Last updated: June 2026
Account data: Email address and hashed password when you create an account. We never store passwords in plaintext.
Age attestation data: When you confirm you are 18 or older, we store a record containing: a pseudonymised (cryptographically hashed) version of your IP address and browser identifier, your approximate region (country and, where applicable, state), the exact attestation text and Terms version you accepted, and a timestamp. We cannot recover your raw IP address from this record. Where identity-based age verification is required by your local law, verification will be handled by a third-party provider — we will not receive, store, or process identity documents, biometric data, or facial scans.
Region data: Your country (and state, where applicable) is determined from your IP address on every request to enforce regional availability. This determination is not stored except as part of the age attestation record above.
Usage data: Interactions such as likes, saves, comments, and video views for the purpose of providing the Service.
Analytics & attribution data: We operate our own first-party analytics. We record anonymous usage events (for example pages viewed, how far you scroll the feed, and steps of the signup and checkout flow) tied to a first-party identifier stored on your device, and — where present in the link you arrived from — the marketing campaign parameters (UTM tags) and referral/click identifiers that indicate which channel or campaign referred you. This data stays with us, is processed on our own infrastructure, and is never sold or shared with advertisers. You can turn this off at any time by choosing "Essential only" in the cookie banner. Once you create an account, these events may be associated with your account so we can understand and improve the Service.
Card-payment waitlist: If you ask to be notified when card payments become available, we store the email address you provide (and the plan you were interested in) solely to send you that one notification and to measure demand for card payments. This is based on your consent and you may ask us to delete it at any time.
Session data: Session tokens stored in HttpOnly cookies for authentication.
Payment data: Processed entirely by our payment providers (for cryptocurrency payments, NOWPayments; for card payments where available, a PCI-DSS-compliant card processor). We do not receive or store card numbers, CVVs, billing addresses, or wallet private keys. We receive confirmation of payment status, the order reference, and — for crypto payments — the public blockchain transaction identifier.
Technical data: IP address, browser type, and device information collected automatically for security and service operation.
We process your data on the following legal bases under GDPR Article 6:
We use the following cookies and similar first-party storage:
We do not use third-party advertising or cross-site tracking cookies, and we do not embed third-party analytics or advertising pixels (such as Google Analytics or the Meta Pixel). Our analytics are first-party and processed on our own infrastructure. If this changes, we will update this policy and, where required, request your consent.
We share personal data only with:
We do not sell personal data. We do not share data with advertisers. We will disclose data if required by law or valid legal process.
Account data is retained for the lifetime of your account. When you delete your account, we delete your personal data within 30 days, except where retention is required by law (e.g., tax records retained for 7 years under Swedish law).
Age attestation records are retained after account deletion (with the link to your account removed) because we are legally required to be able to demonstrate that age assurance was performed. These records contain only pseudonymised identifiers and cannot be traced back to you without the cryptographic key.
Session data expires automatically after 30 days of inactivity.
Under GDPR, you have the right to:
To exercise any of these rights, contact us at hello@portality.co. We will respond within 30 days.
Your data is primarily stored in the EU/EEA. Where data is transferred outside the EU/EEA (e.g., to US-based service providers), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or adequacy decisions.
We implement appropriate technical and organizational measures to protect your data, including encrypted connections (TLS), hashed passwords (bcrypt), HttpOnly session cookies, and access controls.
The Service is strictly for users aged 18 and over. We do not knowingly collect data from minors. If we discover that a minor has created an account, we will delete it immediately.
We may update this Privacy Policy from time to time. We will notify you of material changes via the Service or email.
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the supervisory authority in your EU/EEA member state.
Data Protection Contact: hello@portality.co — see also our contact page.
Portality AB, Sweden