- Porta is local-first: SSH workspaces and credentials stay on your device by default.
- Porta does not sell personal information or use it for cross-context behavioral advertising.
- Free features remain available without a Porta account.
- Connections and optional integrations send data only to destinations you choose or enable.
1. Scope and controller
This policy applies to Porta and account, membership, diagnostics, and support services that explicitly identify themselves as Porta services. The data controller or personal information processor is Beyond Matrix; the registered Chinese entity name shown in the app is 上海矩阵之外科技有限公司.
This policy does not govern remote servers, self-hosted gateways, identity providers, app stores, model providers, document services, or other third parties you choose. Their own privacy terms apply to their processing.
2. Current product state
Porta can be used without an account. A build in which account, cloud, or Pro services are not enabled does not send account information to those services. Before a new cloud-backed feature begins collecting data, Porta will identify the feature, the relevant data, and available choices in the product or an updated notice.
A feature being described in this policy does not mean that the feature is available in every build, country, platform, or account tier.
3. Information Porta handles
The categories below describe data Porta may handle when you use the corresponding feature. Porta does not collect every category from every user.
- Local workspace and connection data
- Saved hosts, addresses, ports, usernames, host-key fingerprints, connection preferences, project paths, tmux metadata, snippets, automation definitions, tunnels, SFTP paths and downloads, preview records, agent-work metadata, inbox events, terminal history, logs, and app settings. These records are stored locally by default.
- Credentials and secrets
- Passwords, private keys, passphrases, API keys, and provider credentials that you choose to save. On supported native platforms, Porta uses the app vault and operating-system security facilities. Web or unsupported environments may provide weaker storage guarantees and should not be used for high-risk secrets.
- Account and profile data
- If account services are enabled and you sign in, Porta may receive a provider-specific account identifier and, when supplied by the provider, your display name, avatar, verified email, linked-provider status, session metadata, and account security events. Porta does not need this information for guest use.
- Purchase and entitlement data
- If Pro purchases are enabled, Porta may process store product identifiers, transaction or original-transaction identifiers, purchase time, country or storefront, entitlement state, renewal or grace-period state, and receipt-validation results. Apple or Google processes your payment instrument; Porta does not receive your full card number.
- Commands and content you direct elsewhere
- Terminal input, file content, prompts, snippets, environment information, document content, and generated-command requests are transmitted to the remote host, gateway, model provider, document service, or other endpoint you select when needed to perform your action.
- Optional diagnostics
- Diagnostic sending is off by default. If you enable it and a diagnostics endpoint is configured, Porta may send operation type, status, time, title, summary, error detail, related identifiers, and trace identifiers. These fields may contain hostnames, paths, command fragments, or other sensitive context, so review the setting before enabling it.
- Support communications
- If you contact us, we process your email address, message, attachments, and troubleshooting information you choose to provide. Do not send passwords, private keys, recovery codes, or unredacted production logs.
- Technical and security data
- When online services are enabled, they may receive IP address, request time, app and platform version, language, authentication result, security events, and limited service logs needed to operate, secure, and troubleshoot the service. Porta does not use advertising identifiers for targeted advertising.
4. Device permissions and capabilities
Porta requests a device capability only when the platform or selected feature requires it. You can deny or later revoke optional permissions in system settings, although the related feature may stop working.
- Network and local network
- Used to connect to SSH hosts, gateways, file-transfer targets, account services, model providers, document services, and other endpoints you configure. Remote operators can observe and log traffic that reaches them.
- Notifications and foreground services
- Used to show active-connection, transfer, bridge, or task status and to keep supported operations visible while running. Notification content may reveal host or task context on a locked screen depending on your device settings.
- Biometrics or device credential
- Used to unlock protected vault data. Authentication is performed by the operating system; Porta receives the success or failure result and does not receive your biometric template.
