Privacy Policy for the porthor App

Last updated: 11 September 2026 · Deutsche Fassung

This is a translation of the German original. In case of doubt, the German version applies.

1. Scope

This policy applies to the porthor desktop application for Windows, macOS and Linux. It describes which personal data the application processes, to whom data is transmitted, on what legal basis this happens, and how long the data is stored.

A separate policy applies to visiting the porthor.de website: privacy policy of the website (German). Where processing overlaps (purchase, newsletter), this page refers to that policy.

2. Controller

menosgada Service GmbH
represented by its managing director Stefan Holhut
Bahnhofstr. 64
96231 Bad Staffelstein, Germany
E-mail: service@porthor.de

No data protection officer has been appointed. The conditions of sec. 38 BDSG (German Federal Data Protection Act) are not met. We answer data protection questions at the address above.

3. Core principle: processing happens on your device

porthor is a locally installed application. Opening and analysing documents, redacting, pseudonymising, text recognition (OCR) and the detection of names, addresses and other personal details (NER) run entirely on your device. The models required for this ship with the application, work without network access and are not downloaded later.

The same holds for the models that porthor 3 additionally brings along, such as the one for obscuring faces and licence plates in images. They sit on your device as part of the installation package. At runtime porthor downloads no model from the network; if one is not installed, the application says so and the feature stays off.

One exception, which we name openly: dictation in the AI assistant does not work on your device. To be turned into text, the audio recording goes to the provider you have bound for that purpose, in the original, because a recording cannot be pseudonymised beforehand. This is switched off until you allow it, and it then asks for your consent for every single recording. Details in section 4.7.

It holds for search as well: the full-text search across all folders and the pulling of matching passages for a question to the AI run entirely on your device. Neither a search index nor your search terms leave it.

E-mail: two different routes. The e-mail import reads stored message files (.eml, .msg) that sit on your device; no connection arises in the process. To be distinguished from it is mounting a mailbox (porthor Automate): if you set that up, porthor signs in to your mail server and fetches messages. That is the only e-mail connection, and it is set out in section 4.5. Without that setup it does not take place.

Documents and their contents are at no point transmitted to us or to third parties. The mapping table between the real details and the pseudonyms also stays exclusively local, in your working folder. We have no access to it and cannot resolve pseudonyms.

Your working folder stays your working folder. porthor moves into the folder structure you show it; it copies, moves and renames nothing in the process. What porthor stores itself sits in a subfolder of its own, .porthor (section 7). A folder you place on a shared drive is readable by everyone who has access to that drive; that is down to the permissions of your file system, not to porthor.

The application contains no telemetry, no advertising identifiers and no automatic crash reporting. It does not access camera, location, contacts or calendar; it accesses the microphone only when you have allowed dictation in the settings and started a recording yourself (section 4.7). porthor counts how often you used which feature for your own overview; these counters stay on the device (section 7).

Notices on your screen. porthor shows tasks, deadlines and reminders as cards inside the application and, if you switch that on, as a notice from your operating system. These notices are created on your device and are displayed there: there is no push service, no external notification network and no transmission to us.

The orchestration of multi-step flows — an interview that asks for missing mandatory details, for example — is handled by a program library that ships with the application. Its built-in usage measurement is removed and switched off in porthor; it cannot establish a connection. The intermediate state of a flow sits as a file in the folder concerned.

Who is responsible for the document contents. The controller for the processing of the document contents is the respective user, or the organisation within whose sphere of responsibility porthor is used. Someone using porthor at work is as a rule not the controller themselves; the controller is the body that decides on the purposes and means of the processing, usually the employer. We are responsible for the connections described in section 4, not for the contents edited with the application.

On your device, porthor stores only what is necessary for the functions you have requested (section 7). The application reads no further information from your terminal equipment (sec. 25(2) no. 2 TDDDG).

4. Connections the application makes

The following list is complete. The application makes no other outbound connections. Links you click inside the application (for example to the pricing page or to booking an appointment) open in your browser; the policy of the respective site applies to those.

