Skip to content

Three new Halloween themes. See them

Portage privacy

What Portage keeps about you.

Here’s what we store when you make a page and what we count when people visit it. If anything isn’t clear, email us at hello@cadenic.studio.

Last changed 7 October 2026

The short version

Portage keeps your email address so you can sign in, and whatever you put on your page. If you ask for news, we also use your email to send you the odd note about new features, and we’ll never email you asking for money. We count visits to your page without cookies and without storing anyone’s IP address. We don’t show ads or follow anyone around the internet, and we never sell anyone’s data.

The rest of this page goes into the details.

On this page14 sections
  1. The short version
  2. What we keep about you
  3. What we count when people visit your page
  4. Email addresses you collect on your page
  5. Cookies
  6. Other companies involved
  7. Identity and business checks
  8. If you ask about custom work
  9. If you suggest a feature or report a bug
  10. YouTube
  11. How long we keep things
  12. What you can ask us to do
  13. Children
  14. Changes, and who to write to

What we keep about you

Your email address, because it’s how you sign in and the only way we can reach you about your page. We don’t need anything else about you, and there are no other fields you have to fill in.

If you tick “Send me news about Portage” in the editor, we keep the date you ticked it and send you the occasional note about new features and what we’re working on. We won’t ask you for money or send you anything from anyone else. Every note has an unsubscribe link, or you can just untick the box. The date is deleted with your account.

What you put on your page: the words, links, colours and pictures. Your page is public, since that’s the point of publishing it.

Public doesn’t mean free to mine. Our robots.txt asks the crawlers that collect material for training AI to stay off every page at portage.camp/@ and off the pictures and files you upload, and both carry the TDM reservation at portage.camp/.well-known/tdmrep.json. Search engines aren’t asked to stay away. It’s a request, so crawlers that follow the rules stay out.

If you sign in with Google, Discord or Twitch, we ask for your email address and whether it’s verified. Discord and Twitch also send us your username, which we keep in a cookie for ten minutes so the editor can show it to you and, for Twitch, offer to add your channel to your page. Portage can’t post, read or join anything as you, because we never ask for that permission.

Pictures you upload are stored by us and served from our own domain. We save a fresh copy of each one as it arrives, which strips out the details a camera adds, including where a photo was taken.

If you buy Unmarked, we keep that it’s paid and when the paid year ends. While it’s active, your published page is shown without the Made with Portage credit.

If you ask someone to help run your page, or someone asks you, we keep who helps with which page, in which role, who added them and when. An invitation keeps the address it was sent to, who sent it, when, and a scrambled copy of its link that can’t be turned back into the link. The address on an invitation nobody answered is deleted a week after the invitation ends.

Each page keeps a history of who changed what: who published each version, who was invited, who joined or left, and when it was renamed or handed to someone else. Only the page’s owner and its managers see anyone’s address in it: the owner sees everyone’s, and a manager sees the addresses of the people on the page now, not of anyone who has left. It never holds a sign-up address, a private name or anything that would open the page. It’s kept for four hundred days, up to the newest two thousand entries for a page.

If you choose to pay by Interac e-Transfer, we keep the request you started: its reference code, what it’s for (with how much room, or which page when you pay for someone else’s), the amount, when you asked, and when the payment arrived and the paid year ends. The studio is emailed the code, the page it’s for (or, for room when you have no page of your own, the address you sign in with) and the amount, so we know to look for it. When your payment arrives, we email you a receipt at the address you sign in with. A request that’s cancelled or never paid is deleted ninety days after you made it, and a paid one is kept with your account as the record of what you paid.

If you pay by bank transfer, we keep the same request, with its currency, the country you told us you live in, and the country your connection came from when you asked. Tax rules ask us to keep those two as the record of where we sold, so they’re kept with the request. A request that’s cancelled or never paid is deleted ninety days after you made it, and a paid one is kept with your account.

