privacy policy

effective july 31, 2026

This policy explains what Portals collects, how customer production data is handled, when data may be processed by service providers, and how customers can request access, export, correction, or deletion.

01

scope

scope

This Privacy Policy describes how Portals collects, uses, discloses, and protects personal information and customer production data in connection with the Portals website, applications, hosted services, pilots, support, and related communications.

Portals is designed for creative production teams. Customer assets, prompts, source media, version history, approvals, comments, lineage, metadata, and repository context may contain confidential business information. We treat that material as customer data, not as public content.

This policy is informational and may be supplemented by a signed order form, data-processing addendum, enterprise agreement, security review, or other written terms.

02

information we collect

information we collect

We may collect account and identity information such as name, email address, organization, role, authentication identifiers, workspace membership, and billing or procurement contacts.

We may collect customer content submitted to or generated in the service, including production assets, files, prompts, instructions, references, outputs, comments, approvals, repository structure, version history, and related metadata.

We may collect operational information such as device and browser data, IP address, timestamps, logs, feature usage, support messages, error reports, security events, and integration configuration.

We may collect payment, contract, and invoicing information through billing providers, but we do not intentionally store full payment card numbers in the Portals application.

03

how we use information

how we use information

We use information to provide, secure, maintain, troubleshoot, improve, and support the service; authenticate users; manage accounts and permissions; process transactions; communicate about the service; and comply with legal obligations.

We use customer production data to operate requested product features, preserve production history, support collaboration, process assets, generate or manage outputs, provide support when authorized, and perform security or integrity checks.

We do not sell private customer production data. We do not use private customer assets, prompts, source media, version history, private repositories, or proprietary production context to train shared AI models without explicit written permission.

04

ai processing and third-party providers

ai processing and third-party providers

Some features may send customer-selected content, prompts, files, metadata, or instructions to AI providers, cloud infrastructure, object storage, databases, authentication providers, email services, billing providers, observability tools, support tools, analytics tools, or integration providers as needed to deliver the service.

Website lead operations use a managed marketing-intake database, Tally for the embedded workflow assessment, Attio for customer-relationship records, Resend for requested delivery and follow-up email, and Mixpanel for consented website analytics. Each system receives only the data needed for its stated purpose.

Provider use depends on the deployed service, enabled integrations, customer configuration, and plan. Portals will not identify a provider as active unless it is actually used.

Where available and applicable, Portals seeks provider settings that limit provider use of customer data for training. Deployment-specific provider lists, data categories, and region details may be supplied during vendor or security review.

05

cookies and similar technologies

cookies and similar technologies

The website and application may use cookies, local storage, session storage, and similar technologies for authentication, security, preferences, analytics, performance, and product operation.

When you submit a website form, Portals may set an opaque, HTTP-only browser cookie for up to 90 days so later forms can omit contact details already supplied in that browser. The cookie contains no readable personal information or CRM identifier, does not identify you across devices, and can be reset using the visible “not you?” control.

Mixpanel analytics is initialized only after analytics consent. Portals does not send form messages, workflow descriptions, names, or email addresses to Mixpanel.

You may control cookies through browser settings. Some service features may not work correctly if required authentication or security cookies are blocked.

06

security

security

Portals uses commercially reasonable administrative, technical, and organizational measures designed to protect information. Current product architecture expects encrypted transport through HTTPS/TLS and infrastructure-supported encryption at rest.

Customer data is intended to be logically isolated by organization, workspace, repository, and permission boundaries. Dedicated environments, private cloud, customer-managed keys, specific recovery objectives, or formal certifications apply only when separately confirmed in writing.

As of July 31, 2026, Portals does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, GDPR certification, or another formal third-party security certification.

07

retention, export, and deletion

retention, export, and deletion

We retain account records, customer content, production history, metadata, logs, support records, billing records, and security records as needed to provide the service, comply with law, resolve disputes, enforce agreements, maintain integrity, and support security.

Customers may request export or deletion of customer data subject to account permissions, plan limits, technical feasibility, applicable agreements, and legal requirements. Active-system deletion may occur before backup, archive, or log expiration.

Certain records may be retained where required for legal, accounting, fraud-prevention, security, dispute-resolution, or repository-integrity purposes.

08

your choices and rights

your choices and rights

Depending on your location and relationship with Portals, you may have rights to request access, correction, deletion, portability, restriction, or objection regarding personal information.

Workspace administrators may manage many user and repository records directly. For requests that require Portals support, contact us at privacy@portals.works.

We may need to verify your identity, authority, and workspace relationship before fulfilling a request.

09

children

children

Portals is not directed to children under 13 and is not intended for personal use by children. We do not knowingly collect personal information from children under 13.

10

international transfers

international transfers

Portals and its providers may process information in the United States and other countries where we or our providers operate. Data protection laws may differ from those in your location.

Enterprise transfer mechanisms or data-region commitments apply only when included in a signed agreement.

11

changes and contact

changes and contact

We may update this Privacy Policy from time to time. The effective date above identifies the current version.

Questions or requests may be sent to privacy@portals.works.

12

contact

questions about privacy policy.

contact us for privacy, legal, or document questions.