Privacy Policy
Last updated: May 15, 2026
This Privacy Policy explains how CraftedBio (“we,” “us”) collects, uses, and shares information when you use our service. We’ve written it to be plain-English and short — if anything is unclear, email us at hello@craftedbio.com.
1. What we collect
Account information
When you sign up we collect your email address and, if you sign in with Google, the name and profile picture associated with your Google account. We use this to create and personalize your account.
Your bio content
Anything you add to your bio — work history, education, projects, skills, hobbies, photos, video, audio, and text — is stored by us so we can render your public bio and let you edit it. This is the data you create using the service.
Résumé uploads
If you import a résumé we process the file with AI to extract its contents and pre-fill your bio sections. The raw file is stored in our media storage so you can reuse or replace it later.
Usage and technical data
Our servers automatically receive standard request data: IP address, browser type, pages visited, and timestamps. We use this for security, debugging, and keeping the service running.
2. How we use your information
- To provide, maintain, and improve the service.
- To render your public bio at the URL you choose.
- To process your content with AI when you ask us to (e.g., “Polish my bio,” “Import résumé”).
- To send transactional emails (welcome, account notifications, password reset).
- To prevent abuse, fraud, and security incidents.
- To comply with applicable law.
We do not sell your personal information. We do not use it to train public AI models. We do not send marketing emails without your opt-in.
3. Who we share data with
We share limited data with a small set of vendors who help us run the service. Each handles data on our behalf:
- Supabase— our database, authentication, and file storage provider. Hosts all your bio content. supabase.com/privacy
- Google (Gemini API)— processes text you submit to AI features. Per Google’s paid API terms, content sent via the API is not used to train Google’s public models. ai.google.dev/gemini-api/terms
- Resend— sends transactional emails on our behalf. resend.com/legal/privacy-policy
We may also share data when required by law, to enforce our Terms, or to protect the rights and safety of CraftedBio, our users, or the public. If we’re ever acquired or merged with another company, your data may transfer to the successor entity under this Privacy Policy.
4. Your public bio
CraftedBio publishes your bio at a public URL (e.g., craftedbio.com/yourname). Anything in a section you’ve marked visible is accessible to anyone with the link and can be indexed by search engines. Don’t add anything to a visible section you wouldn’t want strangers to read. You can hide sections or delete content from the dashboard at any time.
5. Cookies and similar technologies
We use a single category of cookies on CraftedBio: strictly-necessary authentication cookiesset by Supabase so you can stay signed in. Without them, the app can’t remember who you are between page loads. We don’t use marketing, advertising, or analytics cookies. We don’t embed third-party trackers (no Google Analytics, no Facebook Pixel, no LinkedIn Insight, etc.).
Because our only cookies are strictly necessary for the service to function, no cookie consent banner is required under EU/UK e-privacy rules.
6. Visitor analytics on public bios
When someone visits a public bio at craftedbio.com/<username>, we record an aggregate visit so the bio’s owner can see how their page is performing. This data is shown only to the bio’s owner.
What we record per visit:
- Country derived from the IP address (never city, never the raw IP).
- Device category (mobile / tablet / desktop) derived from the user-agent string.
- Referring source bucket (e.g. LinkedIn, email, search) derived from the Referer header. The exact URL is discarded.
- Which bio sections were on screen long enough to read, so the owner can see which parts hold attention.
How we identify visits without identifying you:
- No cookies, no fingerprinting. We don’t set anything in the visitor’s browser and we don’t use canvas, WebGL, or font tricks to track identity.
- One-way visit hash. To de-duplicate the same person within a single day, we compute a SHA-256 of (IP + user-agent + UTC day + a server-side secret). The hash rotates every UTC midnight, so cross-day tracking of the same person is impossible. We never store the raw IP or user-agent.
- DNT and Global Privacy Control honored. If your browser sends
DNT: 1orSec-GPC: 1, we don’t record the visit at all. - Bot traffic excluded — we drop visits whose user-agent matches known crawlers.
Raw events (used for the “recent visits” feed in the owner’s dashboard) are kept for 90 days and then deleted. Daily aggregates (used for “visits per day” charts) are kept indefinitely so the owner has a long-term view. Neither is shared with third parties.
7. Your rights
You can, at any time:
- Access — see your data through the dashboard, or email us for a copy.
- Correct — edit your bio content directly, or email us for fields you can’t change yourself.
- Delete — remove individual content from the dashboard, or email us to delete your entire account.
- Export — email us and we’ll send you your data in a machine-readable format.
If you’re in the European Economic Area, the UK, or California, you have additional rights under GDPR/UK GDPR or the CCPA, including the right to object to processing, the right to data portability, and the right to lodge a complaint with your local data-protection authority. Email hello@craftedbio.comto exercise any of these rights and we’ll respond within 30 days.
8. Data retention
We keep your account and bio data for as long as your account is active. When you delete your account, we remove your content within 30 days. Some records (e.g., billing history once we have it, security logs) may be retained longer where required by law or for legitimate business purposes.
9. Security
We use industry-standard measures to protect your data, including encryption in transit (HTTPS), row-level security in our database, and access controls on internal systems. No service is 100% secure — if you spot a vulnerability, please report it to hello@craftedbio.com rather than disclosing it publicly.
10. Children
CraftedBio isn’t directed to children under 13 (or under 16 in the EEA). We don’t knowingly collect personal information from children. If you believe a child has signed up, contact us and we’ll delete the account.
11. International transfers
Our service is operated from the United States. If you access it from outside the US, your information may be transferred to and processed in the US. By using CraftedBio, you consent to this transfer.
12. Changes to this policy
We may update this Privacy Policy as the service evolves. Material changes will be announced by email or via an in-app notice before they take effect. The “Last updated” date at the top of this page always reflects the most recent revision.
13. Contact
Questions about this Privacy Policy or your data? Email us at hello@craftedbio.com. We usually reply within two business days, and within one for deletion or privacy requests.