4.1 Checking for updates and news

Trigger Two separate requests with separate switches:
Updates. Only if you have switched the check on. It is off as shipped; the application asks about it during initial setup. The switch is labelled „Automatisch auf Updates & News prüfen" and sits in the settings under „Updates".
News. The application loads the list of product messages when you open it, then every six hours and whenever you return to the window, and shows them under „Benachrichtigungen" (notifications). This request is on by default and can be switched off in every licence tier in the settings under „Updates". The notice about a new program version does not depend on that switch; it belongs to the update check above. If a message contains a video, the application additionally loads the corresponding still image from our server — including for videos hosted on YouTube: our server fetches the still image there once and serves it from its own address. Opening the application therefore contacts neither YouTube nor Google. That only happens when you click a video; it then plays in a separate porthor window via youtube-nocookie.com, in a session that ends when the window closes.
Recipient Primarily our own server lizenz.porthor.de (Germany). If it does not answer, the application falls back to GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA via api.github.com and raw.githubusercontent.com. Still images for videos come exclusively from our own addresses.
Data transmitted A read-only request for the version and news list, without sign-in. Neither a device identifier nor any account reference is sent. Operating system and processor architecture are sent so the answer can name the matching installer, as is the program version. The news request additionally carries the occupational role you selected, as a keyword (such as „hausverwaltung"), so that you only receive messages relevant to your work — a category, not a statement about you as a person. Your licence tier is not transmitted; the application sorts by it on your device. For technical reasons the recipient also sees your IP address.
Purposes Informing you about available updates, in particular security updates. And: displaying product news — including new features and skills, explanatory videos, and pointers to paid extensions. The news are therefore also the channel through which we promote and finance the free offering.
Legal basis For the update request: your consent, Art. 6(1)(a) GDPR, given by switching it on. You may withdraw it at any time with effect for the future by switching it off again.
For the news request: our legitimate interest in informing users about further developments and paid extensions, Art. 6(1)(f) GDPR (recital 47). You may object at any time (Art. 21 GDPR) — the switch in the settings is enough, whichever licence you use.
The access logs created on our server in the process have their own basis: our legitimate interest in secure and stable operation, Art. 6(1)(f) GDPR.
Transfer to a third country Only in the fallback case, to GitHub in the USA. To the extent that GitHub is effectively listed under the EU-US Data Privacy Framework for this processing, the transfer is based on the adequacy decision of the European Commission (Art. 45 GDPR). No third-country transfer takes place in the regular case via our own server.
If you click a YouTube video, that request transmits your IP address to Google Ireland Limited or Google LLC in the USA — on the same basis (Art. 45 GDPR), to the extent Google is effectively listed for this processing. Without that click it does not happen: still images are fetched by our server, not by your application.
Storage period We store no user data about this request. Access logs are created on our server (IP address, time, requested resource); we delete them after 14 days. GitHub's own policy governs storage at GitHub.

