Kazakhstan Users
Please note: If you are accessing the Service as a resident of, or from within, the Republic of Kazakhstan, your use of the Service is not governed by this document. Instead, your access is subject to a separate Privacy policy governed by the laws of the Republic of Kazakhstan, which can be accessed here.
Privacy Policy for the Portals Application
Version 1.0
Effective date August 2026
1. INTRODUCTION AND DATA CONTROLLERS
Your privacy is of the utmost importance to us and the foundation of our service. We are committed to safeguarding your personal data through strict data firewall protocols, industry-standard encryption methodologies, and non-AI design mechanics. This Privacy Policy explains how APS pay LLP, a limited liability partnership registered under the laws of the Republic of Kazakhstan and an official resident of the Astana Hub International Park of IT Startup (operating globally or through its localized regional affiliates) (together, "Portals", "Company", "we" or "us") collects, uses, and discloses your information when you access or use our websites, mobile applications, interactive self-regulation tools, community features and other online products and services (collectively, the “Services”), and when you contact our customer service team, engage with us on social media, or otherwise interact with us.
Global Data Controller: For all users accessing the Platform globally—specifically excluding residents of the Republic of Kazakhstan, whose data access is subject to a localized policy—the primary Data Controller is APS pay LLP.
Depending on how you interact with our Platform, the following may also apply to you:
- Certain optional features within the Portals App may be governed by supplementary privacy notices where required by applicable law.
- Our Platform may contain links to third-party websites or services not operated by us. This Privacy Policy does not apply to those third parties, and we strongly encourage you to review their respective privacy policies to understand their data practices.
- If you choose to access our Platform using single sign-on features (such as Sign in with Apple or Google), your authentication process is also subject to that SSO provider’s terms and privacy policies.
- This Privacy Policy covers end-users of our Platform and does not apply to Portals employees or job applicants.
Please read the following carefully to understand our practices regarding your personal information. We also strongly encourage you to review our comprehensive Terms of Use [Insert Link to Terms of Use], which outlines the specific governing laws and dispute venues strictly applicable to your residency, including distinct legal stipulations for UK, UAE, and US residents.
2. JURISDICTION, TERRITORIAL SCOPE, AND DATA PORTABILITY
We apply strict, privacy-by-design standards that adapt dynamically to your physical location and residency:
- In accordance with our Terms of Use, your "Home Jurisdiction" is established based on the country of residence you select when creating your account. You may update your declared Home Jurisdiction at any time by contacting our support team at Support@portalslab.com. We may use approximate IP-derived location information for app attribution purposes. Home Jurisdiction helps us determine the appropriate regional privacy notice, controls and service configuration; applicable data protection laws are determined by law and are not altered by this classification.
- United Kingdom Residents: Processing is governed by the UK Data Protection Act 2018 and the UK Data Use and Access Act (DUAA) 2025.
- UAE Residents: Processing is governed by UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection.
- United States Residents: Processing is governed by applicable federal and state privacy statutes (including the California Consumer Privacy Act/CPRA, Washington My Health My Data Act, and state-specific consumer health data laws), with governing law specified under Delaware jurisdiction where applicable.
- Global & Rest of World Residents: For users residing outside the jurisdictions listed above (and excluding residents of the Republic of Kazakhstan), your personal data processing is governed by the high-standard privacy framework of our primary Data Controller under the laws of the Republic of Kazakhstan (including Law No. 94-V "On Personal Data and Their Protection"). Where mandatory consumer privacy laws in your local jurisdiction grant stricter statutory rights, we apply those mandatory protections.
- Your privacy rights "follow" your account worldwide. If you register in the UK, US or elsewhere and subsequently travel abroad, your Home Jurisdiction protections remain active. If you access the App from an unlaunched jurisdiction, we may restrict certain features (including high-intensity data logging, real-time multiplayer interactions, or community sharing) to shield your data from conflicting local surveillance or data interception regulations and to prevent unauthorized cross-border transfers.
3. DATA SOVEREIGNTY AND FOREIGN ACCESS PROTECTION
Your personal data is protected under the privacy and data-protection laws applicable to the relevant processing and under the security controls described in this Policy. Your selected Home Jurisdiction does not exclude the application of mandatory laws that otherwise apply.
We do not voluntarily provide user data to governmental authorities except where disclosure is legally required or otherwise permitted by applicable law. We assess governmental requests for validity, necessity, proportionality and applicable jurisdiction and disclose only the minimum information legally required.
For our non-Kazakhstan infrastructure hosted on AWS, we use regional and, where implemented, sovereign-cloud controls, including jurisdiction-appropriate cryptographic and access-management safeguards.
