Privacy Policy

Last updated October 5, 2026

The short version

stackinfolio collects the profile info you sign in with, whatever you choose to add to your page, what you do on the site (hearts, follows, replies, visits while signed in), and a lightweight anonymous cookie for visitors who aren't signed in. Some pages show ads from Google, which uses its own cookies. We don't sell your data. You can edit or delete everything at any time from your dashboard.

Information we collect

When you sign in with GitHub, we receive:

  • Your GitHub username, name, and avatar image
  • Your public email address, if your GitHub account exposes one
  • A sign-in token from GitHub, which we store and use only to read public information on your behalf: your public repositories (for Import from GitHub and the Proven badge), their READMEs, and your contribution chart. It can't change anything on GitHub. You can revoke it any time in GitHub's settings under Applications.

When you use stackinfolio, we store whatever you choose to add to your profile:

  • Bio, headline, location, and links you add
  • Your tech stack tags
  • Projects you add, including their status, tags, icon, photos and README
  • Journey posts you write, and any images you attach to them
  • Your experience entries, availability (such as “open to work”), and status line

And what you do on stackinfolio:

  • Replies you post, and the images you attach to them
  • Hearts you give, people you follow, and people you block from replying to your posts
  • Feedback you send and your votes on it. Feedback and its status are shown publicly on the feedback board, with your username unless you sent it signed out; a thank-you we reply to may appear on the appreciation wall on /feedback and the home page
  • Reports you file about replies or reviews, which only we see
  • Event registrations, entries and votes
  • Your XP, level, quests, streak and achievements. Your level and unlocked achievements are shown on your public profile
  • When you're signed in, which profiles and projects you've opened (once per day each). This counts toward your achievements and quests and the owner's view count; owners see totals, never who viewed them

We also set an anonymous, random cookie (sf_vid) on visitors who aren't signed in. It's used to avoid double-counting a profile or project view from the same visitor on the same day, to count a signed-out visitor's feedback vote once, and, with signed-in members' account ids, for the rounded “people online” count (an open, active tab checks in every couple of minutes, and drops out after a few minutes idle). It isn't linked to any other identity, and a profile owner's own views of their own page are never counted.

If you ask to sponsor stackinfolio, we store the contact details you send (name, email, optional phone number and website), your budget range, and your message so we can reply. When you pay — as a sponsor, to feature a project, or as a developer backer — PayMongo processes the payment; we send it your email address and what you're paying for so it can take the payment and email your receipt. We keep a record of what was paid, when, the amount, and when you agreed to our Terms (and which version), but never your card, e-wallet, or bank details. Sponsor and featured cards count how many times they were shown and clicked, as totals per day only — never who saw or clicked them. So one person isn't counted twice in a day, your IP address is held for that day and then deleted.

When you open a stackinfolio link someone shared, we note that a visitor arrived through it so the sharer can earn XP, using a scrambled id that can't be turned back into you. The sharer sees only the XP, never who visited.

Cookies

We set a handful of first-party cookies, all of them to make the site work rather than to follow you around. None of them track you across other websites, which is why you won't see an “accept cookies” banner here.

  • Sign-in session — keeps you signed in after you log in with GitHub. Strictly necessary; removed when you sign out.
  • sf_vid — a random id for visitors who aren't signed in, so the same person reloading a profile or project isn't counted as a new view that day, a feedback vote counts once, and the “people online” count doesn't count one person twice. Lasts a year. Not linked to a name, email or any other identity.
  • sf_discover_seen, sf_discover_seen_projects — remember which profiles and projects Discover's “Next” button has already shown you, so it doesn't repeat them. Short-lived.
  • Browser storage — kept on your device, not in cookies, and never sent to us: your light or dark theme; when you last visited Discover (for the “New” tags); which Discover tab and leaderboard you had open; and whether you closed the dashboard's getting-started, backer and feedback cards.

Our usage analytics are cookie-less. The one exception is advertising: on pages that show an ad, Google sets its own cookies (see Advertising below). Where the law requires consent for those — the EU, UK and Switzerland — Google shows its own accept/reject choice before any ad cookie is set; elsewhere you can opt out through the links in the Advertising section. Developer backers see no ads and no Google cookies while signed in.

