Privacy Policy
What Publish Your Profile collects—and why.
Effective August 25, 2026 · Version 2026-08-25
This policy explains how Publish Your Profile, as the configured data controller for this deployment of Publish Your Profile, handles information when you create, manage, publish, or visit a card.
1. Account and authentication information
The application stores account identifiers such as name, email, verification state, account status, role, consent version, and timestamps. You may add an optional unverified contact phone to your private account details without an OTP; for an email-first account, that contact does not enable phone sign-in or password recovery. Previously established accounts may also retain a verified phone identity for legacy sign-in and recovery. Password credentials are hashed by the authentication service. If you choose Google or enterprise sign-in, the provider first shares the identity needed to authenticate you, including name, verified email, provider account identifier, and a profile image if provided. The provider link, encrypted authentication tokens, restricted session, and request metadata also exist before the date-of-birth step. The service creates a restricted pending account with no product access until you confirm age eligibility and finish setup. A fresh ineligible pending account, provider link, and session are deleted from active systems immediately; an abandoned pending account expires after 24 hours and is removed on restart or during scheduled maintenance. Unexpired backup copies follow the rolling backup period in the retention schedule, and the identity provider remains responsible for its own records.
For email signup, the browser first sends a separate request containing the date of birth and credential signup type only. It sends the name, email address, password, and terms choice and delivers an email OTP only after that check succeeds. A new administrator-created account also requires email OTP. The administrator may submit the date-of-birth check or record an adult-age attestation, but cannot waive email verification.
To prevent one successful eligibility check from being replayed, the service temporarily stores a one-way hash of a random security nonce, status, and timestamps for email signup. This anti-replay receipt contains no date of birth, name, email address, phone number, or provider account identifier and is removed after it is no longer needed, normally within one day.
2. Profiles, Web Profiles, links, and media
The service stores the details you choose to enter, such as names, images, biography, location, organization, role, contact details, links, appearance choices, and Web Profile content. Managed profile images are stored in private object storage and delivered through access-controlled application routes. Designated contact fields are encrypted at the application layer.
3. Published information is public
Published cards and Web Profiles are intentionally public. Anyone with the URL may see, follow, download, or copy enabled details. Unpublishing stops this deployment from serving the item but cannot remove screenshots, saved contacts, search caches, or copies made elsewhere. Draft fields remain nonpublic unless another feature specifically discloses them.
4. Connections, messages, and calls
Connection requests store the participating profile and account identifiers, request state, preferences such as mute or block, and timestamps. Accepted connections can exchange messages encrypted at rest. Calls use encrypted signaling and retain call lifecycle metadata such as participants, audio or video type, status, connection time, end time, and duration. The service does not intentionally record or store call audio or video.
5. Visits, analytics, cookies, and device data
The service records first-party profile visits, shares, contact saves, link clicks, and event time so an owner can understand engagement. Profile analytics do not retain a visitor referrer, user-agent, or fingerprint. Authentication sessions may retain IP address and user-agent information for account security. Essential cookies and session storage are described in the Cookie Policy.
6. Safety, moderation, support, and audit information
Reports can include the category, relevant account or content, encrypted details, reporter contact when supplied, review notes, decisions, and appeals. The service also records bounded audit events and operational logs to enforce access controls, investigate abuse, diagnose failures, and document sensitive account actions. Support correspondence is processed to answer the request and protect the service.
7. Payments and entitlements
Stripe receives the account and transaction information necessary to process checkout, recurring billing, refunds, and fraud prevention. This service stores Stripe customer, checkout, payment, subscription, and invoice references together with amounts, status, revenue treatment, and entitlement. It does not store complete card numbers or card security codes. Administrative credits and offline arrangements may be recorded separately from user-paid online orders.
8. Why information is used
Information is used to create and secure accounts, provide requested profiles and communications, publish selected content, measure engagement, process purchases, prevent fraud and abuse, moderate content, answer support requests, maintain and improve the service, enforce agreements, and comply with legal obligations. We do not sell account or profile information or use it for cross-context behavioral advertising in the current service configuration.
9. Providers and other disclosures
Information is shared only as needed with configured hosting, storage, authentication, notification, payment, communications, monitoring, and support providers; with a customer acting as controller under the Data Processing Terms; at your direction when publishing or following a link; during a lawful business transfer; or when reasonably necessary to protect rights, safety, and the service or comply with law.
10. Security
Sensitive card contact fields are encrypted at the application layer. TLS, access controls, rate limits, secure cookies, and security headers provide additional safeguards. Authentication-provider tokens and connection messages are encrypted at rest. Access to managed media and administrative functions is checked by the application. No system can promise absolute security.
11. Your choices and requests
Signed-in controls allow you to correct content, unpublish or delete an individual profile, export eligible account data, deactivate the account, or request permanent account deletion. Depending on where you live, you may also have rights to know, access, correct, delete, or appeal a privacy-request decision. We verify requests and may withhold information that would expose another person's private safety action or weaken security.
12. Retention and deletion
Account and content records remain while active or deactivated unless deletion is requested. Sessions normally expire after 30 days. Analytics, communications, safety, audit, billing, support, provider, lifecycle, and backup records follow the specific periods and exceptions in the Data Retention & Deletion Schedule. Permanent deletion removes eligible records from active application use, but restricted legal-hold, safety, accounting, processor, and unexpired backup copies can remain for their stated period. Verified requests may also be sent to support@publishyourprofile.com.
13. Children
The service is restricted to adults aged 18 and over, as described in the Children & Minimum Age Policy. A person under 18 may not create or use an account. Self-service email signup checks the date of birth before the server uses or stores the other submitted account details. For an administrator-created account, the administrator must either complete the same eligibility check or attest that the customer is at least 18. Google and enterprise signup first creates a restricted pending identity and then checks the date of birth before allowing product access; a fresh ineligible identity is deleted. The date itself is not retained in the account, cookies, audit metadata, analytics, or application logs. A successful account retains only the applicable adult-eligibility result, the confirmation time, and limited evidence of the applicable policy and setup method. A short-lived, non-identifying credential-signup anti-replay receipt may remain for up to one day, and a separate browser-only denial marker may last 24 hours after an unsuccessful attempt, as described in the Cookie Policy.
14. Questions and related policies
The configured data controller is Publish Your Profile. Contact: support@publishyourprofile.com. Address: SYSKASA LLC, 2501 Chatham Road #6679, Springfield, IL 62704, United States. See the Cookie Policy and Data Processing Terms.