4. DATA CLASSIFICATION AND MINIMAL DATA PROCESSING
To align with our privacy-by-design principles, Portals practices strict data minimization. We process only information necessary to operate the app, manage your progression, facilitate multiplayer and community features, provide user-selected content, maintain security, and support the optional features described in this Policy.
- User Experience, Multiplayer & Interaction Data: All data collected operates within this standard user experience stream, which includes:
- Your interface engagement, audio/visual session playback, and technical identifiers of content or iterations used to operate and measure the service.
- Your multiplayer interactions and community participation.
- Visual progress indicators, including your overall progress percentage and virtual progress units ("ports"), which reflect progression within the app.
- Please note: Any virtual progress units utilized within the app are strictly internal visual indicators. They possess no monetary value, cannot be traded or redeemed, and do not constitute financial assets.
- Explicit Exclusions (What We Do Not Collect): Because our platform is currently focused solely on self-regulation mechanics rather than scientific research or clinical diagnostics, we enforce the following data collection boundaries:
- No Clinical Questionnaires: We do not collect or process responses to deep psychological assessments or validated medical instruments (such as GAD-7 or PHQ-8).
- No Medical Profiling: We do not track, infer, or store clinical mental health diagnoses.
- No Scientific Vaulting or Research Processing: Portals does not currently collect or process user data for scientific research purposes and does not maintain a separate scientific or research data repository. Operational product analytics are used only to operate, secure and improve the Service and are not treated by Portals as a scientific research program.
5. INFORMATION WE COLLECT AND COLLECTION METHODS
A. Information Provided Directly by You
We practice strict data minimization, collecting only the information required to provide you with a personalized, interactive self-regulation experience. We do not collect clinical questionnaires or psychological assessments. We may collect information when you register for an account, participate in multiplayer features, fill out a form, make a purchase, or communicate with our support team. The information you provide includes:
- Account Credentials: Your email address (unless Sign in with Apple/Google provides a private relay address), username chosen by you (which may be a name or nickname), account authentication information, selected country of residence, and confirmation of the applicable digital-age consent requirement.
- Payment Data: We do not collect, store, or process raw credit card numbers or financial account credentials. All monetary transactions are processed directly through the Apple App Store or Google Play Store. When you make a purchase, these platforms act as the "Merchant of Record." We only receive a transaction confirmation or a unique "subscription token" from these providers to verify that your purchase was successful and to grant you access to our premium features. This confirmation may include your approximate location (for tax purposes) and the date of the transaction, but it does not include your full payment method details. Please refer to the privacy policies of the Apple App Store and Google Play Store for information on how they handle your payment data.
- User-Generated Content (Community & Multiplayer): Our Services include community, multiplayer and user-to-user sharing features. You may create and save visual constructs (mandalas) in your profile and may add a title or other text. You may also voluntarily post content to the community or send a visual construct (such as a mandala/"postcard"), together with any title or text you choose to add, to another user. Your username and the name of an initiated multiplayer session may be visible to other participating users. Portals does not provide private peer-to-peer chat. Content you choose to post or send is visible to the intended recipients or audience, and recipients may further copy, save or share content outside Portals. You may delete a visual constructs (mandalas) and any associated title/text saved in your profile.
B. Special Category & Health Integrations:
Certain iteration names or optional health-integration data may reveal or relate to aspects of emotional or physical wellbeing and may be classified as sensitive, special-category, or consumer health data under applicable law. Where applicable law requires explicit consent for sensitive or health-related data, Portals relies on the consent or affirmative action required for the relevant feature and provides the corresponding controls.
- Apple HealthKit & Google Health Connect: With your permission, Portals may sync specific wellness metrics. HealthKit and Health Connect data are strictly isolated from advertising use and are never sold to data brokers or used to build machine-learning health profiles.
How this may arise:
- Iterations and Content Selection: You voluntarily choose a specific iteration from the app menu. Portals processes the selected iteration to deliver that practice. Portals does not maintain a user-facing history showing how many named iterations you completed.
- Examples of iteration names may include emotional-wellbeing themes such as Depression Mood or Anxiety State.
- Other examples may include Sleep Aid (insomnia-related content).
- These names describe user-selected wellbeing content and are not diagnoses or clinical assessments.
- Saved Content and Text: You may choose to save a visual construct (such as mandala) to your profile and may add your own title or text. Saved visual constructs and associated text remain available to you until you delete them or delete your account.
Our Legal Basis & Your Control:
Portals processes user-selected iterations only as needed to provide the practice and operate the Service. We do not use iteration selections to create a clinical or psychological profile.