- Microphone and on-device speech recognition
- On supported Android builds, microphone access is used only when you invoke headset voice input. Audio is routed to the device on-device recognizer where available, and Porta receives recognized text. Availability and processing behavior also depend on the installed system speech service.
- Files, downloads, and older Android storage
- Used for files you open, import, export, transfer, download, preview, or install. On older Android versions, a legacy storage permission may be requested for user-initiated file operations.
- USB and package installation
- Optional Android capabilities support serial devices and user-initiated installation of generated preview packages. Porta does not install a package without your action and the operating system confirmation flow.
- Operating-system backup and device transfer
- Depending on platform settings, the operating system may include locally stored Porta application data in cloud backup or device migration. Those copies are controlled by the platform provider and may outlive deletion from the original device. Review your iCloud, Android backup, or device-transfer settings before saving sensitive infrastructure data.
5. Purposes and legal bases
Where a law requires a legal basis, Porta relies on the basis appropriate to the feature and jurisdiction. Withdrawing consent does not affect processing already lawfully completed.
- Provide requested functionality or perform a contract
- To establish connections, save your configuration, authenticate an account, deliver Pro entitlement, restore purchases, and perform actions you request.
- Consent
- For optional diagnostics, optional device permissions, and other processing for which consent is required. You can withdraw consent through Porta or system settings.
- Legitimate interests where permitted
- To secure services, prevent abuse, investigate failures, maintain compatibility, and improve reliability without overriding your rights. We do not rely on legitimate interests for cross-context behavioral advertising.
- Legal obligations and claims
- To comply with tax, accounting, consumer, security, sanctions, and lawful-process requirements, and to establish, exercise, or defend legal claims.
- Protect vital interests and systems
- Where necessary to respond to an immediate security threat, prevent serious harm, or protect users, Porta, or third parties.
6. When data leaves your device
Local-first does not mean that all features are offline. Data leaves your device when you direct Porta to communicate with another system or enable an online service.
- Remote infrastructure
- SSH, SFTP, tunnels, commands, agent tasks, and preview traffic go to your selected host or a gateway you configure. The owner of that infrastructure controls its logs and retention.
- Identity providers
- Google, Apple, GitHub, or X receives an authorization request when you choose that provider. Porta receives only the profile and authorization data covered by the requested scope and provider response.
- App stores and payment services
- Apple or Google processes checkout, tax, refunds, and store account information. Porta may exchange transaction evidence with the store and the account service to verify entitlement.
- Model and document providers
- Prompts, selected context, documents, or generated-command requests go to the endpoint you configure only when you invoke that feature. Do not include secrets unless the provider and task require them and you accept that provider’s terms.
- Diagnostics and support
- Optional diagnostic events go to the configured diagnostics service. Support material goes through the email or support provider you choose when contacting us.
- Legal and organizational events
- Information may be disclosed when reasonably necessary to comply with valid law, protect rights and safety, investigate abuse, or complete a merger, financing, reorganization, or asset transfer subject to appropriate notice and safeguards.
7. No sale or targeted advertising
Porta does not sell personal information, does not share it for cross-context behavioral advertising, and does not use third-party advertising SDKs. If this practice changes, we will update this policy, provide any legally required notice and choice, and will not treat silence as consent.
8. International transfers
Your chosen remote hosts, identity provider, app store, model provider, gateway, or document service may process data in another country. Review the region and terms of each endpoint before sending sensitive data.
Where Porta itself transfers personal information across borders and applicable law requires safeguards, we will use a recognized transfer mechanism, contractual protection, security assessment, certification, or separate consent as required. A production cloud service must disclose its hosting regions and material subprocessors before launch.
9. Retention
Porta keeps information only for the period needed for the stated purpose, subject to legal obligations and the realities of user-controlled devices and third-party systems.
- Local data
- Remains until you delete the relevant record, clear application storage, or uninstall Porta. Operating-system backups and device transfers may retain separate copies under the platform provider’s schedule.
