← portlkit

Privacy policy

Last updated: September 6, 2026

Who we are

Portlkit provides client portals for freelancers and small studios: one shareable link holding a project's milestones, files, messages, and invoice. This policy explains what we collect and why.

What we collect

Account data. When you create an account we store your email address, your name (if you sign in with Google), and your studio name. Authentication is handled by Supabase; if you use Google sign-in, Google shares your email and basic profile with us and nothing more.

Portal content. The projects, milestones, messages, and files you and your clients put into portals are stored so we can show them to the people you share the link with. Your clients do not create accounts; anything they submit (approvals, messages) is stored against the portal, not a profile.

Payments. Payments are processed by Stripe. Card numbers never touch our servers, and money moves directly from your client to your connected Stripe account — we never hold your funds. We store only the invoice status and Stripe's reference IDs.

Client details you enter. When you add a client's name and email to a portal, we use them only to show the portal and to send the notifications you trigger (new invoice, new file, reminders) on your behalf. That's your client's data — you're responsible for having the right to share it with us, and it's deleted with the portal.

Cookies. Three, all first-party: a session cookie that keeps you signed in, a 10-second cookie that carries "saved"-style confirmations between pages, and a small 90-day cookie that remembers this browser has an account (so the site can show "Log in" instead of "Sign up"). No analytics cookies, no advertising cookies, no cross-site tracking — which is why you don't see a cookie banner here.

If you delete your account, we ask why. That feedback is stored with no name, email, or account id attached — we can't trace it back to you, and we use it only to make Portlkit better.

What we never do

We don't sell your data. We don't show ads. We don't read your portals except when you ask us to (support) or the law requires it.

Your data, your call

You can export your portal content and delete your account at any time — both live in Settings, no email required. If you cancel, your portals go read-only so your clients keep access to what you delivered; deleting your account removes your data from our systems, subject to legal retention requirements for payment records. You can also ask us to access, correct, or delete anything by email, and we'll do it.

Sub-processors

Supabase (database, authentication, file storage), Stripe (payments), Resend (delivers the notification emails — sees the recipient's name, address, and subject line), and Vercel (hosting). Each processes data only to provide their service to us.

Contact

Questions or requests: support@portlkit.com. We answer everything ourselves.