If you support Portage and ask for your name on the list of supporters on /support, we keep the name or @handle you give us, how you said you gave, and anything you tell us to help find your support. Someone at the studio uses that only to match your name to a real gift, and deletes it as soon as they’ve decided. A name we can’t match is never shown and is deleted thirty days after you sent it, and one nobody has looked at is deleted after sixty. A matched name stays on /support until you ask us to take it off, and it never appears on your own page.

For the count of supporters on /support, the studio keeps a short note of each supporter it has found a gift from: how they gave, once or every month, the dates, and a note to recognise them by. It holds no amounts and no card or bank details.

If you made your account after tapping the Made with Portage credit on someone’s page, we note that page’s handle on your account. Whoever runs that page only sees how many people signed up from it.

If you make a link for a job application or a pitch on your numbers page, we keep the name you gave it and when you made it. Its opens are counted by the word in its address, like any other visit, and never say who opened it.

If you make a link that shares your page’s numbers, anyone holding it can see the totals you chose for the dates you chose until it stops working. We count how many times it was opened and when, never who, and we delete the link’s record ninety days after it stops.

When you press Find a picture on a link, we read that page once, identifying ourselves as PortagePreview and following its robots.txt, and keep a copy of the picture it shares with your uploads. A copy you don’t use is deleted within two days.

If you turn on 18+ for your page, as a section or for the whole page, we keep what you confirmed (that you’re 18 or older, and that everyone in the content you link to is an adult who agreed to it) and the date you confirmed it. It isn’t shown on your page, and it’s deleted with your page.

What we count when people visit your page

Views and link clicks, so you can see which of your links people use. With each one we note the day, the country, whether it was a phone or a computer, and which site the visitor came from.

If a page has an 18+ section, each time a visitor opens it is counted the same way, with the day, the country and the visitor hash below, so its owner can see how many people opened it. If the owner keeps the section closed in places they choose, the country and the province or state our host works out from the visitor’s connection are used at the moment they tap, to answer, and aren’t kept.

A visitor is identified by a hash of their IP address, their browser details, your handle, a secret held on our server and today’s date. That’s enough to tell two people apart today and means nothing tomorrow, because the date is part of it. The IP address and browser details are only used to work out the hash and are never saved.

A published page never sets a cookie of any kind, which is why a Portage page doesn’t need a consent banner.

When a visitor confirms they’re 18 or older to open an 18+ section, an 18+ link or a page marked 18+, their own browser keeps that answer for ninety days, with the date it runs out, so they aren’t asked again on every page. It’s kept in the browser’s own storage, and the only thing we’re sent is the request to open the section or link, which we count as described below. “Hide these links again” or “Ask me again” deletes it. It works for every Portage page on the same site. Nothing else about the visitor is kept with it.

To stop the forms on a page (a sign-up, a password, an 18+ confirmation or a report) from being abused, we count requests for a short while. We count a keyed hash of the IP address each request came from (and, for sign-in, of the email address asked for), and never store the address itself. Each count runs out within the hour and is deleted in the next nightly clean-up.

Separately, we keep daily totals of how the site itself is doing, with nothing that identifies anyone: how many sign-in links and codes were asked for and used, how many pages were made and published, how many people said they’d use a check on the verification page, and for each of those, whether it happened in an app’s own browser (like Instagram’s or TikTok’s) or a normal one. We work that last part out from the browser details at the time and don’t keep them. On the sign-up page we also note which of our own pages sent someone there.

Do Not Track and Global Privacy Control are both honoured. If a visitor’s browser sends either one, we don’t count the visit at all.

We don’t use advertising pixels, third-party analytics scripts or fingerprinting.

Email addresses you collect on your page

If you add an email sign-up block, the addresses your visitors give you are stored with your page, along with the day each one was given and, if your form asks which show is nearest, the place they pick. Nothing else.

They’re yours, and you can export them as a CSV whenever you like. We don’t email them, use them for anything of our own or give them to anyone.

