Privacy policy
Last updated:
What we collect
We collect the information needed to give you a working Portals AI workspace:
- Account and identity information from our identity provider when you sign in — your name, email address, and the identifier that ties you to your organization.
- The data you connect through connectors — the records, files, and spreadsheet content you import or link, and the credentials or authorizations you grant so we can access a source on your behalf.
- Operational telemetry about how the Service runs for you — job activity, tool calls and their metered usage, and standard technical logs (such as timestamps and error diagnostics) used to operate and secure the Service.
The marketing site itself sets no advertising or analytics cookies and runs no third-party tracking.
How we use it
We use your information solely to operate the workspace you asked for: to authenticate you, to sync your connected sources, to answer your portal questions through the AI agent, to meter tool usage against your plan, and to keep the Service secure and reliable.
We do not sell your data, and we do not use the content you connect to train models. Your Content is processed to provide the Service to you, not for our own unrelated purposes.
Third parties we share it with
We rely on a small set of subprocessors to run the Service. Each receives only the data needed for its function:
- Amazon Web Services (AWS) — cloud hosting and storage, in the United States region where the Service runs.
- Auth0 — identity and authentication (sign-in and account identity).
- Stripe — payment processing and subscription billing for paid plans.
- Google and Microsoft — OAuth-based connectors, used only for the sources you explicitly connect and only within the access you grant.
- Anthropic — the AI model provider behind portal answers; the prompts and context needed to answer your questions are sent to generate a response.
- Tavily — web search, when a portal question uses the web-search tool.
- Mapbox — geocoding, when a portal question uses the geocoding tool.
In addition, any custom webhook tool you register sends data to the endpoint you host and control; that endpoint is your responsibility, not a Portals AI subprocessor. We may also disclose information where required by law or to protect the rights, safety, and security of Portals AI, our users, and the public.
Where your data lives and how long we keep it
Your data is hosted with AWS in a United States region.
We keep data only as long as it is needed to provide the Service:
- Connected records are retained while they are live and are purged approximately 30 days after they are removed from your workspace. Records whose parent connector has itself been deleted are purged sooner — approximately 7 days — because nothing can reference them again.
- The usage audit ledger, which records metered tool activity for billing and accountability, is retained for approximately 24 months and then purged.
Deleting a record, a connector, or an organization removes the associated data from the active Service and schedules it for purge on the windows above. Backups and logs age out on their own routine cycles.
Your rights
You can access, correct, export, and delete the data you hold in the Service directly from the app: records and connectors are editable and deletable in your workspace, and an organization owner can delete the entire organization.
Depending on where you live, you may have additional rights over your personal data, such as the right to access, correct, delete, or port it, or to object to or restrict certain processing. To exercise a right we cannot service in-app, or to ask a question about your data, contact us at qa@portalsai.io and we will respond as required by applicable law.
Security
We protect your data with encryption in transit and at rest, and we handle connector credentials as secrets — stored encrypted and used only to access the sources you authorized.
Access to production systems and data is scoped to what is needed to operate the Service. No method of transmission or storage is perfectly secure, but we work to protect your information consistent with the sensitivity of the data and industry practice.
Changes to this policy
We may update this policy as the Service evolves. When we make a material change, we will update the “Last updated” date below and, where appropriate, notify you. Questions about this policy can be sent to qa@portalsai.io.
Questions about this policy: qa@portalsai.io