01
Who is responsible
Designco is responsible for Portalworld and everything in it: the controller, in the words of the GDPR. Designco is a design and engineering studio at 241 Syngrou Avenue & Alikarnassou 1, 17122 Athens, Greece. For anything on this page, write to hello@designco.agency.
Portalworld is not a public product. The people who use it are the studio's team and anybody an admin adds by their exact Google address, such as a salesperson working with the studio. Clients and prospects never use it, but some of their details are in it, so this page is for them too.
02
What it keeps
Grouped by what it is for, with who can see each part. Wherever it says the studio, a private project narrows that to the people on it.
- Your accountThe studio
- Your name, work email, role, disciplines, access level, contracted hours, default shift, XP and level. The photo you upload for your portrait is yours alone; the illustrated portrait made from it is seen by everyone.
- Your workThe studio
- Quests you open, own, review or help on, their steps and files, and every progress update. What you typed is kept exactly as you typed it, beside whatever Aurealis made of it.
- Your time and presenceThe studio
- Hours you log, check-ins and check-outs, where you said you work from (office, remote, a client's site, travelling, off), your status line and absences. On a weekday you do not check in, your default shift is assumed, and marked as assumed.
- CommitsWhoever can see the project
- From the studio's GitHub: each commit's repository, branch, the first line of its message, the author's name, the time and the size of the change. Your git addresses are listed, for everyone in the studio, so a commit is matched to you exactly and never guessed.
- Agent timeYou, admins, whoever can see the project
- Only if you turn it on. Which agent you used (Claude Code or Codex), when a session started and ended, when you sent a prompt, the session's id and the repository's name. Never what you typed, what the agent answered, or which folder you were in.
- Chat and notificationsThe studio, or a private project's people
- Messages and reactions in channels, and when you last read each one, which the studio can see. Your notifications, your reminders and your conversations with Aurealis are yours alone.
- Meetings and callsWhoever can see the project or deal
- Who attended, including people outside the studio, a recording if somebody uploads one, its transcript with the speakers' names, and what Aurealis read from it, the tone of the conversation included. A call logged by the sales seat is the caller's own account, written or spoken afterwards.
- Voice notesNobody keeps the sound
- When you speak into a box, the sound goes to Google's Gemini and is written down as you speak. Only the text is kept.
- Files and photosWhoever can see what they belong to
- Images, documents, recordings and website screenshots, stored with Cloudflare and handed out only after Portalworld checks who is asking. Files are kept as they were made, so a photo can carry what the camera wrote into it, such as where it was taken.
- Clients and prospectsThe studio; deals, the sales seat and admins
- Companies and the people at them: name, role, email and phone. For the sales seat, deals, quotes, plans, campaign lists, every touch in the words it was written, and photos of shopfronts. A request not to be contacted is kept, so no later list reaches that person.
- MoneyAdmins; quotes, the sales seat too
- What each project was sold for, contracts and their files, client rates, and quotes on open deals. Even for those who may see them, figures stay hidden until Show budgets is switched on.
- HistoryWhoever can see what changed
- Every change to a client, contact, project, quest, bug, meeting or file, with what it was before, so it can be undone and traced.
- Your settings and devicesYou; Aurealis usage, admins too
- Your colour setup, sounds, which notifications reach you and how, each browser you allowed to receive push notifications (with the name that browser gives itself), and how much of Aurealis you used each day, in tokens and cost.
- Sign-in attemptsAdmins
- A Google account that signs in without having been added: its name, email and photo, as Google sent them. It is shown nothing.
03
Why it keeps it
Each use rests on one of the grounds the GDPR allows. None of it is used for advertising, and none of it is sold.
- Your contractGDPR 6(1)(b)Running the work you do with Designco: quests, hours, reviews, XP and the conversations around them.
- Legitimate interestGDPR 6(1)(f)Keeping a true record of what each client was delivered, sharing work fairly and keeping Portalworld secure: the commits, the history and the readings. Weighed against your interests, which is why time is kept without words and nobody is compared on raw output.
- Legitimate interestGDPR 6(1)(f)Doing business with clients and prospects: their contacts, deals and calls. A request not to be contacted always wins.
- A legal dutyGDPR 6(1)(c)Keeping the commercial records the law asks Designco to keep: contracts, prices and the work behind them.
- Your choiceGDPR 6(1)(a)Agent time, push notifications, voice notes and the portrait made from your photo run only once you start them, and stop when you turn them off.
04
Aurealis and the readings
Aurealis is the AI inside Portalworld, built on Google's Gemini. Whatever you hand it is sent to Gemini to be read: the words, screenshots and PDFs you paste, call notes, a contract, a list of leads, a photo, a meeting recording, and each morning the new commits. To propose who should do what, it is also told about the studio: names, roles, contracted hours, levels, presence and how full each plate is. Recordings go through Google's file service, which deletes them after 48 hours.