If you ask people to help run your page as managers, they can see and download the list too. Editors can’t. While your page has a manager, your sign-up form says that the people who help run the page get the addresses as well.

Each address in the export comes with its own unsubscribe link for you to use in what you send, and you can remove any address, or all of them, from your numbers page. If you rename your page, the list moves with it.

You’re responsible for what you do with a list you collect, including telling the people on it what you’ll do with it.

Cookies

We only use cookies that are strictly necessary, to sign you in and to finish things you’ve started. None of them is ever set on a published page.

A session cookie that keeps you signed in. It lasts thirty days, and it’s renewed for another thirty when you come back with less than twenty-three days left. Only our server can read it, and signing out ends it everywhere.

A cookie that lasts ten minutes while you’re sent to Google, Discord or Twitch and back, so we can check that the sign-in coming back is the one you started.

A sign-in link cookie, set for twenty minutes when you ask for a sign-in link. It only holds a random value, and it lets us tell that the link is being opened in the browser that asked for it.

A cookie that lasts ten minutes when you sign in after pasting your old page’s address on the sign-up page. It holds that address, and the code of your preview if you made one, sealed so only our server can read it as yours. The editor reads it once to start rebuilding that page, or to open your preview, and it’s deleted as it’s read.

Two cookies, set for an hour when you’re asked to sign in partway through something, like buying a check or Unmarked, or deleting your account. They only hold the name of the page you were on, so we can take you back to it.

Three more cookies, each lasting ten minutes, are used when you sign in with Google, Discord or Twitch. One holds the choices you made before signing in, such as your handle and theme, the page whose credit sent you, and your old page’s address if you pasted one, with the code of your preview if you made one. One holds the example page you chose to start from, if you chose one. The last holds your Discord or Twitch username, so the editor can show it to you after you sign in.

Other companies involved

Vercel hosts the site. Supabase holds the database, in the eastern United States. Resend sends sign-in emails, invitations to help run a page, news to people who asked for it, receipts for payments made by e-Transfer, and custom work enquiries to the studio’s inbox. Each of them only sees what it needs to do that job.

When a page lists a Twitch, Kick, YouTube or Trovo channel, or a Discord server or event, our server checks its public details with that platform, like whether the channel is live or when the event starts. We never send them anything about your visitors, and we keep their answers for a few minutes at most.

If you show a Rumble live badge, you give us the private livestream address from your Rumble account. It’s stored encrypted and only our server uses it, to ask whether you’re live and what the stream is called. It’s never shown to anyone again, including you. Everything else in Rumble’s answer, including chat, rants, follower lists and the stream key, is thrown away as soon as it arrives.

A video, stream or music player on a page doesn’t load until the visitor taps it. Until then nothing is requested from YouTube, TikTok, Twitch, Kick, Spotify, SoundCloud or Vimeo, and nothing of theirs is stored on the visitor’s device.

Link verification reads the public profiles a page lists, looking for a link back to it. It identifies itself as PortageLinkCheck.

If you choose a video call for an identity check, it happens on Google Meet, from a link we email you, and it isn’t recorded. Google Meet opens on Google’s own site, nothing of Google’s runs on Portage, and Google’s privacy notice covers what Google Meet handles.

Didit runs the automatic identity check for us, if you buy one and choose it. It reads the photo of your ID and your selfie, checks the selfie is a live person and matches the face to the ID, and tells us whether you passed and the name on the ID. You don’t make an account with Didit, and the check happens on portage.camp. As soon as the check is decided, we ask Didit to delete everything from it, the pictures and the face data included, and its own setting deletes anything left after thirty days at most.

When an app card has a TestFlight public link, our server reads that link’s public page on testflight.apple.com once a day, identifying itself as PortageBetaCheck and following Apple’s robots.txt, to see whether the beta has room. It keeps one word (open, full, closed or gone) and nothing about your visitors.

