Legal

Cookie Policy

Last updated October 9, 2026

This policy explains what Portail stores on your device: cookies and similar technologies such as browser local storage. We use no advertising cookies and no analytics or tracking from third parties; the only third parties involved are the ones named below.

1. What we store A cookie is a small file a website saves in your browser. Local storage is a similar browser feature that holds data for a site without sending it with every request. We use both, and we call them "cookies" together in this policy.

2. Strictly necessary storage (always on) This storage is needed to provide the service you asked for, so it does not require consent. (a) Sign-in: your Firebase Authentication session, kept in your browser so you stay signed in. (b) A cookie named portail-auth-hint (1 year, first-party, holds only the value 1) that lets us send signed-in visitors from the home page straight to your chat; it is removed when you sign out. (c) Preferences and data your device keeps so the app works: theme, language, selected model, sidebar state, drafts, notice and tour dismissals, conversation data and settings cached locally (for example when you are signed out), and short-lived sign-up progress in session storage. Firebase Authentication also uses your browser's IndexedDB. (d) Your cookie choice itself.

3. Security and abuse prevention (always on) To stop one person from repeatedly claiming free allowances through new accounts, we store a random installation ID in your browser and send it, together with a coarse device profile (time zone, languages, platform, screen size, processor cores, device memory and touch support), with sign-up and with authenticated requests such as chat. Our server also sees your IP address, from which it keeps only the network prefix, plus your user agent and country. We do not use canvas, audio, font or WebGL fingerprinting. The server stores these signals only as keyed hashes (HMAC), and uses them only for fraud and abuse prevention, which is our legitimate interest in keeping free allowances fair. Hashed does not mean anonymous: the values can still recognize a returning browser or account. Our sign-up form also loads Cloudflare Turnstile, a bot check that may set its own cookies; see Cloudflare's policies for details.

4. Analytics (only if you accept) If you accept analytics, we count anonymous steps of the sign-up funnel and page views (for example landing page views and which sign-up step people reach) and keep a local-storage flag named portail.funnel.seen.v1 so we can tell reloads from new visitors. The data is first-party, aggregated into counts, never sold and never used for advertising. If you reject or ignore the banner, none of this is stored or sent.

5. Third-party services you choose to use If you sign in with Google, Google's sign-in window sets its own cookies. If you buy a plan, checkout is hosted by our payment provider Dodo Payments, which has its own cookie rules. We do not control these cookies.

6. Your choices You can change or withdraw your analytics choice at any time with the Cookie settings link in the footer. You can also clear cookies and site data in your browser settings; this signs you out and resets your preferences. Blocking necessary storage may stop sign-in from working.

7. Contact and updates Questions about this policy: email info@portail.cc. We may update this policy as Portail changes and will change the date above when we do. Our Privacy Policy explains how we handle personal data more broadly.