | Legitimate interests in a safe service for everyone |
| Counting visits to show you how your CVs are doing | Legitimate interests, using counts that cannot identify anyone |
| Keeping records the law requires | Legal obligation |
We never sell your data, never show adverts and never use your data to build marketing profiles.
Automated decisions
We make no decisions about you by automated means. Two automated checks run without affecting your rights: Cloudflare Turnstile scores whether a form submission is likely to come from an automated script, and new passwords are checked against a list of known breached passwords using only a short hash prefix.
4. People who visit a CV
When someone opens a CV or profile, we count the visit once per day. To do that we make a one-way code from the date, the visitor's network address and their browser details. The network address itself is never stored. The code changes every day and cannot be turned back into the address. We also keep the website the visitor came from, when their browser shares it, so owners can see where their views come from. The owner's own visits are never counted.
If a visitor reports a CV, we store a one-way code instead of their network address so repeat reports can be recognised without identifying anyone.
5. Who we share it with
Content you make public is visible to anyone. It may also be indexed by search engines unless you make it unlisted or private. Beyond that, we only share data with the service providers that run the site for us, under contracts that limit what they can do with it:
| Provider | What they do |
|---|---|
| Render | Runs the website, in Frankfurt, Germany |
| Aiven | Hosts the database, in Frankfurt, Germany |
| Cloudinary | Stores CV files, project images and videos |
| Resend | Delivers account emails and messages from visitors |
| Cloudflare | Routes traffic to the site, protects forms from spam and counts visits without cookies |
| Sentry | Records technical error reports |
| Google, GitHub, Microsoft and LinkedIn | Confirm who you are, only if you choose to sign in with them |
We would only disclose data to anyone else if the law requires it or to protect someone's safety.
6. Transfers outside the UK
The website and database run in Germany, which the UK recognises as giving adequate protection. Some providers listed above are based in the United States. Where data reaches them, the transfer is protected by safeguards recognised under UK law, such as the UK International Data Transfer Addendum or the UK Extension to the EU to US Data Privacy Framework.
7. How long we keep it
- Your account, profile and CVs: until you delete them or your account. Deleting your account removes your profile, CVs, files, photos and connected sign-ins straight away, including copies held by our file storage provider.
- Database backups: deleted data can remain in encrypted backups for a short time until they are replaced, usually within a few days.
- Visit counts: 13 months, then deleted automatically.
- Sessions and sign-in records: until they expire, usually within hours.
- Old handles: 30 days after you change your handle, so nobody else can take it and pose as you.
- Reports: until they have been dealt with and for as long as needed to handle repeat abuse.
- Error reports: as set by our error tracking provider, usually 30 to 90 days.
8. Your rights
Under UK GDPR you have the right to:
- access your data: download everything from Settings, then Your data;
- correct it: edit your profile and CVs at any time;
- erase it: delete a CV or your whole account from your settings;
- take it elsewhere: export CVs as JSON Resume or your whole account as JSON;
- object to or ask us to restrict how we use it, including anything based on legitimate interests.
Your right to object
You can object at any time to our use of your data that relies on legitimate interests, such as visit counting or abuse prevention. Contact us and we will stop unless we can show a compelling reason to continue. You can also stop visit counting on your own CVs at any time by making them private.
To use a right that the settings do not cover, contact us. We will reply within one month.
9. How we protect it
Everything travels over encrypted connections. Passwords are hashed. Sessions and two-factor secrets are encrypted. Private files can only be opened after a permission check. We support passkeys and two-factor authentication, refuse passwords found in known breaches and limit repeated attempts. No system is perfectly secure, so please use a strong, unique password or a passkey. To report a security problem, see our security contact.
10. Children
Vitafolio is for people aged 16 and over. If you believe a younger person has created an account, contact us and we will remove it.
11. Changes to this policy
If we change how we use your data, we will update this page and its date. For significant changes we will tell account holders by email before they take effect.
12. Contact and complaints
Questions about your data go to contact@isaacadjei.me or the contact page. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put things right first.