Privacy Policy
Effective date: July 25, 2026
This Privacy Policy explains how portzero.cloud ("we", "us", or "our") collects, uses, and protects information when you use the website, dashboard, CLI, and related services. We keep this policy focused on the information we actually need to run the service.
1. Information We Collect
1.1 Account Information
When you create an account or sign in, we may collect:
- Email address used for authentication, account recovery, service notices, and optional product updates
- Name, username, and profile details you choose to provide in the dashboard
1.2 Usage Data
While you use the service, we may collect:
- Tunnel metadata such as domains, ports, request counts, aggregate request size, and last-seen timestamps
- Login and account activity such as sign-in timestamps and actions taken in the dashboard
- IP addresses and related network information used for security and abuse prevention
1.3 Payment Information
If you subscribe to a paid plan, payment processing is handled by Stripe. We do not store your full card number or CVV on our servers. We may receive:
- A Stripe customer or subscription identifier
- The last four digits of your payment card for display purposes
- Billing history, invoices, and payment status
1.4 Technical Data
To diagnose issues and improve the service, we may collect:
- Browser type and version
- Operating system and CLI version
- Error logs and diagnostic data that help us fix problems
1.5 Review Records
If you use review records, we collect the code diff and commit metadata you upload for a branch, the feedback comments left on the tunneled page tied to that review, and a screenshot captured automatically when a comment is pinned. This content is stored under your account so you and your reviewers can track, discuss, and resolve it.
1.6 Guest Comments
Guests do not need an account to leave feedback. When a guest pins a comment on a tunnel you share, we collect the display name they enter, the comment text, and a screenshot of the page at the time the comment was pinned. This information is stored in your account, subject to this policy, and guests see a notice before they submit a comment.
1.7 Product Analytics
We use PostHog, a product analytics platform, to understand how the website and dashboard are used so we can improve them. This covers pages viewed, features used, and events such as sign-in, tunnel activity, and subscription changes, along with technical details like browser, device, and approximate location derived from IP. We use this data in aggregate to improve the product and measure the effect of changes and pricing. We do not use it for third-party advertising, and we do not sell it. See Cookies and Local Storage for how to opt out.
1.8 Agent Cost Measurement Metadata
If you grant training consent for a repository, we collect usage metadata from your AI coding-agent sessions: model names, token counts, computed costs, timestamps, commit SHAs, and file paths. Granting that consent is a licence to use the repository's review history and this metadata to train and improve our models; it also enables the features that are paid for with it on your plan, such as agent cost measurement (what agent work costs per comment, commit, pull request, and line) and the review link. We collect metadata only: we do not collect the contents of your agent sessions — not the prompts, the model's responses, or your source code as seen inside a session. Nothing is collected for a repository until you enable it, and you can withdraw consent at any time (see our Terms for what withdrawal does and does not do).
1.9 What We Do Not Collect
- We do not inspect or store the content of traffic flowing through your tunnels. Review records (Sections 1.5 and 1.6) are different: they are content you, your reviewers, or your guests explicitly submit, not tunnel traffic we observe
- We do not collect the contents of your AI agent sessions — prompts, model responses, or in-session source code — for cost measurement or training (see Section 1.8)
- We do not use advertising trackers or tracking pixels, and we do not sell your data or share it with advertisers
- We do not collect data from your local services beyond what the CLI or browser sends to us
2. How We Use Information
We use information for the following business purposes:
| Provide the service | Authenticate you, manage tunnels, display account data, and keep the product functioning |
|---|---|
| Communicate with you | Send verification codes, service notices, billing messages, support replies, and optional product updates or marketing emails |
| Improve the service | Understand aggregate usage, troubleshoot issues, and ship product improvements |
| Train our models | For repositories where you have granted training consent, use review-loop content and cost/usage metadata to train and improve our models, on the data-for-access basis described in our Terms — never your AI session contents |
| Protect the platform | Detect abuse, enforce our Terms of Service, and protect shared infrastructure |
| Billing | Process subscriptions, invoices, and account status changes |
Marketing and product update emails are optional. You can unsubscribe from those messages without turning off account-related emails such as login codes, security notices, billing messages, and other service communications.
We do not use your information for third-party advertising or cross-service profiling.