You can clear or block any of these in your browser. Blocking the sign-in cookie means you can't stay signed in; blocking the others only affects view counting and Discover's memory of what you've seen.

How we use it

To run the service: displaying your public profile, tracking project hearts and view counts, letting you edit and manage your content, notifying you about replies, follows and hearts, running XP, quests, achievements, leaderboards and events, checking whether you're a developer backer (backers don't see ads), and keeping the platform working reliably (including basic rate limiting to prevent abuse). The location you type is turned into a country for the anonymous developer map and totals.

We don't use your profile data for advertising, and we don't sell it to anyone.

API and badges

What's on your public profile — name, headline, bio, location, links, tech stack, projects and public Journey posts — can also be read as data through our API and README badges. Like your profile page, anyone who knows your username can see it. Your email, follower count, views and XP are never included, and neither are Journey posts that aren't public.

Your own stats are only available with your personal API key, which you create in Settings. We store only a scrambled (hashed) copy of it, so we can't show it to you again. You can replace or delete it any time. Changes to your profile, or deleting your account, reach the API within an hour; we can't recall copies that others have already saved.

Advertising

Some pages show ads served by Google AdSense, marked “Advertisement”. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this and other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on those visits.

You can opt out of personalized advertising in Google's Ads Settings, or opt out of some third-party vendors' cookies at aboutads.info. See how Google uses information from sites that use its services. We don't share your stackinfolio profile or account data with Google for ads. Developer backers don't see these ads, and Google's ad script isn't loaded for them, while they're signed in.

The “From euphydev” section includes affiliate links, labeled “Affiliate”, to stores such as Shopee and TikTok Shop. When you follow one, that store may set its own cookies to record that you came from us, so a commission can be paid. We don't send them any of your stackinfolio data.

Service providers

We use a small number of trusted service providers to operate stackinfolio, each of whom processes data only as needed to provide their specific service:

  • Authentication — to let you sign in securely via GitHub
  • Hosting and infrastructure — to run the application and store uploaded images
  • Database services — to store your profile and content
  • Payments — PayMongo, to process sponsorship and developer purchases (it receives your email address and the amount)
  • Analytics — privacy-friendly, cookie-less aggregate usage analytics
  • Location lookup — Mapbox, which receives only the location text you type on your profile (never your name or account), to find its country
  • GitHub — asked, with your sign-in token, for your public repositories, READMEs and contribution chart
  • Advertising — Google AdSense, which serves the ads marked “Advertisement” (see Advertising above)
  • Security and rate limiting — to keep the platform available and prevent abuse
  • Error monitoring — to help us detect and fix technical issues, which may involve technical context like IP address and browser/OS when something breaks

Apart from Google's advertising cookies described above, these providers act on our behalf and don't use your data for their own purposes.

Where your data is stored

Your data is stored and processed in the United States by our hosting and database providers. Public pages may also be cached on servers closer to you so they load faster. Wherever it's stored, we remain responsible for protecting it under the Philippine Data Privacy Act.

Your choices

Everything on your profile is editable from your dashboard at any time. You can permanently delete your account — and everything tied to it — from Account Settings. Deletion is immediate and can't be undone. Records of payments are the one exception: we keep them, no longer linked to your account, for as long as accounting and tax rules require.

Your rights

Under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), you have the right to be informed about, access, correct, and ask us to delete or stop using your personal data, to get a copy of it, and to file a complaint with the National Privacy Commission. Most of this you can do yourself from your dashboard; for anything else, email [email protected] and we'll respond within 15 days.

Children

stackinfolio isn't directed at, or knowingly used by, anyone under 13. If you're 13 to 17, use stackinfolio only with a parent's or guardian's permission. If you believe a child under 13 has an account, email us and we'll delete it.

Changes to this policy

If this policy changes in a meaningful way, we'll update the date at the top of this page.

Contact

Questions about this policy or your data — reach us at [email protected].