4.2 Account and licence management

Trigger At initial setup and after that whenever you sign in or activate or manage a licence. Initial setup requires your e-mail address — for the free porthor Free as well. There is no password: you confirm your address through a link we send you. Once you are signed in, the application revalidates the licence once a day. That check does not depend on the switch in section 4.1: a licence cannot be verified without contact to the licence server.
If no connection can be established, porthor keeps working. The basis for that is a signed proof issued by the licence server and held on your device; it carries a fixed validity of 14 days. If a due payment is outstanding, an additional grace period of 7 days applies, during which your access remains unchanged. Only after that does porthor fall back to the free scope (watermark in the PDF export); it never locks itself completely, and your documents remain accessible in every case.
Recipients The data goes to our own licence server at lizenz.porthor.de. The following processors within the meaning of Art. 28 GDPR are involved:
  • netcup GmbH, Karlsruhe, for server operations. The server is located in a data centre in Germany.
  • Brevo (Brevo SA, Paris; the contracting party in Germany is Brevo GmbH) for sending the account and licence e-mails. Details in the website policy, section 4.
A data processing agreement under Art. 28 GDPR is in place with both providers, binding them to our instructions. Beyond these processors we do not pass the data on, except where we are legally obliged to.
Data transmitted
  • your e-mail address, which is your sign-in; porthor works without a password and without licence keys, sign-in happens through a link sent by e-mail
  • profile details, as far as you enter them: form of address and title, first and last name, company, phone number, postal address, signature for generated letters
  • a random device identifier generated by the application, one per device; no hardware identifier, no device name
  • program version, operating system and processor architecture
  • evidence of your consents (time and version of the notice)
  • licence and order data from the purchase, including the billing address
  • when changing the account e-mail and when moving a licence: the old and the new address with the time
  • for team licences: the e-mail address and role of the person you invite to a seat
  • if you subscribe to or cancel the newsletter inside the application: your decision with the time
  • the events „download clicked" and „update installed" with the version concerned
  • for team licences exclusively the addresses that belong to that licence: the holder's and those of the seats you invited yourself. porthor reads no address book and no directory service and adds no addresses of its own accord

Reporting the program version. The daily licence check, signing in and activating a device each carry program version, operating system and processor architecture; the application sends the same three details to the endpoint for program events when you click a download or an update has been installed. They show us which program versions are in use and let us recognise outdated versions that lack security fixes. This reporting is tied to your sign-in — without signing in it does not take place, and the anonymous request described in section 4.1 does not contain it.

Not transmitted: documents, document contents, redaction results, mapping tables, your AI access key, your device name and hardware identifiers.
Purpose Sign-in, verification of licence entitlement, management of seats and devices, sending licence-related e-mails, evidence of consents, detection of outdated program versions, as well as billing and accounting.
Legal basis Not the same one for all of the data listed above:
  • Sign-in, licence verification, device and seat management (e-mail address, device identifier, program version, operating system, processor architecture): performance of the usage contract, Art. 6(1)(b) GDPR.
  • Voluntary profile details (form of address, title, name, company, phone number, postal address, signature): your consent, Art. 6(1)(a) GDPR, given by entering them. They are not necessary for the contract.
  • Evidence of consents: legal obligation arising from the accountability principle, Art. 6(1)(c) GDPR in conjunction with Art. 5(2) and Art. 7(1) GDPR.
  • Newsletter: your consent, Art. 6(1)(a) GDPR, withdrawable at any time.
  • The events „download clicked" and „update installed": legitimate interest in recognising whether an account still runs an outdated version and in being able to classify support requests about it, Art. 6(1)(f) GDPR. You may object under Art. 21 GDPR.
  • Invoice and accounting data: legal obligation, Art. 6(1)(c) GDPR in conjunction with sec. 147 AO, sec. 257 HGB and sec. 14b UStG (German tax, commercial and VAT law).
Storage period
  • expired sign-in links: immediately
  • requests to change the account e-mail: 90 days
  • server-side access log: 12 months, after which the e-mail address in it is pseudonymised
  • contact data without a purchase: 24 months. The basis for this is not the contract (there is none) but our legitimate interest in being able to resume a started setup later and to classify follow-up questions, Art. 6(1)(f) GDPR. You may object under Art. 21 GDPR.
  • invoices and accounting records for a purchase: 8 years (sec. 147(3) AO, sec. 257(4) HGB, sec. 14b(1) UStG). For records that go into books, inventories or financial statements, 10 years still apply. The periods do not end while the records are relevant to a tax assessment that is still open.
If you request deletion, the accounting core remains (amounts, order and transaction number, country, VAT ID); we remove name, address and phone number, and the access log is pseudonymised.
Whether providing data is required The e-mail address is required for an account and for a paid licence; without it we cannot assign a licence. The profile details are voluntary. They are only needed if you want generated letters to carry sender details.

