privacy policy
effective july 31, 2026
This policy explains what Portals collects, how customer production data is handled, when data may be processed by service providers, and how customers can request access, export, correction, or deletion.
scope
scope
This Privacy Policy describes how Portals collects, uses, discloses, and protects personal information and customer production data in connection with the Portals website, applications, hosted services, pilots, support, and related communications.
Portals is designed for creative production teams. Customer assets, prompts, source media, version history, approvals, comments, lineage, metadata, and repository context may contain confidential business information. We treat that material as customer data, not as public content.
This policy is informational and may be supplemented by a signed order form, data-processing addendum, enterprise agreement, security review, or other written terms.
information we collect
information we collect
We may collect account and identity information such as name, email address, organization, role, authentication identifiers, workspace membership, and billing or procurement contacts.
We may collect customer content submitted to or generated in the service, including production assets, files, prompts, instructions, references, outputs, comments, approvals, repository structure, version history, and related metadata.
We may collect operational information such as device and browser data, IP address, timestamps, logs, feature usage, support messages, error reports, security events, and integration configuration.
We may collect payment, contract, and invoicing information through billing providers, but we do not intentionally store full payment card numbers in the Portals application.
how we use information
how we use information
We use information to provide, secure, maintain, troubleshoot, improve, and support the service; authenticate users; manage accounts and permissions; process transactions; communicate about the service; and comply with legal obligations.
We use customer production data to operate requested product features, preserve production history, support collaboration, process assets, generate or manage outputs, provide support when authorized, and perform security or integrity checks.
We do not sell private customer production data. We do not use private customer assets, prompts, source media, version history, private repositories, or proprietary production context to train shared AI models without explicit written permission.
ai processing and third-party providers
ai processing and third-party providers
Some features may send customer-selected content, prompts, files, metadata, or instructions to AI providers, cloud infrastructure, object storage, databases, authentication providers, email services, billing providers, observability tools, support tools, analytics tools, or integration providers as needed to deliver the service.
Website lead operations use a managed marketing-intake database, Tally for the embedded workflow assessment, Attio for customer-relationship records, Resend for requested delivery and follow-up email, and Mixpanel for consented website analytics. Each system receives only the data needed for its stated purpose.
Provider use depends on the deployed service, enabled integrations, customer configuration, and plan. Portals will not identify a provider as active unless it is actually used.
Where available and applicable, Portals seeks provider settings that limit provider use of customer data for training. Deployment-specific provider lists, data categories, and region details may be supplied during vendor or security review.
cookies and similar technologies
security
security
Portals uses commercially reasonable administrative, technical, and organizational measures designed to protect information. Current product architecture expects encrypted transport through HTTPS/TLS and infrastructure-supported encryption at rest.
Customer data is intended to be logically isolated by organization, workspace, repository, and permission boundaries. Dedicated environments, private cloud, customer-managed keys, specific recovery objectives, or formal certifications apply only when separately confirmed in writing.
As of July 31, 2026, Portals does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, GDPR certification, or another formal third-party security certification.
retention, export, and deletion
retention, export, and deletion
We retain account records, customer content, production history, metadata, logs, support records, billing records, and security records as needed to provide the service, comply with law, resolve disputes, enforce agreements, maintain integrity, and support security.
Customers may request export or deletion of customer data subject to account permissions, plan limits, technical feasibility, applicable agreements, and legal requirements. Active-system deletion may occur before backup, archive, or log expiration.
Certain records may be retained where required for legal, accounting, fraud-prevention, security, dispute-resolution, or repository-integrity purposes.
your choices and rights
your choices and rights
Depending on your location and relationship with Portals, you may have rights to request access, correction, deletion, portability, restriction, or objection regarding personal information.
Workspace administrators may manage many user and repository records directly. For requests that require Portals support, contact us at privacy@portals.works.
We may need to verify your identity, authority, and workspace relationship before fulfilling a request.
children
children
Portals is not directed to children under 13 and is not intended for personal use by children. We do not knowingly collect personal information from children under 13.
international transfers
international transfers
Portals and its providers may process information in the United States and other countries where we or our providers operate. Data protection laws may differ from those in your location.
Enterprise transfer mechanisms or data-region commitments apply only when included in a signed agreement.
changes and contact
changes and contact
We may update this Privacy Policy from time to time. The effective date above identifies the current version.
Questions or requests may be sent to privacy@portals.works.