Privacy Policy

Effective September 10, 2026

Short version: we collect what it takes to run the builder, store your saved work, and take payment — nothing else, and nothing sold.

What we collect

Building and downloading, with no account — none of this. The builder runs in your browser; nothing you make is uploaded anywhere until you choose to pay, save, or share a model.

Account info — if you sign in, your email address and account ID, handled by our authentication provider, Clerk.

Portfolio content — with a free account, the optimized files and project data you save, stored via our database provider, Supabase.

Payment info — handled entirely by Stripe. We receive confirmation that a payment succeeded and basic billing details; we never see or store your card number.

Why we collect it

To run the service: authenticate you, keep your saved portfolio between visits, process payment for downloads and Pro, and answer support requests. That’s the whole list — no analytics profile is built from it and it isn’t used for advertising.

Who we share it with

Three processors, each doing one job: Clerk (sign-in), Supabase (storage), and Stripe (payment). Each holds only what its job requires. We don’t sell data or share it with anyone else.

How long we keep it

For as long as your account exists. Closing your account from the dashboard is immediate and, in order: cancels any subscription, deletes your portfolios and stored files, and deletes your sign-in identity. What remains afterward is the minimum financial record Stripe and accounting law require us to keep, with you removed from it wherever that record allows.

Prefer to keep nothing here at all? Export a .xrfolio save file instead of creating an account — it never touches our servers, and it’s yours to keep.

The one exception to “as long as your account exists”: a free account whose portfolio hasn’t been opened or edited in 12 months. We’ll email you before doing anything, and only delete the stored files — not the account itself — if we don’t hear back within 30 days after that. A portfolio with a model shared to the public catalogue is kept as long as that listing stands, and an active Pro subscription is never affected by this.

Cookies

Only what sign-in needs: a session cookie set by Clerk. No advertising or tracking cookies.

Your choices

See or delete your data any time from the dashboard, or email cperos@xrtech.dev and we’ll handle it directly.

Children

PortfolioMaker isn’t directed at children under 16, and we don’t knowingly collect their data.

Changes

If this changes in a way that matters, we’ll update the date at the top of this page.

Contact

cperos@xrtech.dev