Privacy Policy
Effective October 6, 2026. Last updated October 6, 2026.
Portal Hound is made by Quill Hound ("we", "us"). This policy covers portalhound.com, buying Portal Hound, the Portal Hound worker and admin apps, and the gateway and control plane we run for customers. It says exactly what we collect, why, how long we keep it, who else handles it, and what you can ask us to do with it.
In short: we collect what we need to sell, build and run Portal Hound and nothing more. We don't use cookies, analytics or advertising trackers. We don't sell or share personal information, and we don't use it to train AI models. Your gateway never decrypts traffic, so we never see what's on the pages your team opens.
Two roles
For our own customers' buyers and contacts (the person who buys, the administrator, anyone who emails us), we decide how the information is used: we are the "controller" or "business".
For your workers and their activity inside Portal Hound (their accounts, devices and access logs), your company decides how that information is used and we process it on your company's behalf: your company is the controller and we are its "processor" or "service provider". Our Data Processing Addendum covers that work. Workers who want to see, correct or delete their information should ask their company; we help the company answer.
What we collect, and why
Visiting portalhound.com
- Request data (IP address, browser, the page asked for, time). Cloudflare, which runs the site, processes it to deliver pages and stop abuse, and our site's request logs keep it for a few days for fixing problems.
- Fonts. Pages load the Inter typeface from Google Fonts, so Google receives your IP address and browser details when a page loads.
- No cookies or tracking. The site sets no cookies and uses no analytics, advertising or tracking tools, so there's no cookie banner. The pricing page remembers nothing between visits.
Buying Portal Hound
- At checkout (Stripe Checkout): your name, email, billing address, tax ID if you give one, company name, company website and how many workers you expect. Stripe collects your card or bank details; we never see or store them. We use this to take payment, work out tax, invoice you and set up your service.
- Your agreement to our terms: which version of the Terms of Service and this policy you accepted, and when, at checkout and on the setup form.
- The setup form: your administrator's name and work email, your company's display name, who workers should contact for help, and optionally your workers' names and work emails and the web addresses of the portals to approve first. We use it to build your gateway, create the accounts and send the invitations.
- The order record holds the above plus your plan, its status and a short history of the build (for example "Provisioning job started"). It is stored in Cloudflare and read by the provisioning job on GitHub Actions.
Downloading the apps
When someone downloads an installer from a company's private download page, we record which page, which file, which version of the terms they accepted, and when. We keep this for three years as a record of acceptance. We don't record who they are.
Using Portal Hound (on your company's behalf)
- Accounts: each worker's and administrator's name, work email, role, Portal Hound ID (like PH01) and status (active, revoked). Passwords are handled by Amazon Cognito; we never see them. With Google Workspace sign-in, Google confirms the person's identity instead.
- Devices: for each computer a worker connects, its name, operating system version, app version, a public key for the secure connection, when it was approved and by whom, and when it last checked in.
- Connection tests: when a worker runs the app's checks, which tests passed or failed (for example "gateway reachable", "personal traffic stays direct"). No browsing history.
- Access log: for each request through the gateway, the time, the worker's Portal Hound ID, their address inside the private tunnel, the destination site name and port, whether it was allowed or blocked, and the size of the response. No page contents, form data, passwords or full web addresses: the gateway never decrypts traffic. Traffic to sites you haven't approved doesn't reach the gateway at all.
- Administrator activity: a record of administrator actions (adding a worker, approving a computer or portal, lockdown) with who did it and when.
- Approved portals: the names and domains your administrators approve. When an administrator asks Portal Hound to find a portal's domains, the control plane fetches that portal's public page.
On the Starter, Team and Business plans we run this for you in a dedicated environment on AWS in the United States (Ohio), separate from every other customer. If your company runs Portal Hound in its own AWS account (Enterprise or a perpetual licence), this information is stored in your account, and we reach it only when you give us access to support or update your deployment.
On the worker's computer
The apps keep the sign-in session and the connection key on the computer, protected by the operating system (Windows Data Protection or the macOS Keychain). The worker app's connection test asks ipify (api.ipify.org) which internet address the computer's ordinary traffic uses, to check that personal browsing doesn't go through the gateway; ipify sees that address. The apps have no analytics or crash reporting.
Emails
We email buyers and administrators about their order: the setup link, "your gateway is ready", account links you ask for, and replies to your messages. Amazon Cognito emails sign-in invitations. These are service emails; we don't send marketing email. If we ever do, it will only be with an unsubscribe link, and we'll honor it.
AI and model training
Portal Hound doesn't send your information to AI or machine-learning services, and we don't use customer data, worker data or access logs to train any model, ours or anyone else's. If that ever changes, we'll ask first; we won't do it without your company's opt-in.
Who else handles it
We share personal information only with the service providers that run Portal Hound for us, listed with what each does on our subprocessor page: Amazon Web Services, Cloudflare, Stripe, GitHub and Google. They may use it only to provide their service to us. We also disclose information when the law requires it, to protect people's safety or our rights, or as part of a sale or merger of the business (the buyer would be bound by this policy).
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have never done so.
How long we keep it
- Orders: while you're a customer. If you delete your account, we remove names, emails, workers and portals from the order at once, and keep only the plan, dates, Stripe references and terms acceptance for up to seven years for tax and accounting.
- Stripe records are kept by Stripe as payment and tax law requires.
- Download acceptance records: three years.
- Gateway access log: 90 days. Control-plane request logs: 14 days. Your company can ask for different periods.
- Accounts, devices, connection tests and administrator activity: while your company's deployment exists; your administrators revoke workers in the console, and we delete any record on your request. When your company leaves, we delete the whole deployment within 30 days.
- Website request logs: a few days. Emails with us: as long as needed to help you, then deleted when no longer useful.
Your rights
Depending on where you live (including California and other U.S. states with privacy laws, and the UK and EU), you can ask us to:
- tell you what personal information we hold about you and give you a copy, in a portable format;
- correct it;
- delete it;
- stop or limit a use of it, or opt out of sale, sharing or targeted advertising (we do none of these).
Buyers can do the main ones themselves on their account page (get the link at portalhound.com/billing): download everything we hold for the order as a file, cancel billing, and delete the account. For anything else, email support@portalhound.com. We'll confirm it's you (usually by replying to the email on the account), answer within 45 days, and won't treat you differently for asking. You can use an authorized agent, and if we refuse a request you can ask us to reconsider by replying to our answer. You may also complain to your local data protection or consumer authority.
If you're a worker, your company controls your Portal Hound records: ask your administrator, or write to us and we'll pass your request to your company.
Security
Each customer has a dedicated gateway, sign-in pool and data store. Data is encrypted in transit, and the AWS data stores are encrypted at rest. Every worker has their own credentials tied to their own computer, administrators approve each computer, and access can be revoked at once. The gateway only reaches approved destinations and never decrypts traffic. No system is perfectly secure; if a breach affects your information we'll tell you, and the affected company, without undue delay.
Healthcare information
The gateway passes encrypted traffic and doesn't see what's on the page, but for healthcare customers we treat the service as handling protected health information where it might, and we sign a Business Associate Agreement with customers who need one. Ask at hello@portalhound.com.
Where it's processed
In the United States. If you're outside the U.S., your information is transferred to and processed in the U.S.; where the law requires it, the Standard Contractual Clauses in our DPA apply.
Children
Portal Hound is a business product. It isn't meant for anyone under 16, and we don't knowingly collect their information.
Changes
When we change this policy we'll update the date above, and for material changes we'll email customers' account contacts before the change takes effect.
Contact
Quill Hound, for Portal Hound: support@portalhound.com.