Legal
Privacy policy
What we collect, why we have it, who else can see it, and how long it lives. The numbers below are the retention constants in our own source code, not round figures — the same inventory the security whitepaper documents.
Scope
This policy covers Portcullis — the marketing website at portculliswp.com and the Portcullis product at dash.portculliswp.com. It does not cover your own WordPress sites, which remain yours to run, nor the AI client you choose to connect.
Two roles are worth separating. For your account — your email, your billing, your audit trail — we decide what to collect, so we’re the controller. For the content on your WordPress sites that flows through an action you run, we act on your instruction and are a processor for you.
What we collect
There is no line in this table you didn’t cause. We don’t buy data, we don’t enrich profiles, and we don’t build a picture of you from anywhere but your own use of the product.
| What | Detail | How long |
|---|---|---|
| Account identity | Your email address, an optional display name and avatar, plus your organization’s name and timezone. | Until the organization is deleted |
| Sign-in records | A SHA-256 hash of each emailed sign-in link — never the link itself — and a session record. Sign-in and sign-out events additionally record an IP address and a truncated user-agent string. | Links: 15 minutes, single-use. Sessions: 7 days. Sign-in audit events: 12 months. |
| Second-factor enrolments | If you add one: an authenticator seed, encrypted at rest; a passkey’s credential id, its public key and signature counter — never a private key, which stays on your device; and SHA-256 hashes of your recovery codes, never the codes themselves. | Until you remove the factor or the organization is deleted |
| Client records | If you group sites by the client they belong to: the client name, an optional contact, internal notes, and which sites belong to it. Notes are never printed on a client report. | Until you delete the client or the organization |
| Connected site records | The normalized URL of each WordPress site you connect, the service-user login on it, and the allowlist of abilities you permitted. No WordPress credential of any kind — we never hold one. | Until the site is disconnected |
| Site snapshots and screenshots | Page title, favicon, WordPress version and a last-reached timestamp parsed from your site’s public /wp-json/ root, plus a homepage screenshot. Organization logos and user avatars you upload. | Overwritten on refresh; deleted with the site or organization |
| Audit events | Who did what, on which site, with what outcome — the governance record the product exists to produce. | 12 months, pruned daily |
| Assistant conversations | If you use the dashboard assistant: your messages and what each tool returned. Optional — the product works without it. | 90 days, pruned daily |
| Job and schedule records | The plan you approved for a bulk or scheduled run and each site’s outcome. | Until the organization is deleted |
| Billing details | A Stripe customer id, subscription id, plan name and site cap. Card number, expiry and CVC are entered on Stripe’s own pages and never reach us. | Until the organization is deleted, subject to tax record-keeping |
| Enquiries | If you email us or use a form on this site: your address and whatever you chose to write. | As long as needed to answer, then periodically cleared |
| Marketing-site analytics | Aggregate visit data from this website only — pages viewed, referrer, approximate location from IP, device and browser type. See Cookies & analytics below. | Per Google Analytics settings; up to 14 months |
One thing we structurally cannot collect: a WordPress password or application password. Portcullis holds no credential for your sites at all — they hold only our public key. There is nothing in our database that could be stolen and replayed against your fleet.
Cookies and analytics
The split here matters more than the list, so it’s stated first: the product loads no third-party analytics, advertising, or session-replay scripts. Nothing watches you while you work. Analytics run on the marketing website only.
- Essential — the product. Signing in to the dashboard sets one session cookie. It is HTTP-only, secure, scoped to the dashboard host alone, and lasts 7 days. Without it there is no way to stay signed in, so it isn’t optional and isn’t used for anything else. Signing out revokes the session rather than merely clearing the cookie.
-
Analytics — this website, and only if you accept. We use
Google Analytics 4, loaded through Google Tag Manager.
These set cookies (typically
_gaand_ga_*) to tell a returning visit from a new one. We use them to see which pages get read and where visitors arrive from — nothing more granular, and no advertising or remarketing audiences.