When you ask us to bring in your old link page, our server reads that one page once, identifying itself as PortageImport, and follows the site’s robots.txt. We keep nothing from it except what you choose to add. Its picture, and up to sixteen of the small pictures beside its links, are copied into our storage so you can see them while you choose, and copies you don’t keep are deleted within two days. Each read is counted in a daily total with nothing that identifies you: the site’s domain (never the page address or your handle), whether it worked (and if it didn’t, why), roughly how many links it found, and whether you went on to build a page. If you save the page and choose the file yourself, or copy the page and paste it into your editor, it’s read in your own browser, and all we get is that same count, plus the site’s domain if the page names one.

You can also see your old page rebuilt before you sign up, on the home page or the sign-up page. Our server reads it the same way, once, or reads the copy of the page you paste in, which is thrown away as soon as it’s been read. What we made of it (its name, bio, links, headings and profiles, the address it came from, and small copies we made ourselves of its picture and of up to six of the first pictures on it) is kept for thirty minutes under a random code, so that signing up can open it in your editor without reading your page again. After thirty minutes it can’t be opened, and it’s deleted as newer previews are made. Nothing about who asked is kept with it. To stop previews being abused, we count a keyed hash of the IP address each one came from, never the address itself, and that count runs out within the hour.

When you ask, by typing your Instagram or TikTok username (or pasting your profile) on the home page or the sign-up page, our server reads your own public Instagram or TikTok profile, and the link page it points to, once, signed out, even where those sites ask automated readers not to. It identifies itself as PortageBot and never signs in or uses any account. It keeps only what goes on your page: your name, your bio, your links, and a copy we make ourselves of your profile photo, held with the preview for the same thirty minutes. The profile page itself is thrown away as soon as it has been read. To stop the same profile being read twice in a row, what was found is remembered for ten minutes on that server, and to stop abuse we count a keyed hash of your IP address, never the address itself, for an hour.

Paying for a check, Unmarked or room by card isn’t open yet. Before it opens, this notice will name the company that takes card payments and say what it’s told.

A gift by card is given through Gumroad (gumroad.com), the merchant of record for gifts. Its checkout opens on portage.camp, you need no Gumroad account, and Gumroad’s privacy notice covers what you give it there. The link we hand Gumroad carries a random note, signed so nobody can change it, so we can tell when your gift is in; it names nobody. In our Gumroad account we see the amount and the name, email address and country you give Gumroad, and we use them only to count you as a supporter and for any question about your gift.

Bank transfers, and Interac e-Transfers, land in Cadenic Studios’ business account at Wise (wise.com). When one arrives, our server reads it from Wise and we see the name on the account it came from, that account’s details as the sending bank passes them on, and the reference or message you added. We use them only to match the payment to your request, to send back money that isn’t ours, and to keep our records. We keep the sender’s name, the country of their bank, the last four characters of their account number and the reference, never the whole account number, for six years, as tax rules require. We never see your bank login.

A refund, or money we can’t match to a request, goes back to you by bank transfer from Wise, to the account it came from.

Support given by card counts you as a supporter by itself, with no amount and nothing about you kept with it, and leaves the count if the gift is refunded. Your name goes on the list only if you ask. Support sent by e-Transfer is handled like any other e-Transfer.

Anything bought through Polar before 28 September 2026, or on Stripe’s checkout after that, stays with them until it ends. They tell us only what was bought and until when, and they hold the card details, not us.

Some of these purchases can go through RevenueCat instead, which handles subscriptions in the studio’s apps. RevenueCat also only tells us what was bought and until when, so we don’t see a card number there either.

Every program of ours that reads other sites is listed on one page, with what it reads, how often and how a site can turn it away.

Identity and business checks

Both are optional and neither adds a feature. After you pay (by e-Transfer, once your payment has arrived), you can do the check yourself on /verify.