- Credentials
- Remain until you remove them, delete the vault, or erase application storage. Revoking a credential at its issuer or remote host is the safest way to invalidate copies outside Porta.
- Account and profile
- If enabled, retained while your account is active and removed or de-identified after a verified deletion request, except for limited security, transaction, backup, or legal records that must be retained.
- Purchase records
- Store and entitlement evidence may be retained for the account lifetime and longer where tax, accounting, fraud-prevention, refund, or dispute law requires it. App stores retain their own transaction records under their policies.
- Diagnostics
- A production diagnostics service must publish and enforce a defined retention period before collection is enabled. Diagnostic data may be kept longer only for an active security incident, legal obligation, or dispute, and then only as necessary.
- Support
- Retained while a request is active and afterward only as reasonably needed for follow-up, security, quality history, or legal claims. You may ask us to delete support content unless retention is legally required.
10. Your choices and rights
Depending on where you live, you may have rights to know or access, obtain a copy, correct, delete, restrict or object to processing, withdraw consent, request portability, limit sensitive-information use, opt out of sale or sharing, and complain to a supervisory authority. You will not be discriminated against for exercising a privacy right.
- Use Porta without signing in for Free features that do not require an account.
- Turn optional diagnostics, notifications, biometrics, microphone, and other permissions off in Porta or system settings.
- Delete local records inside Porta, clear app storage, or uninstall the app; separately manage platform backups.
- Disconnect a linked identity provider and revoke its authorization with the provider.
- Request account access, correction, export, or deletion through account settings when available or by contacting the privacy address below.
- Cancel an app-store subscription in the store; deleting a Porta account does not necessarily cancel store billing.
11. Requests and account deletion
We may verify your identity and authority before fulfilling a request, ask for only the information needed to verify it, and deny or limit a request where law permits. We will explain a material denial and available appeal or complaint options.
Deleting a Porta account removes account-linked profile and entitlement data that we are not legally required to keep. It does not automatically erase local SSH workspaces, remote-server data, provider accounts, app-store records, operating-system backups, or third-party data. Those must be managed at their respective locations.
12. Security
Porta uses measures appropriate to the feature, which may include operating-system secure storage, biometric or device-credential gates, encrypted transport where supported, host-key verification, access controls, data minimization, and separation of local secrets from UI state. No storage or transmission method is completely secure.
You are responsible for securing your device, reviewing host keys, limiting remote privileges, rotating exposed credentials, and avoiding sensitive data in prompts, logs, screenshots, diagnostics, or support messages. Report a suspected Porta security issue to the contact below.
13. Regional notices
For the European Economic Area, United Kingdom, and Switzerland, the sections above describe the controller, purposes, legal bases, recipients, transfers, retention, and data-subject rights. You may complain to your local supervisory authority.
For California residents, Porta does not sell or share personal information for cross-context behavioral advertising. Subject to the CCPA’s applicability and exceptions, you may request knowledge, access, correction, deletion, limitation of sensitive-information use, and non-discriminatory treatment.
For individuals in mainland China, you may request access, copy, correction, supplementation, deletion, explanation of processing rules, or withdrawal of consent as provided by applicable law. Separate consent and transfer formalities will be used where legally required.
14. Children
Porta is a professional infrastructure and development tool and is not directed to children. Do not create an account or provide personal information if you are below the minimum age to consent in your location without authorization from a parent or legal guardian. Contact us if you believe a child provided account data without proper authorization.
15. Changes to this policy
We may update this policy as Porta, providers, or legal requirements change. The document version and effective date identify the applicable text. Material changes will be presented through a reasonably prominent in-app or service notice before they take effect, and renewed consent will be requested where required.
16. Contact
For privacy questions, rights requests, or security reports, contact tryanswer@gmail.com. Include the app platform, account email if applicable, the right you want to exercise, and enough detail to locate the relevant data. Do not include passwords or private keys.
If applicable law gives you stronger rights than this policy describes, those rights are not limited by this policy.