Portfloor

Privacy Policy

Last updated September 14, 2026

This notice explains how the operator of Portfloor handles personal information when you sign in, create cards, generate images or share collections. Contact support@portfloor.com with privacy questions or requests.

1. Information we handle

2. Why we use it

We use this information to authenticate you, save and display cards, generate requested images, operate sharing, apply plan limits, manage subscription access, prevent abuse and respond to support or legal requests. Where GDPR applies, our bases are performance of our contract for requested services, legitimate interests in maintaining security and handling support and claims, and legal obligations where applicable. Where processing requires consent, we request it separately and you may withdraw it without affecting prior lawful processing.

3. Public and private content

New Free cards are public on Explore. Plus offers public or private cards, and existing private cards remain private. Explore displays the card image, title and category, including visible text within the image; it does not publish your account email or separately stored financial details.

Collection sharing is a separate setting. Enabling a collection link makes the collection's cards and their details available to anyone with that link, including cards that are not individually listed on Explore. The value controls determine whether stored monetary values are included. They cannot hide text already embedded in an image or information you type into a story. Disable collection sharing to invalidate its link. Removing public access cannot recall copies others have saved.

4. Providers and disclosures

Providers process information under their applicable agreements and privacy policies. We may also disclose information when legally required, to investigate abuse or protect rights, or as part of a business transfer subject to applicable privacy protections. We do not sell personal information or share it for cross-context behavioral advertising. We do not train our own AI models on your cards; this does not promise that every external provider has identical retention or data-use rules.

5. Cookies and browser storage

We use authentication cookies to keep you signed in and browser storage to remember your theme and preserve unfinished drafts. Login sessions are configured to expire after seven days and may refresh during use. You can clear browser storage or block cookies, but doing so may sign you out or remove local drafts. The current application does not include advertising trackers.

6. Retention and deletion

Account and saved-card information is retained while needed to provide your account and chosen features. You can delete cards in the service and request account deletion by email. Deleting a card is not the same as deleting every associated generation or billing record: job history and usage records may remain to operate allowances, prevent trial abuse and resolve failures. Billing, security and legal records may be retained where needed for their purpose or applicable obligations. We assess retention according to account status, the purpose of each record, outstanding disputes and legal requirements. Backups and provider copies may follow separate retention cycles; deletion is not a promise of immediate erasure from every system.

7. Your choices and rights

Depending on your location, you may request access, correction, deletion, a copy of your information, restriction of processing or objection to processing based on legitimate interests. You may also withdraw consent where used and complain to your local data protection authority. Email support with your account email and request; we may verify your identity and respond within applicable legal deadlines. Do not send passwords or full payment details. We do not make decisions producing legal or similarly significant effects solely through automated profiling.

8. International processing and security

Our providers may process information outside your country, including in the United States. Applicable transfer requirements may require approved safeguards such as standard contractual clauses or a recognized adequacy arrangement. Contact us for information about the safeguards relevant to your data. We use access controls and secure connections where configured, but no storage or transmission system is completely risk-free.

9. Children and changes

Portfloor is not directed at children under 13. Where a higher local age or parental authorization requirement applies, it must be met. Contact support if a child has provided information without required authorization so we can investigate and take appropriate action. We update this notice when practices change and provide additional notice where required for material changes.