- Iteration Selection: When you select an iteration, Portals processes that selection to deliver the requested content. Completion/progress information may be recorded using internal technical identifiers rather than human-readable iteration names.
- Saved Content Control: You decide whether to save a visual construct and any title/text to your profile, and you may delete any saved visual construct and associated text.
- Progress: Portals may record whether an internal practice/iteration was started, resumed, viewed or completed and uses this information to operate progression features, including overall progress and ports. The user-facing app does not present a named statistical history of completed iterations.
- Our Services are for wellbeing and emotional self-regulation purposes and do not constitute medical advice, healthcare, clinical diagnosis or treatment. We do not use your data to diagnose conditions, make clinical decisions, build health profiles for advertisers or third parties, or conduct scientific research.
- Right to Erasure: You may delete saved visual constructs and associated titles/text. You may also delete your account, which triggers the deletion process described in Section 10.
C. Other Information You May Provide:
password or authentication credentials, language settings, country of residence, content you choose to save, and text you voluntarily add to saved or shared content.
D. Information We Collect When You Use the Services or Interact with Us / Information We Collect Automatically
When you interact with our Services, we collect certain information to ensure the app remains secure, functional, and personalized:
- Usage information: We record operational events needed to run and improve the app, such as app_open, practice_started, practice_resumed and practice_step_viewed, together with technical parameters such as section_id, practice_id, step_id, practice_session_id, start_type, resume_count, platform, app_version and app_session_id. These analytics do not include your email, username, or human-readable iteration name.
- Usage Statistics: We use Statsig to measure product usage and feature performance through technical event data and parameters. We do not send Statsig your email, username, or human-readable iteration names.
- Multiplayer & Community Syncing: To provide real-time multiplayer sessions, we process the information necessary to initiate and participate in the session, including the participating username and the name of the initiated session where displayed to participants. (Basis: Performance of Contract).
- Transactional information: information about a purchase, such as product description, price, subscription or free trial expiration date, and time and date of the transaction.
- Behavioral Data (UX & App Improvement): We use Statsig for operational product analytics and feature measurement. Event data is sent using technical event names and identifiers/parameters rather than your email, username or human-readable iteration names.
- Technical Log and Device Information: We process technical information necessary for app operation, diagnostics and analytics, including platform, app version, app-session identifiers and device/system information. Approximate IP-derived information is used for AppsFlyer attribution. Firebase Crashlytics processes crash and diagnostic information to identify and resolve technical failures. We do not use IDFA or Apple cross-app tracking APIs.
- Communications: If you contact us by email, support channel or feedback feature, we process the information you choose to provide in order to respond to your request and improve support. This does not constitute scientific research.
E. When you use the Services, we infer or generate the following information about you to personalise your experience:
- User ID: a unique internal identifier associated with your account.
- We may use limited technical information to operate the Service, measure feature performance and provide progression. We do not infer your gender, clinical condition, psychological diagnosis or other medical characteristics from your use of Portals.
- Strict No-Profiling Rule: We do not generate, infer, or predict medical characteristics, clinical conditions, or psychological diagnoses from your use of the app or your progression through its iterations.
F. Information We Collect from Other Sources
We may receive data about you from third parties to streamline your experience:
- App Stores & Payment Providers: Transaction details from the platforms used to install our app or manage your subscription.
- Marketing & Attribution Partners: We use AppsFlyer for app-install and marketing attribution. Approximate IP-derived information may be processed for this purpose. Portals does not include Meta SDK or Google Ads SDK in the client application, does not send hashed email from the client application for advertising matching, and does not use IDFA or Apple cross-app tracking APIs.
- Calendar information: If you choose to integrate your calendar, we access schedule availability to suggest optimal times for wellness sessions. (Note: Time zone is usually pulled from your device settings, not your calendar).
- Single Sign-On Providers: If you register using Sign in with Apple or another supported single sign-on provider, we receive only the information made available through that authentication flow. With Sign in with Apple, this may include an Apple private relay email address if you choose not to share your email.
- Third-party health app data: With your explicit permission, we may sync selected data from Apple HealthKit or Google Health Connect. We do not use this data to diagnose a health condition, for advertising, or for scientific research.
- Website/Cookie Data: Where our website uses cookies or similar technologies, we process them for site functionality and analytics in accordance with the choices and notices presented on the relevant website.
G. Information You Make Public (or We Collect Publicly):
We may obtain information about you that is publicly available to better understand our community or verify business accounts:
- Public Social Media Content: If you interact with our official pages on platforms like LinkedIn, Instagram, or X (formerly Twitter), we may collect your handle, comments, or public profile details.
