Privacy Policy
POE Portfolio
Effective: September 4, 2026
Overview and scope
This policy explains how POE Portfolio ("we," "us," or the "Service") collects, uses, shares, and retains personal data. It applies to poeportfolio.com, the POE Portfolio Twitch Extension, and the optional POE Portfolio Pricing browser extension.
We collect only what we need to provide build valuations, community appraisal features, account linking, public profiles, subscriptions, support, security, and reliability. We do not sell personal data or use it for cross-context behavioral advertising.
Data we collect
- Account data. Your email address, authentication-provider identifiers, display name, profile settings, subscription tier, and account timestamps.
- Path of Exile data. When you link Grinding Gear Games ("GGG"), we receive your POE account identity, character roster, leagues, equipped items, and an OAuth token. The token is encrypted at rest and used only to make authorized GGG API requests for your account.
- Build data. Saved gear snapshots, item details, valuation results, ranges, confidence information, pricing history, and the character or items you choose to display. If your profile is public, your profile and selected character builds are visible to anyone with the page link.
- Community appraisal data. Price or range submissions, passes, optional notes after automated redaction, related item snapshots, timestamps, reviewer-readiness evidence, and trust or credential state. Public community results are aggregated and are not displayed with an individual reviewer's email address.
- Twitch data. If a broadcaster links Twitch, we store the Twitch user ID, login, display name, selected character, selected Panel items, favorite item, and Extension configuration. Twitch online and offline events may update the channel's live state. We do not store the broadcaster's Twitch access or refresh token.
- Billing data. If you purchase Pro, Stripe processes your payment details. We receive customer and subscription identifiers, billing status, and limited transaction metadata, but not your full card number.
- Support and feedback. Messages you send us, structured feedback, and the information reasonably needed to investigate a report.
- Technical and usage data. Request URLs, IP address, browser or device information, timestamps, security events, performance measurements, and error diagnostics. Vercel also provides privacy-oriented, aggregate site analytics.
Twitch Extension privacy
The broadcaster linking flow requests Twitch identity only. We use the resulting access token once to read the public identity of the Twitch account being linked and then discard it. We do not request or retain the broadcaster's Twitch email address.
When the Extension loads, Twitch sends it a signed token that can include the channel ID and an opaque, per-extension viewer identifier. Our backend verifies that token to authorize the request and return the correct saved build. We do not use it to read or store a viewer's email, chat messages, follows, subscriptions, or general Twitch activity, and we do not build viewer advertising profiles.
Disconnecting Twitch deletes the stored link and its channel configuration. Deactivating or uninstalling the Extension stops Extension requests; disconnecting the account or deleting your POE Portfolio account removes the stored Twitch link.
How we use data
- Authenticate users and maintain account sessions.
- Import saved gear and estimate item and build values.
- Combine eligible community appraisals with automated market estimates while detecting abuse and low-quality submissions.
- Operate public profiles and the Twitch broadcaster-selected build display.
- Process subscriptions and provide paid features.
- Secure, debug, monitor, and improve the Service and comply with legal obligations.
Depending on the context, our legal bases are performance of our contract with you, our legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where we specifically request it. Automated valuations do not make decisions that create legal or similarly significant effects about you.
Cookies and local storage
We use essential cookies for authentication, security, OAuth state, return paths, and account linking. Short-lived OAuth state cookies normally expire within ten minutes. A guest who plays the Daily receives a random, HTTP-only identifier so their plays can be recovered or attached to an account; unclaimed guest data is deleted after 90 days. See the Daily data-use notice for more detail.
Sharing and service providers
We disclose data only as needed to operate the Service, comply with law, protect users, or complete a transaction you request. Providers include Vercel for hosting and analytics, Supabase for authentication and databases, Stripe for payments, Sentry for error monitoring, GGG and Twitch for linked platform services, infrastructure providers supporting market-data requests, and AI providers supporting automated valuation. Valuation prompts are designed to exclude account-level identifiers.
We may also disclose data if legally required, or during a merger, financing, acquisition, or sale, subject to appropriate safeguards and notice where required.
International transfers
We and our providers operate in several countries, including the United States, the European Union, Germany, New Zealand, and others where a provider operates. Where applicable, providers use contractual and other recognized safeguards for transfers of personal data across borders.
Retention
- Account, character, saved build, and Twitch-link data remain while your account or link is active and are deleted when you use the applicable disconnect or account-deletion control.
- Unclaimed Daily guest identifiers and their plays are deleted after 90 days.
- When an account is deleted, community contribution records are stripped of account identifiers and free-text notes. We retain de-identified valuation evidence so historical aggregate results and anti-abuse controls remain internally consistent.
- Security, support, and infrastructure logs are retained only for their operational purpose and then deleted or aged out under provider retention schedules.
- Limited billing and deletion-audit records may be retained for up to seven years where needed for tax, accounting, fraud prevention, dispute, or legal compliance.
Security
We use administrative, technical, and organizational safeguards, including row-level database access controls, encryption of GGG tokens at rest, restricted service credentials, signed-request verification, and rate limiting. No system is perfectly secure, so we cannot guarantee absolute security.
Your choices and rights
You can change profile visibility, disconnect linked services, and delete your account from the Service. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal data, withdraw consent, and complain to a data protection authority. We do not discriminate against users for exercising privacy rights.
Instructions and response timelines are on our data rights page.
Browser extension
If you use the optional POE Portfolio Pricing browser extension, it relays item-stat Trade API queries and results between poeportfolio.com and the Path of Exile Trade API. Its optional authenticated mode lets the browser attach an existing pathofexile.com session cookie. The extension cannot read, store, or transmit the POESESSID value itself. It stores only a local query counter and the weight-filter toggle in browser storage.
Children
The Service is not directed to children under 13. Do not create an account if you are under 13 or below the minimum age required to consent to online services where you live. Contact us if you believe a child provided personal data improperly.
Changes and contact
We may update this policy as the Service changes. We will change the effective date and provide additional notice for material changes where required.
POE Portfolio is the controller of the data described in this policy. For privacy questions or requests, email contact@poeportfolio.com.