Privacy Policy

Last updated 2 October 2026 · Effective 25 September 2026

The short version. Porter is a chat assistant that property managers embed on their own websites. We hold the account details of the managers who buy Porter, and — on their behalf — the conversations their renters have with the widget. We do not sell personal information, we do not use advertising or analytics cookies, and we do not train AI models on your data or your renters’ conversations. The rest of this page is the detail behind those sentences.

1. Who we are

[COMPANY LEGAL NAME], a [STATE/COUNTRY OF INCORPORATION] [ENTITY TYPE] trading as “Porter” (“Porter”, “we”, “us”), registered at [REGISTERED MAILING ADDRESS].

Reach us about anything on this page at [email protected].

2. Two different relationships

Porter handles two kinds of people, and the law treats them differently. Reading this policy is much easier once you know which one you are.

3. What we collect

3.1 Account data (customers)

3.2 Billing data (customers)

Subscriptions run on Stripe. Card numbers are entered directly into Stripe’s own hosted fields and never reach our servers — we hold only the Stripe customer and subscription identifiers, your plan, and the billing status Stripe reports back to us.

3.3 Conversation data (renters)

3.4 Operational data

3.5 Contact form (anyone)

If you use the contact form on this site we collect the name, email address, optional company, and message you type, plus the IP address and browser user-agent the submission arrived with. The message is emailed to our support inbox and stored so an enquiry is never lost to a delivery failure. The IP address and user-agent are kept only to investigate abuse of the form — they are not used to profile you, and there is no analytics or advertising attached to them.

4. What we deliberately do not collect

Data returned from AppFolio is filtered before the AI model or the renter ever sees it. Three independent layers run on every row: rows outside the asking user’s scope are dropped, columns are matched against a per-report allowlist, and a final pass scrubs sensitive values out of free-text fields such as work-order notes and ledger memos. Fields matching Social Security and taxpayer numbers, bank and routing details, account and card numbers, dates of birth, and driver’s licence numbers are removed for every role, including account owners.

We use no advertising cookies, no third-party analytics, and no cross-site tracking. The dashboard keeps your session token in your browser’s local storage, which is strictly necessary to keep you signed in, is not a cookie, is not sent to third parties, and is discarded when you sign out.

5. Why we use it

We do not use your data, or your renters’ conversations, for advertising or for profiling unrelated to the service.

6. AI processing

Conversations are answered by a large language model operated by Anthropic. The messages and the redacted property data needed to answer are sent to Anthropic’s API for that purpose. Under Anthropic’s commercial terms that content is not used to train their models. We do not train any model on customer or renter data either.

7. Who we share it with

We do not sell personal information and we do not share it for cross-context behavioural advertising. We disclose it only to the service providers below, each bound to use it solely to provide their service to us:

We may also disclose data where legally required, or to a successor entity in a merger or acquisition — in which case this policy continues to apply until you are given notice of a new one.

8. Where it is held

Porter is hosted in the United States, and the providers above may process data in the United States and other countries. Where personal data is transferred out of the UK or EEA, that transfer relies on the European Commission’s Standard Contractual Clauses or another approved mechanism.

9. How long we keep it

9a. Website demos

Website demos. When you try Porter on a website from our homepage, we read that site’s public pages and, if it links to one, its public AppFolio listings page. We store what we read, the address you entered, your IP address (to limit abuse) and the chat messages you send in the demo. All of that is deleted 72 hours after the demo is created. We keep anonymous usage counts (how many tokens a demo used, with no content and no IP address) for 90 days to track costs. A demo never has access to AppFolio accounts or resident data.

10. Security

Traffic runs over TLS. AppFolio credentials are encrypted at rest. Passwords are hashed, never stored in the clear. The signup page — the one page that touches a payment form — is served under a strict, per-request Content Security Policy, so an injected script cannot draw a fake card field over the real one. Widget requests are checked against a per-site origin allowlist. Access to production is limited to the people who need it, and account actions are written to an audit log.

No system is perfectly secure. If we suffer a breach affecting your personal data, we will notify you and any required regulator without undue delay.

11. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, export it in a portable format, object to or restrict certain processing, and withdraw consent where we relied on it. California residents additionally have the right to know what is collected and disclosed, to delete it, to correct it, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.

We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of.

To exercise any right, email [email protected]. We will verify your identity — usually by confirming control of the account email — and respond within 30 days, or 45 days for CCPA requests where we may extend once with notice. An authorised agent may act for you with written proof.

If you are in the UK or EEA and are unhappy with our answer, you may complain to your local supervisory authority.

12. Children

Porter is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided data through the widget, tell us and we will delete it.

13. Changes

We will post any revised policy here with a new “last updated” date. For material changes affecting customers we will also email the account owner at least 14 days before they take effect.

14. Contact

[COMPANY LEGAL NAME]
[REGISTERED MAILING ADDRESS]
[email protected]

This policy describes how Porter actually works today. It is not legal advice, and it should be reviewed by counsel in your jurisdiction before you rely on it — particularly the bracketed values above, which must be filled in before launch.