- Consumer Research: We may use aggregated insights from public research platforms to identify broad wellness trends.
6. USE OF INFORMATION
We process your information only for the purposes described below and under the legal bases applicable to the relevant jurisdiction and processing activity:
- To deliver the specific iteration or practice you select, record operational completion/progression using internal technical identifiers, and operate overall progress and ports. Portals does not maintain a user-facing named history of completed iterations.
- To provide and organize app content and progression based on your current use of the Service. We do not use this to diagnose health conditions or profile your clinical or psychological status.
- To provide multiplayer and community functionality, including displaying the username and initiated-session name to participants where required for the feature. (Basis: Performance of Contract).
- If you choose to sync Apple HealthKit or Google Health Connect, we use basic background metrics (such as sleep duration) strictly to optimize the app's timing or content suggestions. We do not use this for machine learning or share it with data brokers. (Basis: Explicit Consent).
- To analyze technical product events and feature usage through Statsig and diagnose crashes through Firebase Crashlytics in order to keep the app reliable and improve its functionality and user experience. Statsig event data does not include your email, username or human-readable iteration names.
- Customer Support & Communications: To respond to your inquiries and send relationship messages (e.g., account notifications or receipts). (Legal Basis: Legitimate Interest).
- To send service-related communications and, where you have separately opted in where required, marketing communications about Portals. We do not use hashed email from the client application for third-party advertising matching.
- Advertising and Attribution: Portals does not use Meta SDK or Google Ads SDK in the client application and does not use IDFA or Apple cross-app tracking APIs. AppsFlyer may be used for app-install and campaign attribution as described in this Policy.
- We strictly enforce a no-clinical-profiling rule. We do not use your iteration selections, saved mandalas, captions/text or usage events to diagnose health conditions, profile your clinical mental health status, or build medical profiles for third parties.
- Security & Fraud Prevention: To detect, investigate, and prevent illegal activities, spam, unauthorized access, and fraud to protect our community and server infrastructure. (Basis: Legitimate Interest).
- Legal Compliance & Regulatory Obligations: To meet our regulatory obligations. While our partners at Apple App Store or Google Play Store handle the transactional details, we maintain the essential records required by law to keep our business compliant. (Basis: Legal Obligation).
- Aggregation: We may create aggregated statistics that do not identify individual users for internal product, operational and business analysis.
7. DISCLOSURE OF INFORMATION
We do not sell your personal data or use your sensitive wellbeing information for cross-context behavioral advertising. We disclose information only as necessary to provide, secure and support the Services, at your direction, or as required or permitted by law.
- Essential Service Partners: We use service providers necessary to operate and support the Service, including cloud infrastructure, Firebase Crashlytics for crash diagnostics, Statsig for operational product analytics, AppsFlyer for attribution, app stores/payment providers, and communications or security providers. They may process only the information required for their contracted function and are subject to applicable contractual and legal safeguards.
- Professional Guidance: We may disclose necessary information to our legal counsel, auditors, accountants, or insurers to ensure our corporate operations meet required legal, regulatory, and financial standards.
- Safety & Legal Requirements: We may disclose the minimum information necessary where required or permitted by applicable law, including in response to a valid court, regulatory or law-enforcement request, or where necessary to protect users, rights, security or the integrity of the Service.
- Corporate Evolution: If Portals undergoes a merger, acquisition, corporate reorganization, or sale of assets, your personal data remains protected under this Privacy Policy. You will be notified of any change in ownership or data control before your information becomes subject to a different policy.
- Your Explicit Choice: If you choose to connect third-party integrations (such as Apple HealthKit or Google Health Connect), export content, post to the community, or send a mandala/"postcard" to another user, information is disclosed or made visible as necessary to carry out your action.
8. PROTECTION AGAINST PROFILING
We do not sell or disclose your individual wellbeing content, saved mandalas/text, or usage history to:
- Insurance Companies: To ensure your data is never used to influence premiums or coverage, or risk assessments.
- Data Brokers: We do not sell user profiles or behavioral data to third-party marketing databases.
9. ANALYTICS & ATTRIBUTION
To understand app performance and improve the Service, we use limited operational analytics, crash-diagnostic and attribution services. We do not use these services as a scientific research program.
- Operational Analytics: We use Statsig for product analytics. Statsig receives technical events and parameters such as app_open, practice_started, practice_resumed, practice_step_viewed, section_id, practice_id, step_id, practice_session_id, start_type, resume_count, platform, app_version and app_session_id. We do not send Statsig your email, username or human-readable iteration names.
