Privacy Policy
Last updated 24 September 2026
This explains what Portveil collects, why, and who else handles it. Short version: we don't log what you browse.
What we don't collect
- The websites you visit, DNS queries, or the contents of your traffic.
- Traffic logs on our exit servers.
What we do keep
- Account: your email address, plan, and Stripe customer ID.
- Devices: the names you give them, their WireGuard public keys, and the private tunnel address assigned to each on each server. Private keys for devices you add in your browser never reach us.
- Connection status: which server a device is on, the time of its most recent WireGuard handshake, and data-transfer counters, kept only as current status (not a history). Exit servers report recent handshakes for up to 10 minutes.
- Activity log: actions on your account (for example "switch server", "device added") and whether they came from you or an API token, so you can audit your agents.
Abuse and legal requests
Because a tunnel address maps to one device, we can tell which account a tunnel address belonged to at the time of an abuse report received while that device still exists. We don't keep traffic records that would show what that device did. We respond to valid legal requests only to the extent the law requires, and only with the data listed above.
Who processes data for us
- Stripe: payments (we never see your card number).
- Hetzner: server hosting in Germany, Finland, and the US.
- Cloudflare: website and API delivery.
- AgentMail: sending and receiving our email.
Retention and deletion
When your subscription ends, your account, devices, tokens, and activity log are deleted. Billing records are kept as tax law requires. You can ask us to delete your account at any time by replying to your welcome email.
Your rights
Depending on where you live (for example under the GDPR), you can ask for a copy of your data, correction, or deletion. Reply to your welcome email and we'll handle it within 30 days.