For an identity check, you photograph a government ID and take a short selfie, on portage.camp, and Didit checks the ID, checks the selfie is a live person and matches your face to the ID. If the check doesn’t go through, you can try once more. You can also choose a short video call with a person at the studio instead, at any time. It’s on Google Meet, from a link we email you: you hold the ID up to the camera, and they compare its name with a private name you give us and check you’re the person your page shows. The call isn’t recorded, the document is never copied or photographed, and we’ll never ask you to email one. Google’s privacy notice covers what Google Meet handles.

Before the automatic check opens, a screen tells you what it collects (a photo of your ID, a short selfie, and face data: measurements of your face that show the selfie is a live person and match it to your ID), why, that Didit does it, and how long each part is kept. The check only starts once you tick “I agree”, which starts unticked, and the video call is offered right beside it as an equal choice. You can stop at any point before the check is done. We keep the date you agreed, and which version of that screen you saw, with the check’s record, for as long as the record is kept.

Either way, the check is of the name on your ID, never the name on your page, which can be a stage name, an alias or anything you like. For a page with an 18+ section, it confirms a real adult owns the page. Your date of birth is used only for that, to confirm you’re 18 or older, and it isn’t kept.

The automatic check reads the name on your ID and we keep it privately. If you choose the call, you can give it to us on /verify or in the editor, or just tell the person doing your check. It’s used for nothing but your check. Nobody sees it unless you choose the call, when only the person doing your check does, on the call and on the studio’s own list of checks, and it never appears on your page, on your mark or anywhere else public. It’s stored encrypted. It’s never sold, and we only hand it over if a court or the law makes us, telling you first unless the law stops us. Once it’s saved we don’t show it in your account, even to you, so nobody who gets into your account can read it. We keep it while your check is current, in case anyone questions your mark, and delete it thirty days after your check ends, within a day of a refund if your check doesn’t pass, or thirty days after you saved it if you never buy a check. You can delete it yourself at any time, and it’s deleted with your account. A deleted name can stay in our database’s backups, still encrypted, for up to 30 days.

For a business check, you show us your business’s own website is yours, with a code we email to an address at its domain, a DNS record or a tag on its home page, and the website links to your page (or your page uses that domain). We look again once a year; if the proof has gone, we email you, and the mark comes off fourteen days later if it’s still gone. With no website of your own, a person at the studio reads the public registration record for your organisation instead. We don’t ask for anything private.

Apart from the name on your ID, what we keep is the result: which check, whether it passed, the date, and for an automatic identity check, Didit’s reference and the date you agreed to it; for a business, the website it proved, which way, and the dates we checked, or the registry and jurisdiction the mark names. We never keep pictures of your ID or its number. A code we email is kept only in a scrambled form for fifteen minutes, and we don’t keep the address it went to. It’s kept while the check lasts and deleted with your account; the record of an automatic check that didn’t pass is deleted after a year. If a check can’t pass, you get a full refund.

If you ask about custom work

If you ask about custom work, what you send (your name, email, message and any links) goes by email to Cadenic Studios’ inbox. It’s only used to reply and, if you go ahead, to do the work, and it’s deleted if you ask. It’s never added to a mailing list.

If you’re signed in when you send it, your page’s handle goes with it, so we know which page you mean. A copy is written to the server’s log just before the email is sent. The only thing you’ll get back is our reply.

When you send us an enquiry through the form, we keep a copy for ninety days so nothing’s lost if an email goes astray, then delete it.

If you suggest a feature or report a bug

If you use “Suggest a feature” or “Report a bug”, we keep what you write and, for a bug, what you were doing and which page on portage.camp it happened on; your account if you’re signed in, or an email address if you’re signed out and give one for a reply; the date; and whether we’ve dealt with it. Nothing about your connection or browser is kept with it. It’s used only to read it and reply to you, only Portage staff see it, and it’s deleted a year after you sent it. If you delete your account before then, it stays with nobody named.