- Crash Diagnostics and Attribution: We use Firebase Crashlytics for crash diagnostics and AppsFlyer for app-install/campaign attribution. The client application contains no Meta SDK or Google Ads SDK, does not send hashed email for advertising matching, and does not use IDFA or Apple cross-app tracking APIs.
- Your Control: Because the current iOS application does not use IDFA or Apple cross-app tracking APIs, it does not request permission through Apple’s App Tracking Transparency prompt for those activities. Where optional analytics, health integrations, cookies or communications are subject to user choice or consent, you may manage them through the relevant app, device or website controls.
10. DATA RETENTION & DELETION
We treat your data with a "shelf-life" mindset. We only keep what we need, for as long as it serves your self-regulation journey and the app mechanics you have chosen to engage with.
- We retain account data, saved mandalas and associated user-added text, and operational information for as long as your account remains active, unless a shorter period is required by law or the data is deleted earlier by you.
- When you delete your account, Portals initiates immediate deletion of your personal data from active systems and deletion of associated backups in accordance with the implemented deletion workflow. We also instruct applicable processors to delete or return personal data as required by our agreements and applicable law.
- We do not retain your Portals transaction or subscription records after account deletion except to the extent a specific record must be retained by law or is retained independently by the relevant App Store/payment provider under its own legal obligations.
11. INTERNATIONAL DATA FLOWS & GLOBAL OPERATIONS
To provide our services and real-time multiplayer functionality, personal data may be processed on regional cloud infrastructure.
- Portals uses AWS infrastructure with regional data hosting appropriate to the relevant service region.
- Where personal data is transferred internationally, we use the transfer mechanisms and safeguards required by applicable law, which may include adequacy decisions, contractual safeguards such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses, and applicable transfer mechanisms.
- We select infrastructure and service providers based on appropriate technical, organizational and contractual security requirements and periodically review those controls.
12. DATA SECURITY: THE CYBER-SHIELD FRAMEWORK
We treat your personal data with the highest level of rigor to protect your privacy and ensure a secure self-regulation journey. We implement a multi-layered security framework:
1. Encryption at Every Step
- In-Transit (TLS 1.3): Data transmitted between the Portals app and our controlled service endpoints is protected using TLS 1.3 where supported by the relevant connection and infrastructure.
- In-Storage (AES-256): Personal data stored in our production infrastructure is protected with AES-256 encryption at rest.
2. Data Isolation & Access Levels
We use logical separation and access controls within our database architecture to distinguish direct account identifiers from interaction/content data. These data may reside in separate tables within the same database rather than in physically separate databases.
- Access to personal data is restricted according to role and operational need. Authorized backend, support or administrative personnel may technically access data where necessary for support, security, maintenance or other legitimate operational purposes, subject to access controls and confidentiality obligations.
- Administrative Access: Authorized support or backend personnel may access account information and, where operationally necessary and permitted by their role, saved content or relevant session/usage information. Access is not represented as technically impossible.
- Private Text: Text or captions that you save are not visible to other users unless you choose to post or send them. They may be accessible to authorized backend personnel under controlled access. Portals does not currently represent this content as "zero-knowledge" encrypted.
3. Community Content & Public Visibility
- Private-by-Default: Content saved in your account, including saved mandalas and associated text, is not visible to other users unless you choose to post it, send it to another user, or otherwise make it visible through a sharing feature.
- Visible by Choice: Community content and mandalas/"postcards" that you choose to post or send are made visible to the selected audience or recipient. Portals does not provide private peer-to-peer chat. Once content is shared with another user or outside Portals, the recipient may copy, save or further distribute it, and Portals cannot control those subsequent actions.
13. YOUR PRIVACY RIGHTS AND CONTROLS
We believe you should have total clarity and control over your personal data. Regardless of whether you reside in the United Arab Emirates, the United Kingdom, the United States, or elsewhere globally, we provide these core privacy rights to all members, grounded in the UK GDPR, and applicable US state frameworks.
A. Core Privacy Rights
- The Right to Know & Access: You have the right to request a copy of the personal data we hold about you, provided in a structured, portable, and easily readable format.
- The Right to Correct: You can update or rectify your name, account credentials, email address, or password at any time directly within your in-app account settings.
- The Right to Delete ("Full Wipe"): You have the right to request the permanent deletion of your personal information across our operational systems. Execution of a "Full Wipe" adheres to the following protocols:
- Account Deletion: When you delete your account, Portals initiates immediate deletion of your identity, saved mandalas, associated user-added text and other personal data from active systems, together with associated backup deletion under the implemented deletion workflow, subject only to any retention specifically required by applicable law.
