Back to portzero.net

Privacy Policy

Effective date: July 25, 2026

This Privacy Policy explains how portzero.cloud ("we", "us", or "our") collects, uses, and protects information when you use the website, dashboard, CLI, and related services. We keep this policy focused on the information we actually need to run the service.

1. Information We Collect

1.1 Account Information

When you create an account or sign in, we may collect:

  • Email address used for authentication, account recovery, service notices, and optional product updates
  • Name, username, and profile details you choose to provide in the dashboard

1.2 Usage Data

While you use the service, we may collect:

  • Tunnel metadata such as domains, ports, request counts, aggregate request size, and last-seen timestamps
  • Login and account activity such as sign-in timestamps and actions taken in the dashboard
  • IP addresses and related network information used for security and abuse prevention

1.3 Payment Information

If you subscribe to a paid plan, payment processing is handled by Stripe. We do not store your full card number or CVV on our servers. We may receive:

  • A Stripe customer or subscription identifier
  • The last four digits of your payment card for display purposes
  • Billing history, invoices, and payment status

1.4 Technical Data

To diagnose issues and improve the service, we may collect:

  • Browser type and version
  • Operating system and CLI version
  • Error logs and diagnostic data that help us fix problems

1.5 Review Records

If you use review records, we collect the code diff and commit metadata you upload for a branch, the feedback comments left on the tunneled page tied to that review, and a screenshot captured automatically when a comment is pinned. This content is stored under your account so you and your reviewers can track, discuss, and resolve it.

1.6 Guest Comments

Guests do not need an account to leave feedback. When a guest pins a comment on a tunnel you share, we collect the display name they enter, the comment text, and a screenshot of the page at the time the comment was pinned. This information is stored in your account, subject to this policy, and guests see a notice before they submit a comment.

1.7 Product Analytics

We use PostHog, a product analytics platform, to understand how the website and dashboard are used so we can improve them. This covers pages viewed, features used, and events such as sign-in, tunnel activity, and subscription changes, along with technical details like browser, device, and approximate location derived from IP. We use this data in aggregate to improve the product and measure the effect of changes and pricing. We do not use it for third-party advertising, and we do not sell it. See Cookies and Local Storage for how to opt out.

1.8 Agent Cost Measurement Metadata

If you grant training consent for a repository, we collect usage metadata from your AI coding-agent sessions: model names, token counts, computed costs, timestamps, commit SHAs, and file paths. Granting that consent is a licence to use the repository's review history and this metadata to train and improve our models; it also enables the features that are paid for with it on your plan, such as agent cost measurement (what agent work costs per comment, commit, pull request, and line) and the review link. We collect metadata only: we do not collect the contents of your agent sessions — not the prompts, the model's responses, or your source code as seen inside a session. Nothing is collected for a repository until you enable it, and you can withdraw consent at any time (see our Terms for what withdrawal does and does not do).

1.9 What We Do Not Collect

  • We do not inspect or store the content of traffic flowing through your tunnels. Review records (Sections 1.5 and 1.6) are different: they are content you, your reviewers, or your guests explicitly submit, not tunnel traffic we observe
  • We do not collect the contents of your AI agent sessions — prompts, model responses, or in-session source code — for cost measurement or training (see Section 1.8)
  • We do not use advertising trackers or tracking pixels, and we do not sell your data or share it with advertisers
  • We do not collect data from your local services beyond what the CLI or browser sends to us

2. How We Use Information

We use information for the following business purposes:

Provide the service Authenticate you, manage tunnels, display account data, and keep the product functioning
Communicate with youSend verification codes, service notices, billing messages, support replies, and optional product updates or marketing emails
Improve the serviceUnderstand aggregate usage, troubleshoot issues, and ship product improvements
Train our modelsFor repositories where you have granted training consent, use review-loop content and cost/usage metadata to train and improve our models, on the data-for-access basis described in our Terms — never your AI session contents
Protect the platformDetect abuse, enforce our Terms of Service, and protect shared infrastructure
BillingProcess subscriptions, invoices, and account status changes

Marketing and product update emails are optional. You can unsubscribe from those messages without turning off account-related emails such as login codes, security notices, billing messages, and other service communications.

We do not use your information for third-party advertising or cross-service profiling.