YouTube

Portage uses YouTube API Services. A page can show a creator’s YouTube videos in YouTube’s own player, their newest upload, and a live badge while their channel is streaming. The newest upload is read from the channel’s public feed, and the live badge also asks YouTube’s Data API about the channel’s newest videos.

By using the YouTube parts of a page, such as pressing play on a YouTube video, you agree to YouTube’s Terms of Service. Google’s Privacy Policy covers what Google does with what it receives. Portage doesn’t send YouTube anything about the visitor. Our server only asks about the channel, and uses each answer for a few minutes at most.

How long we keep things

Your page, for as long as you keep it.

Anything you take off your page is kept for 30 days, so a mistake can be undone: earlier versions of your page, with the blocks in them, and pictures, videos and files you remove or replace. Every version you publish is kept for 30 days after you publish the next one, and your last 30 however old they are; a version you’ve named is kept until you delete it. In those 30 days you can restore a version, or put an upload back, from Versions in the editor, or ask us to. Then the nightly clean-up deletes them.

So this can’t fill up, we keep at most 500 versions and 200 MB of removed uploads for each page, and past that the oldest go first. An upload you never published is deleted after a day, and a version you delete yourself goes straight away.

If you delete your account, we keep your page, its versions and your uploads out of sight for 30 days, so we can bring them back if it was a mistake: email hello@cadenic.studio from the address you signed in with and ask. Nobody sees them in that time, and after 30 days they’re deleted. Nothing else is kept: your numbers, your email list and the rest go straight away, and a paid mark or Unmarked doesn’t come back by itself.

A handle you give up, by renaming or deleting your page, is held for ninety days so no one can take it and pretend to be you. Nothing of yours is kept with it. After a rename you can take it back in that time, but after deleting your account you can’t. If you rename more than three times, only the three handles you gave up most recently are held. After ninety days anyone can claim it.

Visit and click records, for four hundred days, then a nightly job removes them.

Sign-in links and the six-digit code that comes with each, for twenty minutes. Using one uses up both, and a code stops working after five wrong tries. We only store a keyed hash of each one.

If your page was taken down after a report, we keep a copy of it out of sight for a year from the takedown, even if you delete your account, because the law can require us to hand it over. Then it’s deleted.

Our database’s backups are kept for up to 30 days, so something deleted can stay in them until they roll over. That includes the name on your ID for a check, still encrypted, where nobody can read it without our key. Nobody reads the backups; they’re only there to recover the database if something goes wrong.

The studio’s own record of each payment (what was paid for, how much and when) is kept in our accounts for six years, because Canada’s tax rules require every business to keep one. It holds no card or bank details, and it stays even if you delete your account.

What you can ask us to do

Export everything without asking anyone: your page as JSON from the editor, and your numbers and subscriber list as CSV from your numbers page.

Get back something you took off your page: restore a version or put an upload back from Versions in the editor within 30 days, or email hello@cadenic.studio and we’ll do it for you.

Delete everything: type your handle at the bottom of the editor and your account and page are deleted, with everything attached to them, including pictures, files, versions, numbers and your subscriber list. Nothing is kept back for analytics. Your page, its versions and your uploads are kept out of sight for 30 days in case it was a mistake, then deleted. If you’d rather, email hello@cadenic.studio from the address you signed in with and we’ll do it for you. Pages you only help with stay with their owners, and their history keeps that someone who has since left made a change, without your address. A page we took down after a report is kept longer: see How long we keep things.

Correct anything: you can change your page in the editor, and for anything else, just email us.

If you’re in the UK or the EU, these are your rights under the UK GDPR and the GDPR, and this is how you use them here. If you’re in Canada, the same rights apply under PIPEDA and Alberta’s PIPA.

Children

Portage isn’t meant for children under 13, and we don’t knowingly hold information about one. If you think we do, email us and we’ll remove it.

Only people who are 18 or older can turn on an 18+ section or mark a page 18+.