- Public Contributions: Any contributions you have made to public community forums will remain visible to preserve conversation continuity, but will be permanently stripped of your identity and relabeled as "Former Member."
- Legal & Statutory Exceptions: We retain information after account deletion only where a specific legal obligation requires retention; App Stores and other independent providers may separately retain their own transaction records under their applicable obligations.
- Data Portability & Limitations: Where applicable law provides a portability right, you may request a machine-readable export of eligible personal data you provided to us, such as account information and saved user content. This does not extend to Portals proprietary app mechanics, system iterations, algorithms, or information that would adversely affect the rights of other users.
B. Consent Autonomy & Feature Controls
- Feature Controls: You may delete saved mandalas and associated titles/text and may disconnect optional health integrations. Portals does not maintain a user-facing Journey Log of named completed iterations.
- Health Integration Revocation: You can disconnect Apple HealthKit or Google Health Connect at any time through your mobile device settings or within the app, instantly halting all background wellness metric synchronization.
C. Automated Decisions & Tracking Controls
- We do not subject you to decisions based solely on automated processing or profiling that produce legal or similarly significant effects. Automated app mechanics are used only to deliver requested content, operate progression and support app functionality.
- Mobile Tracking: The current iOS application does not use IDFA, ATTrackingManager/AppTrackingTransparency APIs, or other Apple cross-app tracking functionality. Accordingly, the app does not request an ATT permission prompt for such tracking. AppsFlyer is used for attribution as described in this Policy.
- Global Privacy Control (GPC): On our web platforms, we automatically detect and respect Global Privacy Control (GPC) signals transmitted by your browser, opting you out of non-essential third-party trackers instantly.
- You can review, adjust, or revoke your consent for specific categories of cookies and web trackers at any time using our Cookie Preferences Manager located in the app settings and website footer.
D. Exercising Your Rights
- To exercise any of the rights described above, or if you have questions regarding our data practices, please submit a verified request to our Privacy Team: Email: Privacy@portalslab.com
- We will acknowledge and process all valid requests within 30 days of receipt.
- We will never deny you services, charge different prices, or provide a lower level of quality if you choose to exercise any of your privacy rights.
14. CHILDREN’S PRIVACY & DIGITAL SAFETY
We are committed to maintaining the highest standards of digital safety and high privacy by default for younger users. While Portals is designed primarily for adults, our cognitive self-regulation tools may benefit teenagers, our data practices are guided by the specific age of consent in your jurisdiction.
- We do not knowingly collect or process personal data from individuals below the age of digital consent or minimum operational age set forth in our Terms of Use without explicit, verifiable authorization from a parent or legal guardian. Where local law sets a higher age threshold for digital consent than defined in our Terms of Use, we strictly adhere to the local statutory requirement.
- Users aged 13 to 17 may access wellness tools independently, but are automatically placed in a restricted High-Privacy Mode pursuant to the UK DUAA 2025 and UAE Federal Decree-Law No. 26/2025 on Child Digital Safety (CDS Law).
- High Privacy by Default (UAE CDS Law and UK AADC Compliance):
- We never use children's data for targeted advertising, marketing analytics or commercial profiling.
- Precise location tracking is permanently disabled for younger users.
- In compliance with the UK Age-Appropriate Design Code's "Best Interests" principle, our interface excludes persuasive design or "nudge techniques" that encourage excessive screen time.
- Parents or legal guardians may review, update, or request the deletion of their child’s information at any time by contacting us at Support@portalslab.com.
- Global Variation: However, we recognize that the legal age of consent varies by country. We strictly adhere to local regulations in every region where we operate. If we discover we have collected data from a minor below the local legal age without proper consent, we will take immediate steps to delete that information from our active systems.
15. IDENTITY VERIFICATION & AUTHORIZED AGENTS
To protect your sensitive wellness data against unauthorized access or fraudulent privacy requests, we implement strict verification standards.
- When you submit a request to access, correct, or delete your personal data (a "Full Wipe"), we verify your identity by matching provided details against our secure system records (such as account creation year or recent session metadata). Where applicable, we may utilize UK-certified digital identity verification services.
- You may designate an authorized agent to exercise privacy rights on your behalf. We require written, signed proof of the agent's authorization. To safeguard your sensitive cognitive data, we reserve the right to contact you directly to confirm your identity before executing an agent's request.
16. APPEALS AND COMPLAINTS
If we decline to take action on a privacy request, or if you have concerns about how your data is handled, you have the right to request a formal human review and escalate your request.
