Privacy Policy
What Bluefolio collects, why, who can see it, and the choices you have.
Last updated October 3, 2026The short version
- We collect what you put on your page and the basics from your Google sign-in. We use it to run Bluefolio: show your work, verify you, and connect you with employers.
- Your course, class and diploma are education records, which the Data Privacy Act treats as sensitive. We process them only with your consent.
- Employers see your page and what you send when you apply. Your email reaches an employer only once they shortlist you.
- No ads. We don’t sell your data. No third-party analytics or tracking.
- Diploma and alumni ID scans are deleted as soon as they’re reviewed. You can delete your account anytime in Settings.
This summary helps you read the full text below; it doesn’t replace it.
Who we are
Bluefolio is a verified, portfolio-first career network for the Ateneo de Manila community. It is run by [Operator legal name], [Business address] (“Bluefolio”, “we”, “us”). For the personal information described here, we are the personal information controller under the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.
Our Data Protection Officer is [Data Protection Officer name], reachable at [Data Protection Officer email].
Bluefolio is not affiliated with, endorsed by, or run by Ateneo de Manila University. We use Ateneo Google accounts only to confirm that you’re part of the community.
What we collect
From Google, when you sign in
Your name, email address and profile photo, and the Google Workspace domain of your account (for example, student.ateneo.edu). Bluefolio has no passwords; Google handles sign-in.
Your page
- Display name, an optional nickname, and your @handle.
- Your status (student, alumni or faculty), course and class year, or department and position.
- Headline, bio, location, profile photo, skills, links (such as LinkedIn), availability and what you’re open to.
- Projects, with any images, PDFs and links you add; experience, education, organizations and awards.
- A résumé, if you upload one, and your choice of who can see your page.
Verification
Students and faculty are verified by their Ateneo Google account. Alumni send their full name, course, graduation year, an optional LinkedIn URL, and a photo of their diploma or alumni ID. The photo is seen only by Bluefolio admins and is deleted as soon as it’s approved or rejected. We keep the decision, the reviewer and any reason given.
Jobs and applications
- The jobs you apply to, an optional note to the employer, the résumé you send, and each application’s status.
- For jobs that apply on the employer’s own site: that you applied, and your answer when we ask “Did you hear back?”.
- Jobs and profiles you save, invitations to apply you receive, and your notifications and notification settings.
- Reports you file about a job or an employer, with the reason and any note.
If you hire
Your organization’s details (name, website or LinkedIn, SEC or DTI registration number, description, logo, photos), the work domain of your Google account, your team and its join requests and invite links, the jobs you post including pay, and what happens to applications.
Generated as you use Bluefolio
- Sign-in sessions and the tokens that keep you signed in.
- Job views: which signed-in person viewed a job, at most once a day, so employers see a view count.
- Error reports when a page breaks: the error, the page path (no query string), your browser and operating system in short form (for example “Chrome 140 · macOS”), and your account ID if you’re signed in. Email addresses are removed before saving.
- Admin actions, such as verification and employer decisions, report outcomes and suspensions, with the admin who took them.
We don’t collect your location, contacts, government ID numbers (other than an employer’s business registration number) or payment details.
Why we use it, and on what basis
We use your information only for the purposes below. Under the Data Privacy Act, each purpose needs a lawful basis:
- Showing your page, projects and profile
- Our agreement with you (the Terms), and your consent for education information
- Verifying students, faculty and alumni
- Your consent, since education records are sensitive personal information
- Sending your applications to employers and showing you their status
- Our agreement with you, and your consent
- Letting verified employers find you in talent search
- Your consent; only live, verified pages appear
- Vetting employers and enforcing the posting rules
- Our legitimate interest in keeping Bluefolio safe from scams
- Handling reports, suspensions and appeals
- Our legitimate interest in safety, and our agreement with you
- Notifications, including optional weekly job matches and product news
- Our agreement with you; the optional ones only if you turn them on
- Fixing errors and keeping the service secure
- Our legitimate interest in a working, secure service
- Responding to lawful requests
- Compliance with a legal obligation
Education information (your course, class, school records and diploma) is sensitive personal information under Section 3(l) of the Act. We process it on the basis of your express consent, which you give when you agree at sign-up. You can withdraw consent at any time (see Your rights); because Bluefolio is built on that information, withdrawing means closing your account.
We don’t use your information for advertising, we don’t sell or rent it, and we don’t make automated decisions about you that have legal or similarly significant effects.
Who can see what
- Your page. Once live, your page is public by default: anyone with the link can see it, it can appear in link previews, and search engines may index it. In Settings → Privacy you can make it visible only to people signed in to Bluefolio who are verified or on an approved employer’s team.
- Before you’re verified, your page isn’t live and only you can see it.
- Employers on an approved team can find live pages in talent search and invite you to apply. What they see when you apply is described in the next section.