3. Legal Bases for Processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6 of the GDPR (and the equivalent provisions of the UK GDPR) for each purpose we process personal data for:
| Account and authentication | Contract (Art. 6(1)(b)) — necessary to create your account and provide the service you asked for |
|---|---|
| Billing and subscriptions | Contract (Art. 6(1)(b)), and Legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Security and abuse prevention, including IP address logging | Legitimate interests (Art. 6(1)(f)) — protecting the service, our customers, and shared infrastructure from abuse, outweighing the minimal impact on you |
| Product analytics (PostHog) | Consent (Art. 6(1)(a)) — collected only after you accept analytics cookies in the cookie banner; withdrawable at any time |
| Review history and agent-cost metadata used for model training | Consent (Art. 6(1)(a)) — collected only for repositories where you explicitly grant training consent; withdrawable per repository at any time (see Terms) |
| Marketing email | Consent (Art. 6(1)(a)) — sent only if you opt in, and you can withdraw at any time using the unsubscribe link |
Where processing relies on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal. Where processing relies on legitimate interests, you can object as described in Your Rights.
4. How We Share Information
We share information only when needed to operate the service or when required by law:
4.1 Service Providers
We name every processor that handles personal data on our behalf, its purpose, and where it processes data, on our Subprocessors page. In summary:
- Stripe processes payments and related billing operations
- SendGrid delivers verification codes, account notifications, and optional marketing emails
- PostHog provides product analytics on how the website and dashboard are used, only after you consent (see Cookies and Local Storage)
- DigitalOcean hosts the application, database, and logs
- Cloudflare provides DNS for our domains
- GitHub provides OAuth sign-in / identity verification
See the Subprocessors page for the current, authoritative list, and our Data Processing Addendum for the contractual terms that apply to them.
4.2 No sale of personal information
We do not sell, rent, or trade your personal information.
4.3 Legal and business events
We may disclose information if required by law, to protect rights and safety, or in connection with a merger, financing, or acquisition.
5. Data Storage and Security
5.1 Security measures
We use reasonable administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
5.2 Access controls
Access to production systems and user data is limited to authorized personnel who need it to operate the service.
5.3 Incident response
If we become aware of a security incident affecting your personal information, we will investigate and notify affected users when required by law.
6. Data Retention
We keep information only as long as needed for the purposes described in this policy, unless a longer retention period is required by law. These are the concrete periods our systems enforce, including the automated purge job that deletes data once its period expires:
| Audit log (incl. IP addresses) | 12 months, then purged |
|---|---|
| Abuse reports (reporter email + IP) | 12 months, then purged |
| Account / profile data | Deleted on account closure; residual copies in backups are purged within the 7-day point-in-time-recovery (PITR) window |
| Login / CLI verification codes | Minutes to hours (single use, short-lived by design) |
| Product analytics (PostHog) | 12 months |
| Billing records | Approximately 7 years, for tax and accounting compliance |
| Marketing-consent record | Until you withdraw consent |
7. International Data Transfers
Port Zero is based in the United States, and personal data is processed in the United States: our infrastructure runs on DigitalOcean's US region, and our service providers Stripe, SendGrid, and PostHog process data in the US. See the Subprocessors page for the current list and each provider's processing location.
When we transfer personal data of individuals in the European Economic Area or the United Kingdom to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) (and, for UK transfers, the UK's International Data Transfer Addendum) as the transfer mechanism. Details on the safeguards for a specific transfer are available on request; see Contact.
8. Your Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict certain processing.
You can unsubscribe from marketing and product update emails by using the unsubscribe link in those emails. Unsubscribing from marketing does not disable account-related emails needed to operate your account and the service.
You can request account changes or data access by contacting us at support@portzero.net. We may need to verify your identity before fulfilling a request.
If you are dissatisfied with our response, you may also have the right to contact your local data protection authority.
10. Children
The service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has created an account, email support@portzero.net.
11. Changes to This Policy
When we make changes to this policy, we will update the effective date and, when appropriate, notify you by email or in-product notice.
- Minor changes may take effect immediately when the policy is posted
- Material changes may be announced before they take effect
12. Contact
- Privacy inquiries: support@portzero.net
- General support: support@portzero.net
We aim to respond to privacy-related inquiries within 14 days.