Privacy policy

Last updated 10 October 2026

Neverstale builds a portfolio from the accounts you connect and keeps it up to date. This page explains what that involves for your data.

What we collect

  • Account: your email address and name, held with our sign-in provider, plus the username you claim.
  • Connected sources: public data from the accounts you connect (for example your GitHub profile and public repositories, Dribbble shots, Instagram posts, or an RSS feed you provide). We read it so we can build and update your site.
  • Text you give us: anything you paste (such as LinkedIn text or a bio), and updates you email to your Neverstale address.
  • Your site content: the text, images and links on your portfolio, and its version history.
  • Billing: handled by Stripe. We store your plan and Stripe customer and subscription identifiers, never your card number.
  • Product emails: we record that a digest was sent and which actions you took from it.

Connected accounts

We ask for read-only access and only the scopes we need. Access tokens are encrypted at rest, are never returned to your browser and are never written to logs. Only public source data is published by default. You can disconnect a source at any time, which stops further fetching; content already on your site stays until you remove it.

How AI is used

We send content from your connected sources and anything you paste to an AI provider (OpenAI) to classify changes and draft the text for your site. That content is treated as untrusted input, and drafts must be grounded in your source data. We do not use your content to train our own models, and we use the provider’s API under terms that do not permit them to train on API data by default.

Visitors to your site

Published portfolios set no cookies and need no consent banner. Their built-in analytics is cookieless and stores aggregates only: daily counts of visitors, views, referrers, countries and which outbound links were clicked. IP addresses are not stored. Unique visitors are counted with a hash that rotates daily, so a person cannot be followed from one day to the next. Raw events are deleted within 24 hours; only the daily totals remain.

Who processes your data

We use these providers to run Neverstale. Each only receives what it needs for its job:

  • Clerk: sign-in and account identity.
  • Microsoft Azure: hosting, database, file storage and background processing.
  • Stripe: payments and subscriptions.
  • Postmark: sending and receiving email.
  • OpenAI: drafting site text, as described above.
  • The sources you connect (GitHub, Dribbble, Instagram and others): we fetch your data from them.

We do not sell your personal information.

Keeping and deleting your data

You can delete your account from Settings. This removes your site, sources, snapshots, drafts and history, cancels any subscription and signs you out. Copies in infrastructure backups age out on the backup schedule. Billing records we are legally required to keep may be retained by Stripe.

If you downgrade, your content is never deleted. A custom domain is unbound after a 14-day grace period.

Your rights

Under the New Zealand Privacy Act 2020, and the GDPR where it applies to you, you can ask to see the personal information we hold about you, correct it, or have it deleted. Most of this you can do yourself in the dashboard. For anything else, or a complaint, email [email protected].

Security

Data is encrypted in transit. Credentials for connected sources are encrypted at rest. Email action links are signed and expire within 14 days. No system is perfectly secure, and if a breach affects you we will tell you as the law requires.

Changes and contact

We will update this page when our practices change and revise the date above. Questions: [email protected].