If you invite colleagues: if you enter someone else's e-mail address for a seat or for transferring a licence, we process that address in order to deliver the invitation and assign the seat. The legal basis is our legitimate interest in operating the licence management (Art. 6(1)(f) GDPR). The invited person receives the information about the processing together with the invitation, that is at the first communication (Art. 14 GDPR); the source of the e-mail address is the person or organisation that issued the invitation. Please only invite people who expect it.

4.3 Optional AI features

This is the only way in which contents of your documents can leave your device.

Off until you set them up. The AI features (chat, skill gallery, generation of letters and evaluations) are inactive until you actively set them up. Without setup, none of the transmissions described here takes place.

Your own access key. To set them up you enter your own access key from an AI provider of your choice. porthor ships no key and operates no language model of its own. Eleven providers are selectable: OpenAI, Anthropic, Google Gemini, Azure OpenAI, Mistral, Cohere, DeepSeek, Groq, Together AI, Fireworks AI and xAI. With some providers you enter an endpoint of your own. The actual place of processing then additionally depends on the deployment and region model you selected at the provider.

An existing Claude subscription instead of a key. As a twelfth option you can connect porthor to a subscription from Anthropic instead of entering a key. porthor opens Anthropic's sign-in page in your browser for that; you sign in there with Anthropic and grant porthor the authorisation. porthor never sees your password. What comes back is an access credential that stays in the main process of the application and is stored encrypted on your device (section 7); it is not sent to us. The only addresses contacted for this are Anthropic's sign-in and token addresses. This route and the route via your own Anthropic key are strictly separate: if the subscription fails, porthor does not fall back to your key — you would otherwise be paying without noticing. You withdraw the authorisation in porthor by disconnecting, and with Anthropic in your account.

The route without any transmission. As a thirteenth option, a model you operate yourself can be connected, on the device or in your own network. The application then addresses the URL you enter; no access key is needed for this. In this mode, nothing leaves your device or your network even when using the AI features.

One provider per capability, and one gate per capability. porthor does not only request text. In the settings under „Modelle" (models) you determine separately for every capability which of the providers named above handles it; without an entry the capability is off. This adds no further recipients — only the providers you have set up anyway. What is transmitted in each case, and what porthor checks beforehand:

Text Chat, skills, letters and evaluations. What is transmitted is pseudonymised text together with your instruction, after the check described below under „What is transmitted".
Describing an image („vision") An image you selected and your question about it. porthor cannot pseudonymise an image. It therefore only goes out once you expressly confirm that no persons, licence plates or name badges are recognisable on it, or that you have obscured them locally beforehand.
Generating and editing images Your image instruction and, when editing, the source image — with the same express confirmation as for describing.
Transcription (dictation) The sound recording from your microphone, in the original. A recording cannot be pseudonymised; before it has been turned into text, porthor does not know what was spoken. Hence two locks: the setting „Diktat erlauben" (allow dictation), off as shipped, and your consent for every single recording. Details in section 4.7.
Speech output (read aloud) Only the text you have read aloud, and specifically the already pseudonymised version, the same one that goes to the language model. The real details are neither read aloud nor transmitted.

Every one of these routes is logged on your device (processing log, porthor Pro) — with time, capability and provider, never with the content.

Who is responsible for this data flow. The connection runs directly between the device and the model provider you chose. We receive neither the document contents nor the requests or the answers; they do not pass through our servers. The controller for the lawfulness of this transfer under data protection law is therefore the user, or the organisation within whose sphere of responsibility porthor is used, not menosgada Service GmbH. Setting the feature up in porthor unlocks it; it does not replace a legal basis under Art. 6 GDPR.

What the controller has to clarify. At least these points belong settled before use:

  • a legal basis under Art. 6 GDPR for the transfer to the model provider and, if special categories of personal data are involved (health data, for example), additionally a permission under Art. 9 GDPR;
  • a data processing agreement under Art. 28 GDPR with the chosen model provider, where that provider acts on your instructions. This is not a recommendation but a prerequisite;
  • the conditions for a transfer to a third country under Art. 44 et seq. GDPR. The selectable providers process in different countries, including countries outside the EU and the EEA. For some of those countries there is no adequacy decision of the European Commission; appropriate safeguards and a risk assessment are then required. Which provider processes where is determined by the provider and can change;
  • whether the provider uses your input to train its models, and how long it stores requests.