- You may appeal our decision by emailing Privacy@portalslab.com. Our Data Protection team will review your case, evaluate any additional context provided, and respond with a written determination within the period required by applicable law.
- If you have a complaint regarding our data handling practices, we encourage you to contact us at Privacy@portalslab.com so that we can investigate and respond. This internal process does not limit any right you may have to lodge a complaint directly with a competent supervisory authority.
- If you remain dissatisfied with our final internal response, you have the right to lodge a formal complaint with the appropriate supervisory authority:
- United Kingdom: The Information Commissioner’s Office (ICO) via ico.org.uk.
- United Arab Emirates: The UAE Data Office.
- European Union / EEA: Your local national Data Protection Authority (DPA).
- United States: The Federal Trade Commission (FTC) or your applicable State Attorney General (such as the California Attorney General for CCPA concerns, or the Washington State Attorney General regarding consumer health data).
- Kazakhstan / Global Headquarters: The Ministry of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan (Information Security Committee).
17. SUPPLEMENTAL NOTICES
Depending on your physical location and jurisdiction of residence, you have additional rights under local privacy laws. We provide this supplemental information to ensure compliance with those frameworks. Please note that APS Pay LLP is headquartered in Kazakhstan and utilizes secure, localized data infrastructure to process your information.
This section provides additional disclosures required by applicable regional privacy laws. Where a conflict exists between this Section 17 and the general terms of this Privacy Policy, this section shall supersede for residents of the respective jurisdiction.
A. INFORMATION FOR INDIVIDUALS IN THE UK, EEA, AND SWITZERLAND
This section applies specifically to users located within the United Kingdom, European Economic Area, and Switzerland.
- Data Retention & Archiving Protocols:
- Account credentials, saved visual constructs and associated user-added text, and other account data are retained for as long as your account remains active unless deleted earlier by you or a shorter period is required by law.
- Operational practice events may be recorded using internal technical identifiers; Portals does not maintain a user-facing persistent history of human-readable iteration names.
- Portals does not operate an automatic 24-month inactivity archive/deletion rule. Retention and deletion are governed by Section 10 and applicable legal requirements.
- Extended Regional Rights:
- You have the right to object at any time to the processing of your non-sensitive operational data conducted under our recognized legitimate business interests.
- You may request a machine-readable, structured copy of eligible account and user-provided data where applicable law provides that right.
- Under the UK Data (Use and Access) Act 2025 (DUAA) and UK/EU GDPR, when you submit a Data Subject Access Request (DSAR), we are obligated to conduct a "reasonable and proportionate" search across our systems to fulfill your request without undue delay and within 30 days.
- In addition to your right to request an internal review (Section 16), you have the right to lodge a complaint directly with your local supervisory authority (such as the Information Commissioner’s Office in the UK or your local EU/EEA Data Protection Authority).
- Data Controller and Cross-Border Transfers:
- APS Pay LLP. acts as the primary Data Controller for users globally (outside the Republic of Kazakhstan, which is subject to a separate localized policy).
- Personal data may be processed using AWS regional infrastructure and transferred internationally as necessary to deliver the Services.
- Cross-border data transfers originating from our Kazakh infrastructure or covering international users are conducted in compliance with Article 16 of RK Law No. 94-V On Personal Data and Their Protection, as well as applicable international mechanisms (including UK International Data Transfer Agreements/Addendums and EU Standard Contractual Clauses).
- Legal Basis for Processing:
Under the UK GDPR, EU GDPR, and UK Data (Use and Access) Act 2025 (DUAA), we rely on the following legal bases to process your data:
- Contractual Necessity: To deliver core app functionality, account authentication, and real-time self-regulation sessions governed by our Terms of Use.
- Consent: For specific opt-in features or optional communications, which you may freely withdraw at any time via in-app settings.
- Legitimate Interests: For network security, fraud prevention, and operational integrity, where our legitimate business interests are balanced against your fundamental privacy rights.
B. UNITED STATES PRIVACY NOTICES
This Supplemental Privacy Notice applies solely to residents of the United States. It supplements the Portals Global Privacy Policy to comply with comprehensive U.S. state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Washington My Health My Data Act (MHMDA), and applicable privacy frameworks in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, and other states with active comprehensive privacy legislation.
