Official document

Privacy Policy

This service processes CVs, and a CV is one of the most personal documents a person owns. This page explains what we collect, where it goes, and how long we keep it.

Effective 5 September 2026. The version published on this page is the one that applies.

Portalio operates in Indonesia and its binding legal texts are written in Indonesian. This English page is a faithful translation, provided so that reviewers and non Indonesian speaking users can read the same commitments. Where the two texts differ, the Indonesian version at portalio.id/privasi governs.

1.Who is responsible

The data controller for this service is the operator of Portalio, whose identity and full address are published on the Contact page.

For questions, access requests, or objections to the processing of your personal data, write to [email protected].

2.What we collect

Account data. Email address, password in one way hashed form, active plan, verification status, and last activity time. The original password is never stored and cannot be read by us.

Data from the account you sign in with. If you sign in through Google or LinkedIn, the provider gives us your stable identifier at their end, your email address along with its verification status, your display name, and for Google the URL of your profile picture. Your password for that account never passes through us, and we cannot read anything there beyond the four items just listed.

Integration permissions and tokens. If you connect LinkedIn so that Feeds posts can also be published there, we store its authorization token in sealed form, along with your LinkedIn profile identifier and display name. Details in section 4.

Portfolio and Feeds content. Everything you write or upload for display: name, summary, history, skills, links, supporting files, and the title, body, and image of each Feeds post.

CV files. The PDF you upload for automatic parsing. The file is kept in your account’s CV library so you can reuse it without uploading again, and it is stored encrypted. Details in section 3.

Payment data. Transaction history and subscription status. Card numbers and banking credentials never pass through our systems, all of that is handled by the payment provider.

Technical logs. IP address and access time are recorded at the server layer for security and abuse prevention.

3.How CVs are handled

CVs get different handling because their contents are the most sensitive. The flow:

  • The PDF is received and fingerprinted so the same file is not processed twice. That fingerprint is computed with a secret key of ours, so it cannot be recomputed from outside to test whether a given file exists here.
  • Text is extracted from the PDF. For scanned PDFs, text recognition runs on our own infrastructure rather than being sent to a third party OCR service.
  • That text is sent to a language model provider to be mapped into structured data.
  • The result becomes a draft portfolio of yours. The raw extracted text is discarded as soon as the mapping is done.
  • The PDF itself is kept in your account's CV library, encrypted, so you can reuse it for another portfolio without parsing it again.

About that encryption, plainly. Each file is sealed with its own key, and that key is wrapped again by a master key that is not stored alongside the database. What this protects against is a copy of the database falling into the wrong hands.

What it does not protect against is our own application. To turn your CV into a portfolio page the system has to open the file, so this is not end to end encryption and we will not call it that. We write it down here so you know exactly what you are getting.

What binds us is not only how it is stored but the limit on its use: your CV is used only to build your own portfolio page and whatever else you ask for from the dashboard. It is not shared, not sold, and not used to train any model. Delete it any time from the CV menu, and the file is genuinely gone from the database, not hidden.

A CV you have not used for 365 days is deleted automatically. We email you before that happens, and using or downloading it once cancels the deletion.

4.Google and LinkedIn

There are two different things here that are easy to confuse, and we keep them deliberately apart. The first is signing in through Google or LinkedIn. The second is connecting LinkedIn so that Portalio may post on your behalf. Agreeing to one never means agreeing to the other.

Signing in with Google or LinkedIn. The permission we request only covers reading your basic identity and email address. Once your profile has been read, the provider’s token is discarded immediately and is never stored. What remains is your identifier, email, and display name, used to recognise your account when you sign in again. An email address the provider has not verified is never used to match an existing account, because that is exactly where account takeover happens.

Connecting LinkedIn. This is optional, off by default, and never bundled into signing up. The permission requested on LinkedIn’s consent screen is permission to post as you, and once you grant it we store:

  • Your LinkedIn profile identifier, in the form LinkedIn uses to attribute the author of a post.
  • Your LinkedIn display name, so the Settings page can tell you which account is connected. That name is already public on your profile.
  • The authorization token, sealed the same way CV files are, never written in plain form to any column.
  • The date that token expires, so the dashboard can warn you before posting starts to fail.

This permission is one way: write, not read. Portalio cannot read your LinkedIn connections, messages, feed, job listings, or anyone else’s posts, and does not request permission to. The only thing we ever send there is a Feeds post you have published and then sent yourself, one at a time, by pressing the button.

What is sent to LinkedIn. The title and body of that post, joined into a single block of text because LinkedIn has no notion of a title, together with its image if the post has one. Nothing leaves automatically: drafts are never sent, and even a published post stays put until you tell it to go. Once there, the post is governed by LinkedIn’s privacy policy rather than by this page.

That token expires on its own. LinkedIn grants us permission that lasts 60 days and gives us no way to renew it automatically. After that the connection stops working until you connect again. We do not treat this as a shortcoming to be papered over: a permission that has to be renewed is a permission that does not quietly stay alive for years after you have forgotten granting it.

Revoking it. Open Settings, the Connected apps section, and press Disconnect. The token is deleted from the database right then, not flagged inactive. You can also revoke it from LinkedIn’s side through the Permitted Services page in your LinkedIn account settings, and that works even if you can no longer sign in to Portalio.

Disconnecting does not pull back posts already live on LinkedIn. Such a post belongs to your LinkedIn account from the moment it is published, and deleting it is done from LinkedIn.