Anyone who does not want to clarify these points has the route via a self-operated model: no transfer to a third party takes place then.

What is transmitted. What is transmitted are pseudonymised contents, that is texts in which detected personal details have been replaced by placeholders such as Vorname_Gruppe1, together with your instruction to the model. Before every send, a built-in check inspects the text for unprotected personal details and for original values from the mapping table; if it finds any, it aborts the transmission. This check is an additional safeguard and works with detection rules and models that cannot catch every case. Please continue to review the text yourself before sending.

Pseudonymised is not anonymous. As long as the placeholders can be resolved again through the local mapping, the transmitted contents remain personal data within the meaning of the GDPR. Pseudonymisation lowers the risk and is a recognised safeguard (Art. 25, Art. 32 GDPR); it does not mean that the data protection requirements for this transfer fall away.

Reversal. Model answers are displayed again with the real details on your device. This reversal is display only: the history stores the pseudonymised version, and follow-up questions to the model likewise use the pseudonymised version.

The route via the clipboard, with no connection from porthor at all. Besides the AI features there is a second route, and it is available in every licence tier, porthor Free included: in the „Zwischenablage" (clipboard) tab, porthor puts the pseudonymised text of a document on your clipboard. With it you ask an AI of your choice in the browser. You paste the answer back into porthor; porthor restores the real details locally. Placeholders that cannot be matched stay as they are and are marked — porthor never guesses.

This matters under data protection law: porthor makes no connection on this route. What happens to the text after you have pasted it into your browser is governed solely by the policy of the service used there; the controller for that transfer is you or your organisation, not menosgada Service GmbH. And: this route produces no processing log — that belongs to porthor Pro (see section 7). Anyone who has to document the transfer documents it themselves here.

Switching off: remove the access key in the settings and every transmission to the model provider ends immediately. Storage period at our end: we store nothing about these requests because they never reach us. How long the chosen provider stores requests is determined by that provider.

4.4 Handover to a program on the same computer

porthor can offer its functions to other programs running on the same computer, an AI tool you installed there for example. This is off until you switch it on in the settings.

This handover is not a network connection. porthor opens no port for it, listens on no address and is not reachable from the network; the exchange runs exclusively through the input and output of the program that called porthor. No recipient within the meaning of the GDPR and no third-country transfer arises from it.

What porthor hands over on this route is pseudonymised, as with the AI features. There is one deliberate exception: the calling program can ask porthor to resolve placeholders back into clear text. That answer goes back exclusively to the local program, the mapping stays in memory and is not passed on. The controller for what the other program does with that clear text — in particular whether it forwards it to a model on the network — is you or your organisation.

4.5 Your own mailbox (IMAP and SMTP)

Off until you set it up. porthor can mount a mailbox so that e-mails and their attachments land in your working folder without a detour (porthor Automate). For that you enter the credentials of your own mail server. Without that setup none of the connections described here takes place.

Recipient Exclusively the mail server you enter, as a rule the one of your company or of your mail provider. There is no porthor mail server and no intermediary service: the connection runs directly between your device and your server. We receive nothing in the process.
Data transmitted Your credentials for signing in to your server (they are stored encrypted on your device, section 7) and, when fetching, the messages and attachments you fetch. When a draft is filed, the draft goes into the drafts folder of your mailbox. Sending happens only on your express confirmation, message by message; porthor sends nothing of its own accord.
Purpose Taking incoming messages into the matching folder, creating drafts, sending replies when you ask for it.
Legal basis For the operation inside porthor: your consent, given by setting it up, Art. 6(1)(a) GDPR. For the processing of the e-mail contents themselves the controller is — as with the documents (section 3) — the user, or the organisation within whose sphere of responsibility porthor is used.
Transport security The connection always runs encrypted (TLS or STARTTLS), and porthor always verifies the certificate of your server. This verification cannot be switched off. porthor accepts an unencrypted connection only against a test server on the same computer.
Storage period We store nothing about this because nothing reaches us. Fetched messages sit in your working folder; how long they stay on your mail server is determined by you or by your provider.
Switching off Unmount the mailbox in the settings or remove the credentials; every connection to your mail server then ends immediately.

