PortaTR·EN

Privacy

Last updated: June 12, 2026 · Questions: [email protected]

What data do we process?

Account data: your email address and session info (via our authentication provider, Supabase).

Usage data: the channels you add to your watchlist, your discovery queries (topic, brand/client name, seed channels), your feedback signals, outreach pipeline notes, and the reports you generate — stored so the product works.

Brand/client info: your white-label settings (brand name, logo, color) and the client brand names you enter during discovery are kept tied to your account only.

Payment data: payments are processed by Stripe; your card details are never stored on our servers.

Third-party services and data sharing

AI analysis: Anthropic (Claude). Analysis requests INCLUDE the relevant public channel/video titles and metrics, plus your discovery topic or the brand/client name you entered and (if enabled) public marketing text fetched from the brand's website. This data is sent only to analyze that request; it is not used to train models.

Web context: Firecrawl — used only in brand mode, to fetch marketing text from the brand's own public website (optional; not used if disabled).

Infrastructure: database and authentication on Supabase (EU region); report emails via Resend; payments via Stripe. We do not sell or rent your data to third parties for advertising.

Porta uses YouTube API Services. By using it, the Google Privacy Policy (policies.google.com/privacy) also applies. The YouTube data processed is limited to public channel/video metrics; no viewer personal data is collected.

Recommendation engine and aggregate signals

To improve discovery ranking, we use AGGREGATE, anonymous signals of all users marking a creator as “relevant / contacted / collaborated.” These signals reflect which creators are positively rated (at the channel level); they do not share client identity, notes, or which agency made the mark.

Practical effect: your positive feedback may slightly influence other users' ranking, and theirs yours. Your discovery result cache and brand research context, however, are private to your account; other users cannot access them.

Cookies and local storage

We use the strictly necessary session cookies set by our authentication provider (Supabase) to keep you signed in, and a 'locale' cookie to remember your language preference. These cookies are required for the product to work; we do not use advertising or third-party tracking cookies.

You can view, block, or delete cookies in your browser settings; however, without the strictly necessary session cookies you cannot sign in.

Retention and deletion

To delete your account or your data, just email [email protected]; once we receive your request we delete your account and all data we hold within 30 days, and can provide an export beforehand if you wish.

Channel metric caches (~1 day), brand context caches (~30 days), and discovery records (~30 days) are auto-deleted at expiry. The YouTube data we process is limited to public channel/video metrics; we refresh it daily and delete any snapshots older than 30 days.

We do not use a Google authorization (OAuth); we access only public data via an API key, so there is no Google access of ours to revoke. You can still review and remove any app's access to your Google data at any time at https://myaccount.google.com/connections.

Your rights (KVKK / GDPR)

You have the right to access, correct, delete, object to the processing of, and port your data. Use the contact address below for requests.

Privacy · Porta