How it works

What happens to your work

Wonfolio asks for your CV, your clients’ words and work that often isn’t public yet. That’s a lot to hand over, so here is exactly what the model is given, what is stored, who can see it, and what this doesn’t protect you from.

How the writing actually works

The short version: the model is never given facts — only your facts. It reorganises and writes up what you supplied. It does not research your project, fill gaps, or improve your results.

Your answers, or what was read from your CV, become a structured brief. That brief carries rules the model cannot negotiate with: never invent a metric, never invent a quote, and if the source material has no numbers, keep the outcome qualitative rather than reaching for a plausible-sounding figure.

Which raises the fair question — if it adds nothing, what is it doing? Structure and framing. It knows what a reviewer looks for in the first thirty seconds, which decisions are worth naming and which are filler, and how to open so the piece gets read at all. That is the work. The facts stay yours.

Quotes are used as given. If your client wrote in German and you’re publishing in English, the quote is translated and marked as translated rather than quietly reworded.

What is stored, and where

Database
Supabase Postgres, hosted in the EU (eu-central-1, Frankfurt).
Your case studies
Stored on your account until you delete them.
Uploaded CVs & documents
Read in memory to extract your projects, then discarded. They are never written to disk.
Uploaded images
Kept, because your case study displays them.
Generation
Sent to Anthropic's API to be written. Under their commercial terms, API content is not used to train models.
Payments
Handled entirely by Stripe. Card details never reach us.
View counts
A single number per page per day. No visitor records, no IP addresses, no cookies — which is also why there is no cookie banner.

Other people’s accounts cannot read yours. That is enforced by the database itself rather than by application code, so a bug in our code cannot leak your rows.

Who can see what

Nothing is public until you publish it. Drafts, imports and unpublished case studies are visible only to you.

When you do publish, here is what each link means:

  • A published case study and your portfolio are meant to be found — they can appear in search results.
  • Tailored links and testimonial requests are not indexed and are excluded from search engines. Their addresses are long and random, so they can’t be guessed — but anyone you send one to can open it, and so can anyone they forward it to. They are unguessable, not password-protected.
  • Testimonials are only ever published with the explicit, recorded consent of the person who wrote them, and they can be withdrawn at any time.

Limits worth knowing

The parts a security page usually leaves out. These are true today.

  • Your drafts are private from other users, not from us. They are stored in a normal database, not encrypted with a key only you hold. Someone with database access could read them. If work is under an NDA strict enough that this matters, don’t upload it.
  • Images follow the case study they belong to. An image in an unpublished draft is visible only to you; publishing makes it public, and unpublishing takes it away again. This wasn’t true until recently — images used to sit at public addresses regardless — so if you uploaded something confidential before, it is covered now.
  • Trying it without an account is protected by the link alone. A case study you write before signing up lives at an unguessable address, and so do any files you upload with it — there is no account yet to check anyone against, so holding the link is enough. It is deleted after seven days if nobody claims it, and the moment you save it to an account the old addresses stop working.
  • No formal certification. No SOC 2, no ISO 27001. Wonfolio is a small product, and saying otherwise would be the first thing worth distrusting.
  • The model can be wrong. It won’t invent your numbers, but it can misread emphasis or phrase something clumsily. Nothing is ever published automatically — you read and edit every word first.

Staying in control

  • Edit or delete any case study at any time.
  • Unpublish a case study or your whole portfolio and the links stop working immediately.
  • Export everything as plain text; nothing is locked in.
  • Anonymise a client so their name never appears anywhere in the output.

Delete your account whenever you like, from the Portfolio page. It removes every case study, your portfolio, testimonials your clients sent, and every image — immediately and for good. Any subscription is cancelled as part of it, so you aren’t billed again.

Language

Output is English only for now. Your source material can be in any language — a German testimonial will be translated and marked as such.

More output languages are coming. We’d rather do one language properly than several passably, so they arrive when the writing in them is as good as the English.

The formal, legal version lives in the privacy policy. If something here is unclear or looks wrong, tell us — this page is meant to be checkable, not reassuring.