4.6 Web search in the AI assistant

Off until you allow it. The AI assistant can look something up on the web for a question, a current interest rate or a regulation for example. The setting is called „Web-Suche erlauben" (allow web search) and is off as shipped. Without it porthor makes no search request.

Recipient No further recipient. The search runs through the search tool of precisely the AI provider you have set up anyway: OpenAI, Anthropic, Google or xAI, depending on which one you connected. porthor integrates no search service of its own and calls no search engine directly. Where the provider searches in turn, and which sources it queries in doing so, is determined by that provider.
Data transmitted The search request, and it is pseudonymised: detected personal details are replaced by placeholders before the request goes out. In doing so it runs through the same built-in check as every other message (section 4.3, „What is transmitted"); if that check finds unprotected details or original values from the mapping table, it aborts the transmission. A search for a real name or a real address therefore does not come about on this route.
Data returned The list of hits the provider delivers (title and address of the page) appears in the chat history and stays there. porthor does not open those pages of its own accord and does not fetch their contents; a hit is loaded only once you click it, and then in your browser.
Purpose Taking current details into an answer that are not contained in the language model itself.
Legal basis Your consent, Art. 6(1)(a) GDPR, given by switching the setting on; revocable at any time with effect for the future. For the transfer to the model provider, everything set out in section 4.3 applies in addition, including the question of who is responsible for it.
Processing log Every search call is recorded in the processing log on your device (porthor Pro), with the time and the provider. porthor Free has no web search, because the web search belongs to the AI assistant.
Storage period We store nothing about this because nothing reaches us. How long the chosen provider stores search requests is determined by that provider.

4.7 Dictation and read-aloud in the AI assistant

Off until you allow it, and then confirmed separately every single time. You can speak a question to the AI assistant instead of typing it. The setting is called „Diktat erlauben" (allow dictation) and is off as shipped.

This is the one place where contents leave your device unpseudonymised. A sound recording cannot be pseudonymised: porthor cannot know which names occur in it before it has been turned into text. The recording therefore goes in the original to the provider you connected for transcription under „Modelle" (models) (section 4.3), and only after your consent to this one recording. So do not speak any details into it that you would not entrust to that provider.

What happens afterwards runs on your device again. The transcript comes back and stays local at first; it lands as text in the input field. Only once you send it is it pseudonymised like every other message and inspected by the built-in check (section 4.3). Turning the recording into text and sending the question are thus two separate steps, and you can read and change the transcript beforehand.

Read-aloud is the harmless way back. If you have an answer read aloud, only the already pseudonymised version goes to the provider you connected for speech output, the same version the language model saw as well. The real details are neither transmitted nor read aloud in the process.

Legal basis for both routes: your consent, Art. 6(1)(a) GDPR, for dictation in two stages (the setting, and consent for every single recording), revocable at any time. Switching off: switch the setting off or remove the connected provider; the route is closed after that. Storage period at our end: nothing, because nothing reaches us. Every call is recorded in the processing log on your device (porthor Pro).

5. Obtaining the app from an app store

If you obtain porthor from an app store rather than from porthor.de, the operator of that store processes the data of your account there and of the installation under its own responsibility. We are not involved in that and receive no personal data from the store operators. Obtaining the app from a store concerns the application only; paid licences are not sold through the stores, section 6 applies to those.

5.1 Microsoft Store

The controller is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA. The Microsoft privacy statement applies. From Microsoft we receive only aggregated figures, such as the number of installations per country.

