[Portsyde LLC] runs Portsyde, and this policy explains what we do with personal data. The short version: we hold the little we need to give you an account, bill you and keep the service up. We do not sell data, we do not advertise, and we cannot see your media.
1.What this policy covers
This policy covers personal data we handle as the controller: the data behind your account on portsyde.com and in the Portsyde service. It does not cover the third-party sources and services you connect, which have their own policies and their own relationship with you.
It also does not cover your media, because we never have it. Playback runs from your source to your device without passing through our servers, so there is no library of yours for us to read, scan or hand over.
2.What we collect
- Account email address
- The address you sign in with. It is how we identify your account and how we send you one-time sign-in codes and service notices.
- Billing status
- Your plan, whether a subscription is active, and the renewal date, received from Stripe. Stripe processes the payment itself; card numbers never reach us and we never store them.
- Engine configuration
- The setup you create: the sources and services you connect and how you have arranged them, including credentials for third-party services, which are encrypted.
- Devices and sessions
- A record of each device paired to your account — device name, app name and when it was last seen — so you can see what is signed in and remove anything you do not recognise.
- Request logs
- Ordinary server logs, including IP address, timestamp and the endpoint called. We keep them for 30 days for security, abuse prevention and rate limiting, then they are deleted.
- Email delivery records
- Postmark sends our email and records delivery outcomes, so we can tell whether a sign-in code actually arrived.
3.What we do not do
- We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.
- We run no advertising and no advertising trackers.
- We set no tracking or analytics cookies. We look at aggregate server metrics — request counts, error rates, latency — which are not tied to individuals.
- We do not store passwords for your account, because there are none: sign-in is by one-time code.
- We do not profile you or make decisions about you by automated means that produce legal or similarly significant effects.
4.Why we use it
Where the GDPR or UK GDPR applies, these are our legal bases:
- Performance of a contract
- Creating and authenticating your account, storing and running your configuration, pairing your devices, and providing support. Without this data there is no service to provide.
- Legitimate interests
- Keeping the service secure and available, preventing abuse, rate limiting, maintaining short-lived logs, and sending necessary service notices. We balance these against your interests and keep the data minimal and short-lived.
- Legal obligation
- Meeting tax, accounting and record-keeping duties, and responding to lawful requests.
5.How long we keep it
- Account email, configuration and device records: for as long as your account exists, and deleted when you delete it.
- Request logs, including IP addresses: 30 days.
- One-time sign-in codes: minutes. They expire on use or shortly after being issued.
- Billing and tax records: retained by us and by Stripe for as long as tax and accounting law requires, typically several years, even after an account is closed.
6.Who we share it with
We use a small number of subprocessors to run Portsyde. Each handles data only on our instructions and under a contract, and each is bound to protect it.
- Supabase
- Database and authentication. Stores account records, configuration and device records, and issues one-time sign-in codes.
- Fly.io
- Compute. Runs the service and produces the request logs described above.
- Cloudflare
- DNS and network. Routes and protects traffic to the service, and sees request metadata such as IP addresses in transit.
- Stripe
- Payments. Takes and processes payment details directly as its own controller, and tells us only your billing status.
- Postmark
- Email. Delivers sign-in codes and service messages to your address.
Beyond these, we disclose personal data only where the law requires it, where it is needed to establish or defend legal claims, or as part of a merger or sale of the business — in which case we would tell you before your data moved.
7.International transfers
[Portsyde LLC] and its subprocessors are based in, or process data in, the United States. If you are in the EEA, the UK or Switzerland, your data will be transferred there.
Those transfers rely on the standard safeguards approved for the purpose, including the European Commission's standard contractual clauses and the UK addendum, together with the technical measures described under Security below. You can ask us for details of the safeguards used.
8.Your rights
Wherever you live, you can ask us to:
- give you a copy of the personal data we hold about you, and tell you what we do with it;
- correct anything that is wrong;
- delete your account and the data attached to it;
- give you your data in a portable form; or
- stop a particular use, where we rely on legitimate interests.
Email legal@portsyde.com from your account address and we will answer within 30 days. We will never charge you for asking, and we will never treat you differently for it.
9.Regional rights
- EEA, UK and Switzerland
- You have the rights above under the GDPR and UK GDPR, plus the right to withdraw consent where we rely on it and the right to complain to your local supervisory authority. We would rather you came to us first, but the right is yours either way.
- California
- Under the CCPA as amended, you have the right to know, delete, correct and obtain a portable copy of your personal information, and the right not to be discriminated against for exercising those rights. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no opt-out to offer.
- Other US states
- Where a state privacy law gives you equivalent rights of access, correction, deletion, portability or opt-out, we honour them through the same request address.
10.Deleting your account
Account deletion is self-service: you will find it in the dashboard, and it does not require an email to support. Deleting your account removes your account record, your engine configuration and the encrypted credentials inside it, your device and session records, and your billing profile with us.
Two things survive, and only these: transaction records that tax and accounting law requires us and Stripe to keep, and request logs still inside their 30-day window, which age out on their own. Backups are overwritten on a rolling cycle.
11.Children
Portsyde is for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, tell us and we will delete the account.
12.Security
Traffic to and from the service is encrypted in transit. Credentials you add for third-party services are encrypted at rest and used only to carry out your own requests. Access to production systems is limited to the people who need it, and sign-in codes are short-lived and single-use.
No service can promise perfect security. If a breach affects your personal data we will notify you and the relevant authorities as the law requires, and tell you plainly what happened.
13.Changes to this policy
When this policy changes we update the effective date at the top of the page. If a change materially affects how we use your personal data, we will email your account address before it takes effect.
14.Contact
Privacy questions and rights requests go to legal@portsyde.com, or by post to [Portsyde LLC], [Mailing address for legal notices]. For everything else, email support@portsyde.com. See also the Cookie Policy and the Terms of Service.