Privacy Policy
The short version. Porter is a chat assistant that property managers embed on their own websites. We hold the account details of the managers who buy Porter, and — on their behalf — the conversations their renters have with the widget. We do not sell personal information, we do not use advertising or analytics cookies, and we do not train AI models on your data or your renters’ conversations. The rest of this page is the detail behind those sentences.
1. Who we are
[COMPANY LEGAL NAME], a [STATE/COUNTRY OF INCORPORATION] [ENTITY TYPE] trading as “Porter” (“Porter”, “we”, “us”), registered at [REGISTERED MAILING ADDRESS].
Reach us about anything on this page at [email protected].
2. Two different relationships
Porter handles two kinds of people, and the law treats them differently. Reading this policy is much easier once you know which one you are.
- Customers — the property managers and their staff who hold a Porter account. For their data we are the controller: we decide why it is held, and this policy governs it.
- Renters and site visitors — the people who talk to the chat widget on a customer’s website. For their data we are a processor acting on the customer’s instructions. The customer is the controller, their own privacy policy governs that data, and we handle it only as described here and in our agreement with them. If you are a renter and want your conversation deleted, contacting the property manager is the fastest route; write to us and we will pass the request on and support them in answering it.
3. What we collect
3.1 Account data (customers)
- Name, work email address, and the property-management business you sign up on behalf of.
- Authentication material: a hashed password and the one-time codes we email you when you sign in. We never store a code in a form we could later read back to you.
- Your site configuration: widget branding, greeting text, guided-flow questions, escalation contacts, and the list of web origins allowed to load your widget.
- Credentials for your AppFolio reporting API, held encrypted at rest. These are used solely to run the reports your widget answers from.
3.2 Billing data (customers)
Subscriptions run on Stripe. Card numbers are entered directly into Stripe’s own hosted fields and never reach our servers — we hold only the Stripe customer and subscription identifiers, your plan, and the billing status Stripe reports back to us.
3.3 Conversation data (renters)
- The messages exchanged with the widget, and a conversation identifier that ties them together.
- Anything a renter volunteers in a guided flow — typically a name, an email address, a phone number, and their answers to the questions the property manager configured. This becomes a lead, visible to that property manager in their dashboard.
- Property and availability data pulled from the customer’s AppFolio account to answer the question asked.
3.4 Operational data
- An audit log of significant account actions — sign-ins, configuration changes, credential updates — so a customer can see who changed what.
- Usage metering: message counts and model token counts per site, used for billing and for spend alerts.
- Ordinary server logs, including IP addresses, kept for security and debugging.
3.5 Contact form (anyone)
If you use the contact form on this site we collect the name, email address, optional company, and message you type, plus the IP address and browser user-agent the submission arrived with. The message is emailed to our support inbox and stored so an enquiry is never lost to a delivery failure. The IP address and user-agent are kept only to investigate abuse of the form — they are not used to profile you, and there is no analytics or advertising attached to them.
4. What we deliberately do not collect
Data returned from AppFolio is filtered before the AI model or the renter ever sees it. Three independent layers run on every row: rows outside the asking user’s scope are dropped, columns are matched against a per-report allowlist, and a final pass scrubs sensitive values out of free-text fields such as work-order notes and ledger memos. Fields matching Social Security and taxpayer numbers, bank and routing details, account and card numbers, dates of birth, and driver’s licence numbers are removed for every role, including account owners.
We use no advertising cookies, no third-party analytics, and no cross-site tracking. The dashboard keeps your session token in your browser’s local storage, which is strictly necessary to keep you signed in, is not a cookie, is not sent to third parties, and is discarded when you sign out.
5. Why we use it
- To provide the service — answering questions, capturing leads, sending escalation and lead-notification email. (Performance of our contract with you.)
- To report back to the property manager — once a signed-out visitor’s conversation has ended, it is read once to note its topics and any question Porter could not answer, so the property manager can fill that gap. Only short, de-identified questions are kept; residents’ signed-in conversations are never read for this. (Performance of our contract with you.)
