Last updated: July 28, 2026
This document describes our current practices in plain language. It is not legal advice.
portablemind is operated by Portablemind LLC, 901 Johns Point, Oakland, FL 34787. You can reach us using the details on our contact page.
We collect the following, and nothing beyond what the service needs to work:
We use this information to provide and operate the service, authenticate you, process payments, enforce quotas and usage limits, diagnose problems, keep the platform secure, and respond when you contact us. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Using an AI feature sends the relevant content to the model provider that serves it, so that it can generate a response. Those providers process it on our behalf as subprocessors: Anthropic, OpenAI, Google, Amazon Web Services (Bedrock), and xAI. Which one receives a given request depends on the model selected for your organization.
Your content is not used to train any model — not ours, and not our providers'. It is sent for the sole purpose of serving your request and returning a result.
Where a model runs locally on infrastructure we operate, content is not sent to a third party at all.
Beyond the AI providers above, we rely on a small set of service providers, each acting on our instructions:
We may also disclose information where we are legally required to, or where it is necessary to protect the rights, safety, or property of our users or of Portablemind LLC.
Our web application keeps your session token in your browser's local storage rather than in a tracking cookie. Our public website uses Google Analytics to understand aggregate traffic, which does set cookies. You can block these through your browser settings without losing access to the product.
We keep your account information and content for as long as your account is active. When an account or organization is closed, we delete or anonymize its data within a reasonable period, except where we are required to retain records for legal, tax, or accounting purposes. Backups are retained on a rolling basis and age out on their own schedule.
Credentials and integration secrets are encrypted at rest with authenticated encryption and kept apart from ordinary data. Traffic is encrypted in transit with TLS. API keys and reset codes are stored only as one-way digests and shown once. Each organization is isolated with its own signing keys, access is capability-based and least-privilege, and access decisions are recorded in a tamper-evident audit trail.
No system is perfectly secure, and we do not claim otherwise — but these controls are engineered rather than aspirational. Our security brief describes them in detail.
If you are a California resident, the CCPA (as amended by the CPRA) gives you the right to know what personal information we have collected about you, to request its deletion, to request correction of inaccurate information, and to receive a portable copy. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front. We will not discriminate against you for exercising any of these rights.
To make a request, contact us using the details on our contact page. We will verify your identity before acting on it.
portablemind is a business product and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
We will update this page when our practices change, and revise the date at the top. If a change materially affects how we handle your information, we will make a point of telling you rather than relying on you to notice.
Questions about this policy, or about the information we hold on you, can go to hello@portablemind.ai.