Portia privacy policy.
Portia keeps writing local by default. Optional intelligence crosses a named boundary only after disclosure, consent, and a request.
Local writing data
Portia stores Markdown documents in locations you select. Settings, writing goals, version snapshots, security bookmarks, and writing preferences remain in Portia's local app data.
Portia does not sell user data. It contains no advertising, cross-app tracking, or developer analytics. Portia does not silently upload a writing repository.
Optional OpenAI Codex on Mac
You may sign in with ChatGPT to use OpenAI Codex. Before use, Portia explains that a submitted request may send your request, complete active document including unsaved text, optional selection, and relevant conversation context to OpenAI for processing under the signed-in account. Portia sends no Codex request until you allow the transfer and submit one.
The bundled Codex runtime manages authentication inside Portia's private application data and may display the signed-in email and plan state. Signing out stops future Codex requests from Portia and invokes Codex logout.
While its process runs, the bundled runtime may write temporary local diagnostic state that includes submitted document text, prompts, and responses. Portia directs that SQLite state to a unique, marked directory inside temporary app data and attempts to remove it after the runtime exits. If the app or computer stops, or cleanup cannot finish, Portia removes marked stale runtime directories the next time Codex starts. Authentication remains in Portia's persistent, private app data so sign-in can survive relaunch.
OpenAI may retain and use account, request, response, and service data according to the applicable ChatGPT plan, OpenAI terms, privacy policy, and data controls. Consumer and business-account practices can differ. Portia does not override those controls.
Recluse Studio requires each service provider that processes Portia data to protect it at least as described in this policy and as Apple requires. If a provider cannot meet that boundary, Portia must stop using that provider for the affected processing.
Optional web research
Web search is off by default. After you enable it and accept the disclosure, Codex may search when a submitted request needs current sources. Search queries and results are processed as part of the signed-in Codex request. Research does not change a document unless you also request a revision and accept the Apply review.
Apple Intelligence
On supported iPhone and iPad devices, Portia capability-checks Apple Intelligence at runtime and uses Apple's system service. Portia does not add those requests or responses to developer analytics. The editor, local files, preview, and export remain available when Apple Intelligence is unavailable.
Permissions and network use
Portia asks for files or folders through system selection panels and stores app-scoped security bookmarks to reopen chosen locations. It does not request camera, microphone, contacts, location, health, photo library, or calendar access.
On Mac, outgoing network access supports user-initiated Codex and web-research requests. Incoming network access supports only the localhost callback required to complete ChatGPT browser authentication.
App Store data disclosure
Optional OpenAI use may involve linked, non-tracking email address, user identifier, search history, and other user content for app functionality. Local files and local app records are not developer collection unless you submit relevant content to an online feature.
Analytics, advertising, and tracking
Portia contains no developer analytics, advertising, or tracking SDK. Portia disables the bundled Codex app-server's client analytics, feedback upload, and OpenTelemetry export on every launch. Portia's Release logs do not record authentication secrets, document text, prompts, or model responses. OpenAI's service-side processing remains governed by OpenAI's policies as described above.
Retention, deletion, and consent
- Delete documents and versions from their local storage locations.
- Reset Portia settings in the Manage drawer.
- Disable Web Search in AI settings.
- Sign out of ChatGPT in AI settings to withdraw consent for future Codex requests from Portia.
- Use OpenAI's account and privacy controls for data held by OpenAI.
Recluse Studio does not operate a Portia account or Portia cloud-data store. Requests concerning information processed by OpenAI must use OpenAI's applicable account and privacy controls. Email support for help identifying the correct control.
Website preference
This page's appearance switch stores one local value in your browser. The value records only the dark or light appearance and is not Portia app data. Read the separate Recluse Studio website privacy notice for hosting and email details.
Contact
Email support@recluse.studio with a Portia privacy question, consent request, or deletion question.