- To bill you — metering usage and running subscriptions. (Contract; legal obligation for tax records.)
- To keep the service secure and working — logging, rate limiting, abuse prevention, debugging. (Legitimate interests.)
- To contact you about your account — service notices, spend alerts, security notifications. (Contract; legitimate interests.)
We do not use your data, or your renters’ conversations, for advertising or for profiling unrelated to the service.
6. AI processing
Conversations are answered by a large language model operated by Anthropic. The messages and the redacted property data needed to answer are sent to Anthropic’s API for that purpose. Under Anthropic’s commercial terms that content is not used to train their models. We do not train any model on customer or renter data either.
7. Who we share it with
We do not sell personal information and we do not share it for cross-context behavioural advertising. We disclose it only to the service providers below, each bound to use it solely to provide their service to us:
- Anthropic — the AI model that generates answers.
- Stripe — payments, subscriptions, and card handling.
- Postmark — transactional email delivery (sign-in codes, lead alerts, escalation notices, contact-form enquiries).
- Appwrite — account and identity infrastructure.
- Our hosting provider — servers, storage, and backups.
- AppFolio — the customer’s own property-management system, which we read from using credentials the customer supplies.
We may also disclose data where legally required, or to a successor entity in a merger or acquisition — in which case this policy continues to apply until you are given notice of a new one.
8. Where it is held
Porter is hosted in the United States, and the providers above may process data in the United States and other countries. Where personal data is transferred out of the UK or EEA, that transfer relies on the European Commission’s Standard Contractual Clauses or another approved mechanism.
9. How long we keep it
- Account and site configuration — for as long as your account is open, then deleted within 90 days of closure.
- Conversations and leads — retained for the customer while their account is open, and deleted with the account. A customer can delete individual leads at any time from the dashboard.
- Usage records and funnel events — swept automatically after one year.
- Contact-form enquiries — deleted automatically after one year, or sooner on request.
- Abandoned signups — unconfirmed signups are purged hourly and never become an account.
- Sign-in codes — expire in minutes and are then removed.
- Billing records — kept as long as tax and accounting law requires, typically seven years.
9a. Website demos
Website demos. When you try Porter on a website from our homepage, we read that site’s public pages and, if it links to one, its public AppFolio listings page. We store what we read, the address you entered, your IP address (to limit abuse) and the chat messages you send in the demo. All of that is deleted 72 hours after the demo is created. We keep anonymous usage counts (how many tokens a demo used, with no content and no IP address) for 90 days to track costs. A demo never has access to AppFolio accounts or resident data.
10. Security
Traffic runs over TLS. AppFolio credentials are encrypted at rest. Passwords are hashed, never stored in the clear. The signup page — the one page that touches a payment form — is served under a strict, per-request Content Security Policy, so an injected script cannot draw a fake card field over the real one. Widget requests are checked against a per-site origin allowlist. Access to production is limited to the people who need it, and account actions are written to an audit log.
No system is perfectly secure. If we suffer a breach affecting your personal data, we will notify you and any required regulator without undue delay.
11. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, export it in a portable format, object to or restrict certain processing, and withdraw consent where we relied on it. California residents additionally have the right to know what is collected and disclosed, to delete it, to correct it, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.
We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of.
To exercise any right, email [email protected]. We will verify your identity — usually by confirming control of the account email — and respond within 30 days, or 45 days for CCPA requests where we may extend once with notice. An authorised agent may act for you with written proof.
If you are in the UK or EEA and are unhappy with our answer, you may complain to your local supervisory authority.
12. Children
Porter is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided data through the widget, tell us and we will delete it.
13. Changes
We will post any revised policy here with a new “last updated” date. For material changes affecting customers we will also email the account owner at least 14 days before they take effect.
14. Contact
[COMPANY LEGAL NAME]
[REGISTERED MAILING ADDRESS]
[email protected]
This policy describes how Porter actually works today. It is not legal advice, and it should be reviewed by counsel in your jurisdiction before you rely on it — particularly the bracketed values above, which must be filled in before launch.