5.2 Apple App Store

The controller is Apple; for users in Europe this is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. The Apple privacy policy applies. From Apple, too, we receive only aggregated figures, such as installation and sales numbers per country. Apple expressly forbids us to derive individual persons or devices from them.

6. Buying paid licences

Purchases do not take place inside the application. The application opens the page porthor.de/preise in your browser for that.

The contracting party for the payment is Copecart GmbH, Rosenstr. 2, 10178 Berlin, Germany. It acts as merchant of record, meaning it sells the licence in its own name and is responsible for payment, invoicing and taxes. Everything you enter during the order process is governed by the CopeCart privacy policy and its terms and conditions.

What CopeCart processes: your entries from the order process, that is name, billing address, e-mail address and the payment details (such as card number or bank account). Payment details do not reach us. We neither see nor store them.

What we receive from CopeCart: the order data, that is name, e-mail address, billing address, purchased plan, number of seats, amount, and order and transaction number. We need it to issue and manage your licence and to keep our accounts. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and, for the retention, the legal obligation under sec. 147 AO, sec. 257 HGB and sec. 14b UStG (Art. 6(1)(c) GDPR). This data ends up in the account on our licence server; the periods from section 4.2 apply.

Invoices, cancellation and withdrawal are handled through CopeCart, not through the application: CopeCart buyer area. For completeness, the purchase process is also described in the website policy, section 6.

7. Data stored on your device

This data stays on your device. We have no access to it.

WhatWhereProtected by
Original documents, redaction states, exports, notes in the working folder you showed porthor, somewhere on your device or on a network drive. porthor files the documents where they already sit; it copies and moves nothing. the access rights of your operating system or of the network drive
Mapping between real details and pseudonyms. It contains the original details in clear text and is the most sensitive part of a folder. in the hidden subfolder .porthor of the folder. On every export, porthor additionally writes the file <filename>_zuordnung.csv next to the export. the access rights of your operating system. If you pass on the folder or the export, you pass on this mapping with it.
Processing log (evidence of what was processed when and with which protection). It belongs to porthor Pro; in porthor Free none is created, not even on the route via the clipboard (section 4.3). in the .porthor subfolder of the folder concerned contains only counters and metadata, no document contents
Tasks and kanban cards, reminders and notifications, as well as the intermediate states of running flows (an interview, for example) in the .porthor subfolder of the folder they belong to, so that they follow a shared folder the access rights of your operating system. They never leave the device: there is no task server and no push service.
Settings, AI access key, the access credential of a connected Claude subscription, the credentials of a mounted mailbox, profile and sender details, account e-mail, sign-in token and licence proof, custom skills in your operating system user profile
Windows: %APPDATA%\porthor
macOS: ~/Library/Application Support/porthor
Linux: ~/.config/porthor
the operating system key store (see section 8)
History of the AI chats and the associated placeholder mapping in the user profile; for chats that belong to a folder, in the .porthor subfolder of that folder, so that a shared folder stays readable encrypted in the user profile; in clear text in the folder, because otherwise only the device on which it was created could read it
Usage counters and program log for troubleshooting (usage-stats.json, app.log) in the user profile do not leave the device. There is no function that sends them to us.

Careful when passing files on. The mapping file is created on every export in the same folder as the exported document. Anyone who passes that folder on as a whole hands over the key for re-identification with it and renders the pseudonymisation ineffective. Send the exported document on its own and keep the mapping file separate from it.

Uninstalling does not delete this data. If you remove porthor, your folders and the directory in your user profile remain, so that a reinstall can pick up your work, and because your folders hold your own files, which porthor must not delete. To remove everything, additionally delete the directory named above by hand and tidy up your working folders yourself.