Nothing non-essential loads until you say yes. Analytics storage starts denied for every visitor in every country — we don’t guess at your location to decide whether you deserve to be asked. Rejecting is one click, exactly like accepting, and no cookie is set either way beyond the record of your own choice. You can change your mind at any time with the link in the footer.
Advertising signals are denied permanently and don’t flip when you accept, because we run no advertising or remarketing cookies at all. If your browser sends Global Privacy Control or Do Not Track, we treat that as a decision already made — analytics stay off and you’re never asked. Any content blocker or Google’s opt-out add-on works too. IP addresses are anonymized by Google Analytics 4 before storage, and we have not enabled Google Signals or ads personalization. Every page here works identically whichever you choose.
Why we process it
- To provide the service you asked for. Signing you in, reaching the sites you connected, running the actions you approved. This is contractual necessity.
- To keep the audit trail. A governance product that couldn’t say who did what wouldn’t be one. This is our legitimate interest, and yours.
- To bill you. If you’re on a paid plan. Contractual necessity.
- To keep the service secure. Rate limits, sign-in records, abuse investigation. Legitimate interest.
- To understand our own website. Aggregate analytics on the marketing site — on your consent, which you give and withdraw from the banner and can revisit any time.
We do not sell personal data, we do not share it with advertisers, and we do not use your fleet content or conversations to train any model.
How long we keep it
Retention is enforced by code, not policy — a daily job prunes audit events past 12 months and conversations past 90 days whether or not anyone remembers to. Per-item periods are in the table above. Two are worth restating because they’re unusually short by design: the token that actually reaches your WordPress site lives about 60 seconds and is never written down anywhere, and an emailed sign-in link is stored only as a hash, is single-use, and expires in 15 minutes.
Deleting your organization is a real delete, not a flag. Backups taken by our infrastructure provider may retain a copy briefly until they age out on their own schedule.
Your rights
- Access and portability
- Your audit log is exportable as CSV or JSON from the dashboard at any time. For anything else, ask and we’ll send it.
- Correction
- Account and organization details are editable in the dashboard. Email us for anything you can’t reach.
- Deletion
- Disconnecting a site removes its record and per-member assignments immediately. Deleting an organization cascades every row that belongs to it — sites, snapshots, audit events, conversations, job history, billing, memberships — and removes its images from object storage.
- Withdrawing consent
- Marketing-site analytics only run if you accepted them, and the Cookies link in the footer takes the choice back as easily as it was given. You can also decline the optional assistant entirely without losing the rest of the product.
- Complaint
- If you’re in the UK or EEA you may complain to your local supervisory authority. We’d rather you came to us first.
To exercise any of these, email hello@portculliswp.com from the address on your account. We aim to respond within 30 days and we don’t charge for it.
Security
The full detail — threat model, key management, tenant isolation, incident response, and an explicit list of what we don’t have — is in the security whitepaper. The short version relevant here: we hold no WordPress credential to leak, tokens are stored only as hashes, every tenant read is scoped to one organization at a single chokepoint, and we publish our gaps rather than waiting for you to find them.
If you believe you’ve found a vulnerability, email hello@portculliswp.com. We’ll acknowledge it and we won’t pursue anyone acting in good faith.
International transfers and children
Portcullis runs on Cloudflare’s global network, so data may be processed in any country where it operates. You cannot currently pin your data to a particular region — we’d rather say that plainly than imply a residency guarantee we don’t offer. Our processors operate under standard contractual clauses or an equivalent transfer mechanism where one is required.
Portcullis is a tool for people who administer websites. It isn’t directed at children, and we don’t knowingly collect data from anyone under 16.
Changes and contact
If we change this policy we’ll update the effective date above, and for anything that materially changes what we collect or who sees it we’ll email account holders rather than quietly editing the page.
Questions, requests, or a compliance review: hello@portculliswp.com. See also the terms of service and the security whitepaper.