What comes back is a proposal. Nothing is created, sent, approved or paid until a person presses confirm, and a reading Aurealis is unsure of is shown as a question, not a fact. A few things are written without a press because they decide nothing: the transcript of an uploaded recording, the morning's reading of new commits, nudges, and the assumed hours of a default shift.
Portalworld also reads the work back to people: XP for delivered work, how full each plate is against contracted hours, and how this week compares with the same person's own past weeks. Every comparison is normalised by effort or contracted hours, never laid side by side on raw output, and none of it decides anything about anybody. People do.
If you connect your own AI agent (Claude Code, Codex, Cursor or the Claude apps), it works as you: it reads what you can read, and anything it drafts waits for your yes. What it reads then reaches that agent's provider, under your own account with them.
05
Who sees what
- Everyone in the studioEach member's name, work email and git addresses, role, contracted hours and shift, XP, presence and status line, how full each plate is, the week's rhythm, who has room, the people at clients, and the work on every project that is not private.
- The people on a private projectThat project's work, files, meetings and history. Nobody else sees it except its lead and admins, and for a deal, the sales seat.
- ManagersAlso the studio's analytics, every quest's original words in one place, and the command view.
- The sales seatAlso every deal, quotes, campaigns, plans and clients' details. Never what projects sold for, contracts, rates or anybody's analytics.
- AdminsEverything above, plus what each project sold for, contracts, client rates and what Aurealis cost.
- Only youYour notifications, reminders, Aurealis conversations, settings and devices, and the photo behind your portrait.
06
Who else handles it
The companies Portalworld runs on, each doing one job for Designco and nothing else with it.
- SupabaseThe database, sign-in and live updates, in Ireland (EU).Everything on this page
- VercelServes Portalworld's pages and runs its server code, in Dublin (EU).Each request, in passing
- GoogleSign-in with your Google account, and Gemini, which reads what Aurealis is handed, writes down voice notes and draws portraits from photos.Your Google account, and what Aurealis is handed
- CloudflareStores files, photos and recordings. Nothing in it is public.The files
- GitHubWhere the studio's code lives. Portalworld reads new commits every 15 minutes and writes nothing back.Nothing it did not have
- ResendSends notification emails, to designco.agency addresses only.Your work address and the notification
- MicrolinkTakes a screenshot of a client's or a project's public website.A public web address
- Apple, Google, MozillaDeliver push notifications to the browsers you allowed.Encrypted notifications they cannot read
Several of these companies are based in the United States, so some of this is handled outside the EU. Designco relies on the safeguards in their data processing terms for that, such as the European Commission's standard contractual clauses. Nobody else is given any of it.
07
How long it stays
Most of it stays as long as Portalworld does, because it is the studio's record of the work: quests and updates, hours and presence, commits, history, meetings, deals and contacts. Some things clear themselves:
- Notifications, 30 days after you read them.
- Removed files, 30 days after they were removed.
- Recordings handed to Google's file service, after 48 hours.
- A push device, as soon as it stops answering.
- The sound of a voice note is never kept at all.
When you leave the studio, your account is removed. What is only yours goes with it, and the work you delivered stays in its projects without your name on it. A Google account that signed in without being added is kept so an admin can recognise it; ask, and it is deleted.
08
On your device
sb-…-auth-tokenKeeps you signed in. Set by Supabase, the sign-in service.pw-theme, pw-densityYour colour setup and density, for a year.pw-auth-handoffTwo minutes after you sign in, to catch a sign-in that did not stick.pw-cookie-testSet and removed at once, to check that your browser keeps cookies.
Your browser also remembers a few things for you alone, and never sends them anywhere: unsent drafts of progress updates, whether sounds, haptics and Show budgets are on, and how you left the calendar, chat and Today. After you tap a phone number on a deal, the contact's name waits in that tab until you log the call.
There are no analytics or advertising cookies and no tracking pixels. A service worker is installed only if you turn on push notifications, and it keeps no copy of anything. Portalworld never asks your browser where you are: location is switched off for the whole site.
09
What you can ask for
These are your rights under the GDPR, about anything on this page that is about you.
- See itA copy of what Portalworld keeps about you.
- Correct itMost of it you can fix yourself. For the rest, ask.
- Delete itUnless it is a record Designco has to keep.
- Take it with youWhat you gave, in a format another system can read.
- Object to itTo any use that rests on Designco's legitimate interest.
- Pause itWhile a question about it is being settled.
Write to hello@designco.agency
From the address Portalworld knows you by, if you have one. Designco answers within a month. If you think Designco got it wrong, you can also complain to the Hellenic Data Protection Authority, at dpa.gr.
10
When this page changes
When Portalworld starts keeping something new about people, sends it somewhere new, or keeps it for longer, this page changes in the same release and the date at the top moves. The version that counts is always the one at portalworld.designco.agency/privacy.