Privacy Policy
Last updated 13 September 2026
DevWorks is a personal, non-commercial portfolio project run by one individual developer ("the operator", "we"). It is not a company and it sells nothing. This policy explains what personal data the service processes and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The operator of DevWorks is the controller for the data described here. For any privacy question or request, contact the contact link on the operator's portfolio at /teop.
If you publish a portfolio, you decide what goes on it. You are responsible for having the right to publish any personal data about other people that you include.
2. What we process and why
Account data
When you sign in, our authentication provider handles your email address, your name and profile image if you sign in through a third-party account, and your login credentials. We store only your account identifier alongside your content.
Legal basis: performance of a contract, Art. 6(1)(b) GDPR, meaning we need it to give you an account.
Portfolio content
Everything you enter in the editor: name, title, bio, photo, projects, screenshots, links, skills, work history, GitHub username, custom domain and similar details. A published portfolio is public and may be indexed by search engines. A draft or unpublished portfolio is visible only to you. If you set a portfolio password, we store only a salted hash of it, never the password itself.
Legal basis: Art. 6(1)(b) GDPR.
Portfolio view statistics
When someone opens a published portfolio, we record the time, which portfolio it was, and the website the visitor came from, reduced to its host name (for example "linkedin.com"). We do not store IP addresses, device fingerprints or tracking cookies. To stop one visitor inflating the count, the server briefly keeps the visitor's address in memory, never on disk, and ignores repeated views from it. The owner's own visits are not counted. Portfolio owners see these numbers as totals.
Personal access links. An owner can protect a portfolio with links made for specific people, each labelled with a name the owner chooses. When someone opens the portfolio through such a link, the view is counted against that link, so the owner can see how often and when it was used. The link itself is kept only as a one-way hash. If you received a personal link and have questions about this, contact the portfolio owner, or us.
Legal basis: legitimate interests, Art. 6(1)(f) GDPR: showing portfolio owners how their page is used, with as little data as possible.
Site-wide analytics
For every page other than the admin panel, our server records a page view: the kind of page (for example "landing" or "dash"), the page's path with any numeric ids stripped, the referring website reduced to its host name, your country derived from your network connection, and a coarse device type (mobile, tablet or desktop). We do not store your IP address or full browser identification string. Instead, each view is tagged with a one-way hash built from the day, the page, your address and browser string, using a secret salt that changes every day - it cannot be reversed to an address, and the same visitor gets a different tag tomorrow. Automated traffic (search engine crawlers, monitoring tools, and similar) is filtered out and not recorded. These rows are kept for 13 months and then automatically deleted.
Legal basis: legitimate interests, Art. 6(1)(f) GDPR: understanding how the site as a whole is used, with as little data as possible.
Error reports
When something breaks, a technical error report is sent to our error-monitoring provider: the error message, stack trace, the page address, browser and operating system type. It is configured not to send IP addresses, cookies or form contents, and no session recordings are made.
Legal basis: Art. 6(1)(f) GDPR, keeping the service working and secure.
Server logs
Our hosting provider keeps short-lived request logs, including IP addresses, as any web server does, to deliver the site and defend it against abuse.
Legal basis: Art. 6(1)(f) GDPR, security of the service.
We never sell data, show ads, build marketing profiles or make automated decisions that have legal effects on you.
3. Cookies and local storage
We use only what the service needs to work, so no consent banner is required:
- Sign-in session cookies, set by our authentication provider to keep you signed in.
- Portfolio unlock cookie, set when you enter a portfolio password or open a personal link, valid for 7 days. It contains a signature, not the password or link.
- Session storage in your browser, so reloading a portfolio does not count a second view. It is cleared when you close the tab.
There are no analytics, advertising or social-media tracking cookies.
4. Service providers
We rely on the following processors. Each processes data only on our behalf and under its own data processing terms:
- Vercel: hosting, request logs and the database.
- Clerk: sign-in and account management.
- UploadThing: storage of uploaded photos and screenshots.
- Sentry: error monitoring.
If you add a GitHub username, our server fetches your public repository statistics from GitHub. No visitor data is sent to GitHub.
Some of these providers are based in the United States. Where data leaves the European Economic Area, transfers rely on the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses, as offered by each provider.
5. How long we keep data
- Account data and portfolio content: until you delete the portfolio or your account.
- Portfolio view statistics: until the portfolio they belong to is deleted.
- Site-wide analytics rows: 13 months, then automatically deleted.
- Error reports and server logs: for the provider's standard retention period, typically no more than 90 days.
Deleting your account from Account settings removes your portfolios, projects, uploaded files, statistics and login immediately. Copies may persist in provider backups for a short time before they are overwritten.
6. Your rights
Under the GDPR you have the right to:
- Access your data, and portability: download everything as JSON from Account settings.
- Rectification: edit your content at any time in the editor.
- Erasure: delete a portfolio or your whole account yourself.
- Restriction of processing and objection to processing based on legitimate interests.
- Complain to the data protection supervisory authority in the EU country where you live or work.
For anything you cannot do yourself in the app, contact the contact link on the operator's portfolio at /teop. We will answer within one month.
7. Children
DevWorks is not intended for anyone under 16. Please do not create an account if you are younger.
8. Security
Data is encrypted in transit (HTTPS), portfolio passwords are hashed, and access to your content is limited to your own account. No online service can promise perfect security, so please do not put sensitive personal data on a public portfolio.
9. Changes
If this policy changes, the date at the top will change with it. Significant changes will be announced in the app. See also the Terms of Service.