- Bluefolio admins see what they need to run the service: verification requests (including diploma photos until reviewed), employer applications, reports and error logs.
- Never shown to other members: your email address (except to an employer who has shortlisted you), your verification documents, your saved items, your notification settings, and the reports you file. Employers you report are not told who reported them.
Sharing with employers
When you apply to a job through Bluefolio, the employer’s team sees your page, your note and the résumé you chose to send, and can move your application through their pipeline. You see the status as it changes.
Your email address is shared only once the employer shortlists you (and stays visible if they contact or hire you), so they can reach you directly.
Employers are separate organizations. Once they receive your application, they are responsible for how they use it and must use it only to consider you for that role (see our Terms). Anything you share with an employer outside Bluefolio, or on their own application site, is covered by their privacy policy, not ours.
Jobs on Bluefolio always show the pay, and applicants are never charged a fee. If an employer asks you for money or for information unrelated to the job, please report it.
Service providers and transfers abroad
We use a small number of providers to run Bluefolio. They process information only on our instructions and under contracts that require them to protect it:
- Vercel Inc. (United States)
- Hosts the website and serves pages
- Convex, Inc. (United States)
- Stores the database and uploaded files, and runs the app’s backend
- Google LLC
- Signs you in with your Google account; we receive your name, email, photo and Workspace domain
Because Vercel and Convex store and process data in the United States, your information is transferred outside the Philippines. We stay accountable for it under Section 21 of the Data Privacy Act and require these providers to protect it to a comparable standard.
We don’t use third-party analytics, advertising networks, tracking pixels or email marketing services. We may disclose information if the law requires it, for example under a valid court order, and only as much as required.
How long we keep it
- Diploma or alumni ID photos
- Deleted when the request is approved or rejected. Abandoned uploads are deleted within a day.
- Your account, page and activity
- Until you delete your account
- Error reports
- Deleted after 30 days without the error recurring
- Old handles after a change
- Redirect to your page for 90 days, then released
- Reports you filed
- Kept for safety after you leave, with your identity removed
When you delete your account
Settings → Delete account takes your page offline and signs you out everywhere at once, then removes your information in stages, usually within minutes:
- Your profile, projects, experience and other entries, and every file you uploaded (photos, project images and PDFs, résumés).
- Your applications, so employers no longer see them; saved items, invites, notifications and job views.
- Your verification records, team memberships, join requests, sign-in sessions and your account itself.
Some things stay because others rely on them: reports you filed (without your name), job view totals (a number, with no viewer), and organizations and jobs that belong to a team (handed over to a teammate, or closed and suspended if you were the last member). Error reports keep an account ID that no longer points to anyone, until they expire. Copies an employer already downloaded are theirs to delete under the law. Backups held by our providers roll over on their own schedule.
How we protect it
- Sign-in through Google; no passwords stored by us. Sessions use secure, HTTP-only cookies.
- All traffic is encrypted in transit (HTTPS), and our providers encrypt stored data.
- Every read and write is checked on the server: people see only what the rules above allow.
- Uploads are checked for type and size; diploma photos are limited to admins and deleted after review.
- Admin access is limited to a few people, and their decisions are recorded.
No system is perfectly secure. If a breach puts your information at real risk, we will notify you and the National Privacy Commission as the law requires (within 72 hours of knowing about it, under NPC Circular No. 16-03).
Your rights
Under the Data Privacy Act you have the right to:
- Be informed about how your information is processed. This policy is how we do that.
- Access your information. Most of it is on your page and in Settings; ask us for a full copy.
- Correct it. Edit your page anytime, or ask us to fix anything you can’t.
- Erasure or blocking. Delete your account in Settings, or ask us to remove specific information.
- Object to processing, including withdrawing consent. You can turn off optional notifications in Settings.
- Data portability. Ask us for your information in a structured, commonly used electronic format.
- Damages if you’re harmed by inaccurate, incomplete, outdated, false or unlawfully obtained or used information.
- File a complaint with the National Privacy Commission (privacy.gov.ph). We’d appreciate the chance to fix things first.
To use any of these rights, email [Contact email] or our Data Protection Officer at [Data Protection Officer email] from the address you sign in with. We may ask you to confirm it’s you, and we’ll answer within the time the law requires.
Age
Bluefolio is for people 18 and older. If you’re under 18, please don’t sign up. If we learn that someone under 18 has an account, we’ll delete it. If you believe a minor has signed up, tell us at [Contact email].
Changes to this policy
When we change this policy, we’ll update the date at the top. If a change affects how we use your information, we’ll ask you to agree again the next time you sign in, before you continue. Earlier versions are available on request.
Contact
Questions, requests or complaints about privacy:
- Email [Contact email]
- Data Protection Officer: [Data Protection Officer name], [Data Protection Officer email]
- Post: [Operator legal name], [Business address]