P Policy
Privacy, by route.
Effective August 28, 2026
Porter is local-first. We do not receive your journal, bookmarked URLs, handoff files, or encryption passphrase.
What the extension stores
The extension stores an encrypted vault in your browser’s extension storage. The vault contains only workspace names, task titles, notes, status values, and URLs that you explicitly add. Encryption uses AES-256-GCM with a key derived from your passphrase using PBKDF2-SHA-256. Your passphrase is held in browser session storage so it disappears when the browser session ends.
Browser permissions
Porter uses extension storage, the active tab, and optional per-origin permissions. It asks for an origin only when you choose “Use this tab.” It reads the URL you chose; it does not read page content, model transcripts, keystrokes, or browsing history.
Exports and sidecar
Encrypted JSON exports are created on your device. Readable Markdown exports are deliberately unencrypted and display a warning before creation. The optional sidecar listens only on 127.0.0.1 and writes the encrypted envelope beneath the workspace directory you choose. It rejects requests from ordinary web origins.
Licenses and payments
If you buy or restore Team Relay, your browser stores the license token locally and sends it to the Sociobot billing API for verification at most once per day. Sociobot/Dodo is the merchant of record and processes checkout and refunds. We do not embed card fields or receive card details. Their service may process the network information needed to prevent fraud and complete a transaction.
Website data
This site includes no analytics, advertising pixels, third-party fonts, or social trackers. Static hosting may retain short-lived security and access logs such as IP address, request path, and user agent.
Deletion and control
Remove the extension to delete its local browser storage, and delete exported files wherever you saved them. To remove a sidecar copy, delete .workspace-history-porter/handoff.json from that workspace. A refunded purchase automatically revokes its license.
Contact
For privacy questions or deletion help, open an issue in the project repository. Because journals never reach us, we cannot recover or delete a journal on your behalf.