Privacy Policy
What information PortModels collects, how it is used and shared, how long it is kept, and the choices and rights you have over it.
This Privacy Policy explains what information PortModels collects when you use the website, the app gallery, your account, credits, the Connect authorization flow, the API, and app data storage, and how we handle it.
It applies to the PortModels platform itself. Apps published by third-party developers are operated by those developers; what an app does with data you give it directly is covered by that developer's own policy.
Information We Collect#
Information you give us
- Account details — your PortModels account identifier, email address, username, and display name. The website does not collect or store a separate website password.
- Content you submit — app listings, cover images and screenshots, comments, ratings, and messages sent through contact forms.
- Payment information — handled by our payment processor. We receive a customer reference, the amount, the currency, the status, and card metadata such as the last four digits and brand. We never receive or store your full card number.
- Correspondence — the contents of emails and support requests you send us.
Information generated by using the Service
- Usage and metering records — which app or API key made a request, the model used, token or unit counts, computed cost, developer share, and the resulting credit transactions. These are the basis of your balance and of developer earnings, so we keep them as financial records.
- Prompts and model output — the input you send to a model and the response it returns, to the extent needed to deliver the response, meter usage, debug failures, and enforce our Terms.
- App data — key-value entries and files that apps store on your behalf, plus their size, so we can enforce storage limits.
- Authorizations — which apps you connected, the scopes you granted, and when tokens were issued, refreshed, or revoked.
- Security and diagnostic data — IP address, request time, user agent, requested path, error reports, and similar server logs.
We do not intentionally collect special categories of personal data. Please do not submit them in prompts, listings, or stored files.
How We Use Information#
We use the information we collect to:
- Create and secure your account, and authenticate API keys and Connect tokens.
- Route requests to model providers and return responses to you.
- Meter usage, calculate charges, maintain your credit balance, and calculate developer earnings and payouts.
- Process payments, subscriptions, refunds where applicable, and chargebacks.
- Operate app data storage and enforce storage quotas.
- Display published apps, comments, and ratings as part of the gallery.
- Review submitted apps and content for compliance with our content guidelines.
- Respond to support requests and other inquiries.
- Detect, investigate, and prevent abuse, fraud, and security incidents.
- Understand aggregate usage patterns so we can improve the platform.
- Comply with legal obligations, including tax and accounting requirements.
We do not use your prompts or model output to train our own models, and we do not sell personal information.
Legal Bases#
Where data protection law such as the GDPR applies, we rely on:
- Contract — to provide the Service you signed up for: accounts, model access, billing, and storage.
- Legitimate interests — to secure the platform, prevent abuse and fraud, and improve the Service, balanced against your rights.
- Legal obligation — to keep financial records and to respond to lawful requests.
- Consent — where we ask for it, such as optional updates. You can withdraw consent at any time.
Sharing of Information#
We do not sell personal information. We share it only in these situations:
- Model providers. Your prompts and related request data are sent to the model provider serving the model you selected, so it can generate a response. Providers process that data under their own terms.
- Payment processing. Stripe processes payments, subscriptions, and payouts, and receives the information necessary to do so.
- Infrastructure providers. Hosting, object storage, email delivery, and error-monitoring providers process data on our behalf under contract.
- App developers. A developer whose app you authorized can see the usage their app generated and data your use of the app created within it. They receive your email only when you approve the separate
profile.emailscope; they do not receive your password, your full credit history, or your activity in other apps. - Publicly, by your action. App listings, comments, ratings, your public display name, and any data you explicitly mark public are visible to others.
- Legal and safety. When disclosure is required by law, regulation, or legal process, or is necessary to protect rights, safety, or the integrity of the Service.
- Business transition. As part of a merger, financing, acquisition, or asset transfer, subject to confidentiality obligations and this policy.
International Transfers#
Our infrastructure and the providers we use may process data in countries other than yours, including outside the EEA and the UK. Where required, we rely on appropriate safeguards such as standard contractual clauses.
Retention#
We keep information only as long as we need it:
- Account details — while your account is active, and for a limited period after deletion to resolve disputes and prevent abuse.
- Usage, credit, and payment records — for as long as required by tax, accounting, and audit obligations, typically several years, even after account deletion.
- Prompts and model output — for a limited operational period for delivery, debugging, and abuse investigation, unless we are required to keep them longer.
- App data you store — until you or the app deletes it, or until your account is deleted.
- Server and security logs — for a short retention window, then deleted or aggregated.
When information is no longer needed, we delete it or de-identify it.
Security#
We use reasonable administrative and technical measures to protect information, including hashed PortModels passwords, scoped tokens with limited lifetimes, revocable API keys, encrypted transport, and access controls on internal systems. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security. Report a suspected vulnerability or compromise to [email protected].
Your Choices and Rights#
You can:
- Update your account details, and delete apps, comments, and ratings you submitted.
- Review and revoke connected apps and API keys at any time.
- Delete data your apps have stored, subject to how each app manages it.
- Request deletion of your account and associated information by contacting us.
Depending on where you live, you may also have the right to access, correct, delete, restrict, or object to processing of your personal data, to receive a portable copy, and to lodge a complaint with your local supervisory authority. To exercise these rights, email [email protected]. We may need to verify your identity, and some records — particularly financial records — must be retained even after an erasure request.
Cookies and Local Storage#
We use a session cookie to keep you logged in and to protect forms against cross-site request forgery. We also use browser local storage for preferences such as your light or dark theme. These are necessary for the site to work as expected; we do not use third-party advertising or cross-site tracking cookies.
Children's Privacy#
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
Changes to This Policy#
We may update this Privacy Policy from time to time. When we do, we will revise the last-updated date on this page. Material changes take effect when posted unless a later effective date is stated.
Contact#
Questions or requests related to privacy can be sent to [email protected].