Privacy notice
How the hosted Portal Heaven service processes account, connection, playback, security and provider data.
Last updated: July 22, 2026. This notice applies to the hosted service at portalheaven.stream. Independent self-hosters are responsible for their own privacy notices.
Who operates the service
The Portal Heaven service operator is the controller for data processed by the hosted service. Privacy requests can be sent to portalheavenstream@gmail.com.
Information processed
- Account details such as username, email address, role and authentication status.
- Encrypted saved connection configuration, favorites, preferences and playback progress when synchronization is enabled.
- Session identifiers, security events, IP address, browser information and diagnostic logs used to prevent abuse and operate the service.
- Billing status and provider identifiers for paid plans. Portal Heaven does not store complete payment-card details.
Provider requests and media
When you add a third-party source, Portal Heaven sends authentication and metadata requests needed to use that source. Direct media requests go from your browser to the provider. If you explicitly use a compatibility relay, media temporarily passes through the hosted server. Portal Heaven does not sell or supply IPTV content.
Why information is used
Information is used to authenticate users, synchronize requested settings, enforce account limits, provide support, process subscriptions, prevent fraud and abuse, diagnose failures and maintain service reliability. Where consent is required for optional analytics, it must be obtained before those analytics are enabled.
Service providers
Depending on enabled features, data may be processed by Cloudflare for Turnstile and network security, Google or GitHub for OAuth login, Brevo for transactional email, Stripe for billing, Google Analytics for optional usage measurement, and the infrastructure provider hosting the service. Each provider processes information under its own privacy terms.
Storage and retention
Account and synchronized connection data are retained while the account remains active or until the user deletes them. Authentication sessions expire automatically. Operational and security records are retained only for the period needed for security, troubleshooting and legal obligations. Backup copies are removed as they age out of the operator's backup cycle.
Your choices and rights
You can remove saved connections and local browser data through application controls. You may request access, correction, export or deletion of hosted account data by contacting the address above. Requests may require identity verification. You can also use guest mode to keep supported data in the browser rather than synchronizing it to an account.
Security and international processing
Saved provider credentials are encrypted in the browser before synchronization. No internet service can guarantee absolute security. Service providers may process data outside your country under their applicable safeguards.
Children and changes
The hosted service is not directed to children under 13. Material changes to this notice will be published on this page with an updated date.