8. How the data is protected

  • All connections of the application use HTTPS with TLS encryption. For the licence server the application enforces HTTPS and aborts an unencrypted connection instead of falling back to it.
  • Account e-mail, sign-in token, the licence proof, the access credential of a connected Claude subscription, the credentials of a mounted mailbox and profile and sender details are stored locally, encrypted through the operating system key store (DPAPI on Windows, the keychain on macOS, the configured keyring on Linux). If no key store is available, for example on Linux without a configured keyring, the application says so: in that case the values are merely encoded, which is not encryption. The encryption therefore depends on the operating system, not on porthor, and porthor tells you when it is missing instead of pretending it is there.
  • The licence proof is signed with a procedure (Ed25519) whose public part is built into the program. A manipulated or substituted proof is therefore detected; it also carries a fixed validity of 14 days, so that a proof someone has captured does not remain valid indefinitely.
  • Connections to your mail server always run over TLS or STARTTLS, with certificate verification. That verification cannot be switched off.
  • The processing log is kept as a hash chain. Later changes to it are detectable; that does not make it unchangeable.
  • Before every outbound AI request the built-in check inspects the content and aborts in case of doubt instead of sending.

9. What you can control

  • AI features: they only become active once you store an access key. Remove the key in the settings and every transmission to the provider ends.
  • Update check: off as shipped, switchable on and off in the settings at any time.
  • News: on by default, switchable off in the settings in every licence tier. The notice about a new program version is not affected. The additional notification through your operating system can be switched off separately — it appears at most once per program start.
  • Newsletter: can be subscribed and cancelled inside the application, and through the unsubscribe link in every e-mail.
  • Model provider per capability: for text, image description, image generation, transcription and speech output you choose separately which provider handles it, or none, in which case the capability stays off. For images and recordings porthor additionally requires your express confirmation every time (section 4.3).
  • Mailbox: only after setup; can be unmounted at any time. Sending is additionally blocked until you release it, and then requires a confirmation for every single message (section 4.5).
  • Web search: off as shipped, switchable on and off in the settings. Without it porthor makes no search request (section 4.6).
  • Dictation: off as shipped, and even then a recording only goes out after your consent to precisely that recording. This is the only route on which contents are transmitted unpseudonymised; accordingly it can be closed again completely in the settings (section 4.7).
  • Handover to local programs: off as shipped, switchable on and off in the settings (section 4.4).
  • Clipboard: the route via the „Zwischenablage" (clipboard) tab needs no setting and no key, because it makes no connection. For every text you decide yourself whether and where you paste it.
  • Account: initial setup requires an e-mail address, for porthor Free as well; there is no password. The account e-mail can be changed in the application, and profile details can be corrected or emptied there.
  • Devices: activated devices can be viewed in the account and signed out again.
  • Local data: it sits in folders you can inspect, back up and delete (section 7).

10. Your rights

You have the right at any time to:

  • access to your stored data (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object to processing based on legitimate interests (Art. 21 GDPR)
  • withdraw a given consent with effect for the future (Art. 7(3) GDPR)

Please contact service@porthor.de to do so.

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you that we base on a legitimate interest (Art. 6(1)(f) GDPR). In this policy this concerns the access logs of our server, the events „download clicked" and „update installed", the retention of contact data without a purchase, and the processing of invited e-mail addresses.

If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims. An informal objection to service@porthor.de is sufficient.

You may also lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany. This is without prejudice to your right under Art. 77 GDPR to approach the supervisory authority of your habitual residence or place of work.

The limit of what we can answer: for data that sits exclusively on your device we cannot provide access and cannot delete it. We have no access to it. We can only serve access and erasure requests for the data held on our licence server (section 4.2).

11. No profiling, no advertising, not for children

Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place. We build no profiles from your use of the application, show no advertising, and pass no data to ad networks or data brokers. porthor is a professional working tool and is not directed at children.

12. Changes to this policy

If the data flows of the application change, we change this policy with them. The version in force is published at porthor.de/en/privacy-app and is reachable from within the application through the settings. We additionally name material changes to signed-in users by e-mail.


Last updated: 11 September 2026. The website privacy policy applies to porthor.de.