5.Where data goes

We use third party providers to run the service. Those that touch personal data:

  • Language model provider, receives the text extracted from your CV to map it into structured data. This processing takes place on servers located outside Indonesia.
  • LinkedIn, only if you connect it. Receives the contents of Feeds posts you send yourself along with their images, and when you sign in or connect, your basic identity and email address flow from them to us. LinkedIn processes this data outside Indonesia as its own controller, under their privacy policy.
  • Google, when you use it to sign in, receives the sign-in request and sends us your basic identity and email address. If you separately allow statistics, Google Analytics receives the page route, device and browser type, approximate region, and aggregate action names such as registration, upload completed, and portfolio published. We do not send your name, email, CV contents, file name, or portfolio contents to Analytics.
  • Payment provider, receives your name, email, and transaction details to process payments and refunds.
  • Email delivery provider, receives your email address to send verification and account notices.
  • Infrastructure provider, stores the database and service files.

We do not sell personal data to anyone, and do not share it for anyone else’s marketing.

6.Portfolio visitor data

Portfolios on the Free plan are served entirely as static files. There is no analytics, no visitor logging, and no cookie set by us on those pages.

On paid plans, the portfolio owner has two separate switches, both off by default. Turning one on does not turn on the other.

Visit statistics. When enabled, each visit to that page records four things, and only four:

  • A pseudonymous visitor marker: a one-way digest of the IP address combined with that day's date, under a secret key of ours. The marker changes every day and is truncated — enough to tell two visits apart within one day, not enough to follow someone across days. The IP address itself is not stored on the visit row.
  • The host name of the referring page, for example linkedin.com. The full address is never stored, because the path of a link often carries data about people who are not even our users.
  • A device class, one of five values: phone, tablet, desktop, bot, or unknown. The original User-Agent string is discarded once classified, because a full one is enough to fingerprint someone and these five values are not.
  • The time the visit started and how long the page was read, capped at six hours.

What is not recorded: names, email addresses, what was read, and any cookie on the portfolio page. The referrer, device, and busiest-hour breakdowns are readable only by owners on the Professional plan; Standard owners see visit counts, visitor counts, and reading time alone.

Guest book. When enabled, visitors are asked to enter a name voluntarily, and what is stored is only the name and time of visit, nothing more. Visitors are always told that their name will be visible to the portfolio owner.

The page owner may choose to cover the page content with a layer until a name is sent. That layer is an invitation, not a lock: it is drawn in the browser and can be bypassed, for instance by disabling JavaScript. We state this plainly here and in the owner’s dashboard, so neither side mistakes the page for one that is truly gated.

On the Professional plan, a portfolio owner may also place a form on their page, with questions they write themselves. Because we do not decide the questions, an answer may contain anything they ask for, including sensitive data. For those forms the following applies:

  • The page owner controls it. They decide the questions and they are the only one who reads the answers. We store them on their behalf and use them for nothing else.
  • Answers are stored sealed. They are encrypted before they reach the database, the same way CV files are.
  • Kept for 180 days, then deleted automatically. That number is also printed on the form itself, before anyone presses send.
  • Beyond the answer itself, we store only the time it was sent and a short-lived keyed hash of the sender address, purely to stop flooding. The IP address itself is never stored next to the answer.
  • Deletion requests go to the page owner, not to us, and they have the button for it in their dashboard. If you cannot reach them, contact us and we will pass it on.

8.Legal basis for processing

We process your personal data on the basis of:

  • Performance of a contract, to deliver the service you signed up and paid for.
  • Your consent, for CV parsing, visitor logging, and the LinkedIn connection, all three of which you switch on yourself and can withdraw.
  • Legal compliance, to retain transaction records as required by tax and accounting rules.
  • Legitimate interest, for system security and abuse prevention.

9.How long it is kept

  • Account data is kept for as long as the account is active.
  • CV files in your library are kept while still in use, and deleted automatically after 365 days without use. You are emailed beforehand.
  • Raw text extracted from a CV is discarded as soon as the mapping is done, not stored.
  • Visit records and guest book entries are kept for as long as the portfolio they belong to exists, and are deleted along with it. The page owner may delete guest book entries sooner from their dashboard.
  • Identity data from Google or LinkedIn is kept for as long as your account exists, because that is what recognises you when you sign in again.
  • The LinkedIn token is kept until you disconnect, or until its 60 day life runs out. Pressing Disconnect deletes it right then.
  • Records of posts sent to LinkedIn, meaning their success or failure status, are deleted along with the post they belong to.
  • Answers submitted through a form on a portfolio page are kept for 180 days, then deleted automatically. The page owner may delete them sooner, and that deletion is permanent.
  • After you delete your account, the data is removed within 30 days. This grace period exists so an accidental deletion can still be undone.
  • Transaction records are kept longer where tax rules require it. So that those records stay traceable as required, an emptied account row is kept as their anchor — with no name, email address, phone number, or password.

10.Your rights

Under Law Number 27 of 2022 on Personal Data Protection, you have the right to:

  • Know what data we process about you and obtain a copy of it.
  • Correct data that is wrong.
  • Delete your personal data, including by deleting your account.
  • Withdraw consent you have given, including disconnecting LinkedIn from the Settings page.
  • Object to particular processing.
  • Lodge a complaint with the competent authority.

Some of those you can exercise yourself from the dashboard without contacting anyone. For the rest, send a request to [email protected] with the subject prefix [Data]. We reply within 14 working days at the latest.

11.Security

All traffic to this service is encrypted. Passwords are stored in one way hashed form that cannot be reversed. Integration tokens are stored sealed. Access to the production database is restricted.

No system is entirely immune. If personal data is breached in a way that risks harming you, we notify you and the competent authority within the timeframes set by regulation.

12.Children

This service is not intended for children under 17. If we learn of an account belonging to a child without valid guardian consent, we delete that account along with its data.

13.Changes to this policy

This policy can change, for instance when a new integration or a new provider touches personal data. For material changes we give notice by email at least 14 days before they take effect, and the effective date is always stated at the top of this page.

Anything here unclear? Contact us before you subscribe, not after.