4. How We Share Information

We share information only when needed to operate the service or when required by law:

4.1 Service Providers

We name every processor that handles personal data on our behalf, its purpose, and where it processes data, on our Subprocessors page. In summary:

  • Stripe processes payments and related billing operations
  • SendGrid delivers verification codes, account notifications, and optional marketing emails
  • PostHog provides product analytics on how the website and dashboard are used, only after you consent (see Cookies and Local Storage)
  • DigitalOcean hosts the application, database, and logs
  • Cloudflare provides DNS for our domains
  • GitHub provides OAuth sign-in / identity verification

See the Subprocessors page for the current, authoritative list, and our Data Processing Addendum for the contractual terms that apply to them.

4.2 No sale of personal information

We do not sell, rent, or trade your personal information.

4.3 Legal and business events

We may disclose information if required by law, to protect rights and safety, or in connection with a merger, financing, or acquisition.

5. Data Storage and Security

5.1 Security measures

We use reasonable administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

5.2 Access controls

Access to production systems and user data is limited to authorized personnel who need it to operate the service.

5.3 Incident response

If we become aware of a security incident affecting your personal information, we will investigate and notify affected users when required by law.

6. Data Retention

We keep information only as long as needed for the purposes described in this policy, unless a longer retention period is required by law. These are the concrete periods our systems enforce, including the automated purge job that deletes data once its period expires:

Audit log (incl. IP addresses)12 months, then purged
Abuse reports (reporter email + IP)12 months, then purged
Account / profile dataDeleted on account closure; residual copies in backups are purged within the 7-day point-in-time-recovery (PITR) window
Login / CLI verification codesMinutes to hours (single use, short-lived by design)
Product analytics (PostHog)12 months
Billing recordsApproximately 7 years, for tax and accounting compliance
Marketing-consent recordUntil you withdraw consent

7. International Data Transfers

Port Zero is based in the United States, and personal data is processed in the United States: our infrastructure runs on DigitalOcean's US region, and our service providers Stripe, SendGrid, and PostHog process data in the US. See the Subprocessors page for the current list and each provider's processing location.

When we transfer personal data of individuals in the European Economic Area or the United Kingdom to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) (and, for UK transfers, the UK's International Data Transfer Addendum) as the transfer mechanism. Details on the safeguards for a specific transfer are available on request; see Contact.

8. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict certain processing.

You can unsubscribe from marketing and product update emails by using the unsubscribe link in those emails. Unsubscribing from marketing does not disable account-related emails needed to operate your account and the service.

You can request account changes or data access by contacting us at support@portzero.net. We may need to verify your identity before fulfilling a request.

If you are dissatisfied with our response, you may also have the right to contact your local data protection authority.

9. Cookies and Local Storage

9.1 What we use

  • Strictly necessary — session authentication: the dashboard uses localStorage to store a JWT that keeps you signed in. This is required for the dashboard to function and is exempt from cookie consent under ePrivacy rules, so it is not covered by the cookie banner below.
  • Optional — analytics: our analytics provider, PostHog, sets first-party cookies and localStorage entries to recognize returning visitors and measure usage across sessions (see Section 1.7). These load only after you accept analytics in the cookie banner shown on your first visit.

9.2 The cookie-consent banner

portzero.net shows a cookie-consent banner on your first visit. Choosing Accept lets analytics load; choosing Reject keeps analytics off and sets no analytics cookies. Your choice is saved in first-party browser storage on this device. You can change it at any time using the Cookie preferences link in the footer, which reopens the banner.

9.3 What we do not use

  • No advertising cookies or tracking pixels
  • No cross-site tracking or cookies shared with advertisers

9.4 Opting out and clearing your data

Analytics only loads after you accept it in the cookie banner, and it also respects your browser's Global Privacy Control / Do Not Track signal even if you accepted. You can also opt out at any time using Cookie preferences in the footer, by blocking analytics cookies in your browser, or by using a content blocker. Sign out from the dashboard to remove the JWT from localStorage, or clear your browser storage manually to remove all of the above.

10. Children

The service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has created an account, email support@portzero.net.

11. Changes to This Policy

When we make changes to this policy, we will update the effective date and, when appropriate, notify you by email or in-product notice.

  • Minor changes may take effect immediately when the policy is posted
  • Material changes may be announced before they take effect

12. Contact

We aim to respond to privacy-related inquiries within 14 days.