Changes, and who to write to

If we change this notice in a way that affects your data, we’ll update the date at the top and say what changed.

Portage is made by Cadenic Studios, and it’s the studio that looks after what’s described here. Cadenic Studios is a sole proprietorship owned by Wyatt McPherson in Edmonton, Alberta.

Cadenic Studios, Edmonton, Alberta, Canada.

7 October 2026

  • Before the automatic identity check opens, a screen says what it collects, why, who does it and how long each part is kept, and the check only starts once you tick “I agree”, with the video call offered beside it as an equal choice.
  • We keep the date you agreed, with the check’s record. The video call for a check is on Google Meet, and it isn’t recorded. Anything you take off your page (earlier versions, and pictures, videos and files you remove or replace) is now kept for 30 days so you can get it back, and if you delete your account, your page, its versions and your uploads are kept out of sight for 30 days so we can undo a mistake. We now say that our database’s backups last up to 30 days. And the Suggest a feature and Report a bug form keeps what you send for a year, for staff to read and reply to.

6 October 2026

  • Card payments through Paddle never opened, and Paddle took no payment for Portage. Until paying by card opens, every check, Unmarked or room is paid by Interac e-Transfer.

3 October 2026

  • When you ask, we read your own public Instagram or TikTok profile, and the link page it points to, once, even where those sites ask automated readers not to, and keep only what goes on your page.

2 October 2026

  • A page made for someone by Portage can start with a photo of them from a website that allows it, such as their shop’s own team page.
  • A check, Unmarked or room paid by card is sold by Paddle, which is told only the ids of your account and your page, and Gumroad now takes gifts alone, with a signed link that names nobody.
  • There is no monthly gift by card for now.

1 October 2026

  • An identity check is done automatically first, through Didit, on portage.camp, and a call with a person is something you can choose instead.
  • We keep only whether it passed, the date, Didit’s reference and the name on your ID, encrypted, and Didit deletes the rest as soon as the check is decided.
  • A business check can be done by showing us your business’s website is yours, and we look again once a year.
  • Every card payment, support included, goes through Gumroad, which is the seller for them, in a checkout on portage.camp that needs no Gumroad account.
  • We pass Gumroad your sign-in email to fill in, and a signed note of your account and page that it hands back with the sale.
  • Support by card counts you as a supporter by itself.

30 September 2026

  • People can help run a page they don’t own, so we keep who helps with which page, the invitations, and each page’s history of who changed what, and a page’s managers can see its sign-up list.
  • You can pay by Interac e-Transfer, and we see the name on the account it comes from only to match it.
  • We email you a receipt when your e-Transfer arrives.
  • If you support Portage, you can ask for your name on the list of supporters, and we keep a note of each supporter we count, with no amounts.
  • We now say that the studio keeps its own record of each payment for six years, as tax rules require.
  • A page taken down after a report is kept out of sight for a year, even if its account is deleted.
  • The preview of your old page keeps small copies of up to six of its first pictures, for the same thirty minutes.
  • A sign-up form can ask which show is nearest, and keeps the place each person picks.
  • Opens of a page’s 18+ section are counted like views, and a section kept closed in chosen places uses where a visitor’s connection appears to be without keeping it.
  • You can make links for job applications and links that share your numbers, and we keep what each one is and how often it was opened, never who.
  • Find a picture reads the page a link goes to once and keeps a copy of its picture with your uploads.
  • We read a TestFlight public link once a day to see whether the beta has room.

29 September 2026

  • If you turn on 18+, we keep what you confirmed and the date.
  • A visitor’s answer to “I’m 18 or older” is kept in their own browser for ninety days.
  • For an identity check you can give us the name on your ID privately (how it’s kept and when it’s deleted is under Identity and business checks).
  • You can see your old page rebuilt before you sign up, which we keep for thirty minutes.

That’s all of it.

Questions about any of this? Email hello@cadenic.studio and a person will answer.

Make my page