Privacy Policy
Easy Studio ("Openfolio") takes your privacy seriously and complies with applicable data protection law, including Korea's Personal Information Protection Act. This policy explains what personal data Openfolio processes and why.
1. Personal data we process
When you sign up, we collect your email address and the identifying information from the GitHub/Google account you sign in with, via Supabase Auth. Beyond that, we only collect what you type in yourself: your name, bio text, project descriptions, website/GitHub/LinkedIn links, and profile/project images. If you enter a contact email on a digital business card and set that card to Public or Unlisted, that email is included too. If you contact us, we collect the email address and message you send. In addition, the hosting infrastructure that serves Openfolio (Vercel) processes connection information — such as IP address and request headers — that's an inherent part of handling any web request.
2. Why we process it
We process personal data to authenticate sign-ups and logins, to provide the portfolio/project publishing service, and to respond to inquiries and check for misuse. We do not use it for any purpose beyond these.
3. What becomes public
Basic profile information (name, headline, bio, profile image, website/GitHub/LinkedIn links, availability for work, etc.) is published on your /@handle page as soon as you create an account — there's no separate step to make your profile public. Unless a profile has been hidden by an administrator or its account deleted, there's no setting that makes the profile itself private. Each project, however, is something you choose the visibility of yourself: Public, Unlisted, Private, or Draft. A Public project appears in your project list and may be indexed by search engines. An Unlisted project is visible only to someone with the exact link — it doesn't appear in your list and isn't indexed by search engines. Private and Draft projects are never exposed on any public page. Digital business cards work similarly, with Public, Unlisted, or Draft chosen by you — Public may be indexed by search engines, Unlisted is reachable only via the exact link and isn't indexed, and Draft is never published. A contact email is only exposed through a business card if you type it in yourself and set that card to Public or Unlisted — it's separate from your sign-up email and must be entered per card. The email address and account identifiers you used to sign up are never made public, under any circumstance.
4. Retention period
We keep your account information until you close your account. A self-service account-deletion flow is still being built — if you'd like your account deleted in the meantime, contact us at the privacy address below and we'll process it after verifying your identity. The email and message you send us are deleted within a reasonable period after we finish handling it.
5. Sharing with third parties
Openfolio does not share your personal data with third parties, except where required by law or where you've separately consented.
6. Processors
We use Supabase, Inc. to process authentication, database, and file storage, and Vercel Inc. for web hosting, CDN, and server runtime. The primary data region for Openfolio's Supabase project is Seoul, South Korea. This is a fact about the primary data region only — it does not mean that Supabase's authentication/email processing, its subprocessors, or Vercel's hosting infrastructure never process data outside Korea. Vercel states that its processing infrastructure is located primarily in the United States, and data may also be processed in other locations where Vercel or its subprocessors operate. The exact processor-contract terms that apply to our use of Vercel — which can depend on our plan — are still being confirmed, and we'll update this document once that's settled. We don't use processors for any purpose beyond operating the service.
7. How to request deletion
To have the personal data tied to your account deleted, contact us at the privacy address below. We'll verify your identity and delete the relevant data. An automated self-service deletion flow is on the way — we'll announce it here as soon as it ships.
privacy@openfolio.me8. Your rights
You may request access to, correction of, deletion of, or a halt to processing of your personal data at any time. Contact us at the privacy address below and we'll act without delay.
privacy@openfolio.me9. How we keep it safe
Openfolio applies Supabase's Row Level Security to restrict anonymous visitors and other ordinary users to only what authorization rules allow — their own data, or data that's been made public. Some server-side operations that are necessary to run the service, such as account deletion and data-retention cleanup, run with narrowly scoped privileges outside this restriction, and each of those paths is separately validated and limited. We don't offer end-to-end encryption, and this doesn't mean Openfolio's backend can never access data.
10. Privacy officer
Jemin Park, CEO of Easy Studio, serves as the privacy officer responsible for personal data handling.
11. Privacy contact
For questions about how we handle personal data, or to request access, correction, or deletion, email us below.
privacy@openfolio.me12. Effective date
This Privacy Policy takes effect on September 28, 2026.