1. California Privacy Notice (CCPA / CPRA)
Categories of Personal Information Collected (Past 12 Months)
Portals is not a data broker. We do not sell your personal information or share sensitive wellbeing data for cross-context behavioral advertising. The following table describes the categories of personal information processed by Portals for the current Service.
| CATEGORY |
COLLECTED |
‘SOLD’/’SHARED’ |
| A. Identifiers (email or Apple private relay email, username, User ID, technical/device identifiers where applicable) |
Yes |
No |
| B. Customer Records (Payment history processed via App Stores) |
Yes |
No |
| C. Internet / Network Activity (App engagement and feature usage) |
Yes |
No |
| D. Sensitive / Consumer Health Information (where applicable: user-selected wellbeing iteration and optional HealthKit/Health Connect data) |
Yes |
No |
Automated Decision-Making Technology (ADMT)
Portals uses deterministic app mechanics and does not use AI or automated decision-making technology to make decisions about users that produce legal or similarly significant effects. We do not use automated processing to diagnose psychological or medical conditions.
Your California Privacy Rights:
- Right to Know & Access: You may request disclosure of the specific pieces and categories of personal information we have collected about you over the past 12 months.
- Right to Delete: You may request the permanent deletion of your personal information, subject to certain statutory legal exemptions.
- Right to Correct: You may request the correction of inaccurate personal information within your account settings.
- Right to Limit Use of Sensitive Personal Information: Where this right applies, you may limit qualifying uses of sensitive personal information. Portals does not use sensitive wellbeing information to infer characteristics for advertising or commercial profiling.
- Right to Non-Discrimination: We will not penalize you or discriminate against you for exercising your statutory privacy rights.
C. WASHINGTON AND NEVADA CONSUMER HEALTH DATA NOTICE
If you are a resident of Washington State or Nevada, or an individual whose data is collected in those states, please refer to our dedicated Consumer Health Data Privacy Policy for specific disclosures required under the Washington My Health My Data Act (MHMDA) and Nevada SB 370. This standalone notice governs our handling of health-related self-regulation selections and can be accessed directly at any time via the link in our website footer or in-app Privacy Settings.
D. PRIVACY NOTICE FOR OTHER US STATES
This section applies to residents of US states with applicable comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon and others.
- Collection and Use: We collect personal information and sensitive data (as defined by your state) solely to provide and maintain Portals application functionality. We do not use this data for targeted advertising, cross-context tracking, or commercial profiling.
- Because Portals does not sell your personal data for monetary or other valuable consideration, nor share it for targeted advertising, we do not trigger the requirement to provide an opt-out mechanism for the sale of personal data under laws such as the Nevada Privacy Law (NPL), the Virginia Consumer Data Privacy Act (VCDPA), or the Texas Data Privacy and Security Act (TDPSA).
- Where required by state law (such as in Colorado, Connecticut, Texas, Oregon, and Delaware), we automatically recognize and honor Global Privacy Control (GPC) opt-out signals transmitted by your device or browser.
- Residents may exercise applicable rights to access, correct, delete, or port data, and any applicable appeal rights, by contacting our Privacy Team at Privacy@portalslab.com.
E. ASIA-PACIFIC (AUSTRALIA, JAPAN, MALAYSIA AND SOUTH KOREA)
- Australia & Malaysia: We process your personal information in compliance with the Australian Privacy Principles (APPs) and the Malaysian Personal Data Protection Act. We do not maintain a local physical entity in these jurisdictions for our store-only model. Complaints regarding privacy practices can be directed to Privacy@portalslab.com.
- Japan (APPI): When transferring Personal Data outside Japan, Portals ensures that appropriate safeguards are maintained across our AWS cloud environments.
- South Korea (PIPA): We process data in compliance with the Personal Information Protection Act. As our processing currently falls below the statutory thresholds requiring a mandatory domestic agent, Portals directly handles all data subject requests. You retain the right to access, correct, and request the deletion of your data.
18. CONTACT US AND GLOBAL PRIVACY INQUIRIES
APS Pay LLP an Astana Hub resident entity incorporated in the Republic of Kazakhstan, serves as the primary Data Controller for users globally (excluding domestic residents of the Republic of Kazakhstan, who are governed by a separate localized Privacy Policy).
To streamline communication and provide a direct "single window" for all global privacy matters, all inquiries, rights requests, and communications regarding this Privacy Policy or our data practices are managed centrally by our primary Data Controller.
- Primary Data Controller: APS Pay LLP.
- Jurisdiction & Regulated Status: Republic of Kazakhstan / Astana Hub Resident
- Global Privacy Contact & DSAR Submissions: Privacy@portalslab.com
- General Support: Support@portalslab.com
- Users located in the United Kingdom, European Economic Area, United States, or other international jurisdictions may contact our central Privacy Team directly at Privacy@portalslab.com to exercise any of their statutory rights or submit privacy-related inquiries. All requests will be acknowledged and processed centrally from our headquarters within 30 days of receipt.