Your space, explained
Privacy.
What you keep, where it lives, and what happens when you share a copy.
Who operates Portal Theory
Portal Theory is owned and operated by Dalton Davis. Privacy and support contact: dalton@mygail.com
Your colors and writing
The current app stores your colors, reflection text, dates and times, optional emotion words, relationships between memories, settings, and garden/sand creations locally on your device. It has no user account or in-app cloud synchronization. Its reflection features do not send your writing to an AI service.
Optional motion
If you choose Tilt and grant permission, the app uses live device orientation to control color selection. The app’s save format does not keep raw motion samples. Selected colors and their positions may become part of your saved memories. You can use touch instead.
Backups and sharing
Export creates a JSON file containing your saved information, including private writing. The app opens your system share sheet so you can choose where it goes. Restore reads a file you select and asks for confirmation before replacing local data. The app does not encrypt these backup files.
Your device’s backup settings and any storage or sharing service you choose may create additional copies under their own policies. This is different from Portal Theory providing automatic cloud sync.
Retention and deletion
Local memories remain until you delete them, reset the app, or the app’s storage is removed. Deleting a reflection does not delete its colors. A restore keeps one earlier local snapshot for recovery; that snapshot may contain writing no longer present in the current collection. The next restore replaces it, and Reset all local data clears both the current collection and the recovery snapshot.
Deleting local data does not delete files you previously exported or copies held in device backups or other services. Manage those separately. Without an available backup, we cannot restore memories lost with an uninstalled app or lost device.
App stores and beta testing
Apple and Google handle their own account, purchase and distribution information. If you participate in TestFlight, Apple may provide beta usage, crash and feedback information to the developer under its TestFlight terms. Do not include private reflections in feedback unless you intend to share them.
Beta invitation requests
When signup is open, we collect your email, iPhone/Android choice, request wording version, and signup/confirmation dates in a private Supabase list. This is separate from app accounts and your memories. Resend delivers the confirmation email. Cloudflare Turnstile checks for bots and processes browser/device signals. These providers have their own privacy practices and may process information outside Canada.
You request a confirmation email and, after confirming, a beta invitation for your selected phone when available. We do not use this request for newsletters, promotions, or launch announcements. Apple or Google receives your email when we invite you through its testing platform. For individual TestFlight invitations, Apple reports acceptance, installation, sessions, crashes and submitted feedback. Website signup does not prove installation.
Use the cancellation link in your confirmation email, or contact dalton@mygail.com, to remove your beta request. Already-sent testing invitations and app accounts are separate; ask us to revoke an invitation, or use the app’s account deletion control when available.
Our daily cleanup removes unconfirmed beta requests after 30 days without a confirmation request, and confirmed list entries after 180 days from confirmation. Provider logs, recovery copies, and testing-platform records follow their own retention policies. This list cleanup does not delete your app account or memories.
This website and support
This site does not add advertising analytics or a journal-upload form. The beta page loads Cloudflare’s security widget when signup is enabled. Render hosts this website through its delivery infrastructure. Serving and protecting the site involves technical request information such as IP addresses, requested pages, and browser information. Provider processing may take place outside Canada. We do not run advertising analytics or keep our own visitor-tracking database. Render controls retention of its infrastructure records under its own policies; our beta-list cleanup does not delete those records. Render’s privacy policy.
If you contact support, your message and contact information are used to respond. Email providers process and store correspondence to deliver that support; their infrastructure and recovery copies may be outside Canada and follow their own retention policies. Please do not send private reflections or full memory backups. We delete routine support correspondence within 12 months after an issue is resolved, unless it is still needed for a dispute or legal obligation. This does not delete your app memories or account.
Changes and questions
Any future account, sync or data-processing feature will require an updated explanation of its data practices. Contact dalton@mygail.com with privacy questions.