Privacy Policy
Last updated: October 1, 2026
Your privacy matters to us. This policy clearly explains which data we collect, what we use it for, and the rights you have over it.
1. Who we are
Modullum is a platform that lets you create and publish a professional portfolio without writing any code. By using our services, you entrust us with your data, and we commit to handling it with transparency and security.
2. Data we collect
We only collect the data necessary for the service to operate:
- Account data:name, email address, avatar and profile information provided at registration or via GitHub/Google.
- Portfolio content:the content you create and publish (sections, projects, experience, contacts, etc.).
- Usage data:visits to your public page, recorded with an anonymous identifier generated in the browser (without associating your IP address), in order to show visit and unique visitor statistics. We also record the country of each visit — the country code only, provided by our hosting infrastructure, with no city, region or address — so you can see which countries visit your portfolio. The Free plan shows visits from the last 24 hours and the last 7 days; the 30 and 90 day windows are only available on the Pro plan.
- Billing data:only for Pro plan users — name, email address and payment information, handled by our billing entity (see section 5).
- Technical data:IP address and session cookies, necessary for authentication and security.
We do not collect sensitive personal data (health, political affiliation, religion, etc.) and we do not sell your data to third parties.
3. How we use your data
The data we collect is used exclusively for:
- Creating and managing your account and authentication;
- Providing, maintaining and improving the portfolio creation service;
- Ensuring security and preventing abusive use;
- Processing Pro plan subscriptions and payments;
- Applying the plan you have subscribed to (Modullum branding removal, content limits, statistics and Pro features);
- Generating sitemaps and traffic statistics.
4. Storage and security
Your data is stored on secure servers with encryption in transit and at rest. We apply restricted access controls and regularly review our security practices.
No method of transmission or storage is 100% secure. Although we strive to protect your data, we cannot guarantee absolute security. We use session token authentication and abuse protection (rate limiting) to mitigate risks.
5. Data sharing
We do not share your personal data with third parties, except:
- Infrastructure providers(such as the hosting service and the data platform that stores it) that process the data on our behalf and are bound by confidentiality obligations;
- Cloudflare (CDN, DDoS and anti-bot), which delivers the service and protects against abuse. The anti-bot verification challenge (Turnstile) used on the authentication forms may temporarily process your IP address and device technical identifiers, solely to distinguish humans from automated programs;
- Payment processor (Paddle), acting as the billing entity (Merchant of Record) for Pro plans. Paddle handles payment data (name, email and card details) securely; Modullum does not store credit card data;
- Legal obligations, when required by law or by court order.
Your portfolio content is public by the nature of the service, since it is published at yourusername.modullum.comaddress.
6. Cookies and authentication
We use strictly necessary cookies to keep you signed in and remember your theme preference. We do not use advertising cookies or third-party tracking.
Cloudflare's anti-bot challenge (Turnstile) and content delivery network (CDN) may set cookies or temporary identifiers strictly necessary for technical operation and abuse protection. These are not used for advertising purposes.
External traffic reporting (third-party analytics) is only loaded if you consent via the “Accept” button shown in the cookie banner. If you choose “Reject” (or have not decided yet), those services are not activated and only the essential features (session, theme and anti-bot protection) remain operational. Closing the banner without choosing has the same effect: non-essential services remain disabled. Your choice is stored locally on your device and can be changed at any time through the “Cookie preferences” link in the site footer.
7. Retention period
We keep your data for as long as your account is active. You can delete your account and its portfolio at any time; the data is then removed from our systems. Billing data associated with payments made may be retained by Paddle for the period required by legal and tax obligations, in accordance with Paddle's privacy policy.
8. Your rights
In accordance with the GDPR, you have the right to:
- Request access to the data we hold about you;
- Ask for rectification of incorrect or outdated data;
- Ask for the deletion of your data (“right to be forgotten”);
- Restrict or object to certain processing activities;
- Port your data to another service.
To exercise these rights, contact us at[email protected]. We will respond within 30 days.
9. Privacy of minors
The service is not intended for anyone under 16, and we do not knowingly collect data from minors. If you become aware that a minor has given us data, contact us so we can delete it.
10. Changes to this policy
We may update this policy from time to time. Whenever we do, the “Last updated” date at the top of this page will be revised. Changes take effect once published, and where they are materially relevant we will be transparent about the change.
11. Contact
Questions about this policy or about how we handle your data? Email[email protected].