Security

How we protect your Notion workspace

Portalize holds an OAuth connection to databases you choose to share. That deserves a clear answer — not a “coming soon” badge. Last updated August 24, 2026.

The core guarantee

Clients never query your Notion databases directly. Portalize fetches data with your connection, applies row and field scoping on the server, and returns only what that client is allowed to see. A client cannot change a filter or navigate into another client's rows the way a Notion guest can.

Notion access

  • Connect via Notion OAuth (preferred). You authorize specific pages and databases — we only see what you share with the integration.
  • We use the token to read (and, when you enable editable fields on paid plans, write) the databases you configure for portal views.
  • We do not sell workspace data, train our own models on it, or expose one agency's data to another.
  • Optional setup suggestions may call OpenAI with schema metadata only (database titles, IDs, property names and types) — not Notion row contents or client records. You review suggestions before they are saved.
  • Disconnect Notion anytime from portal settings; revoke access in Notion as well for a full cut.

Where tokens and data live

  • Notion OAuth tokens are stored in our Postgres database hosted by Supabase. Application access is gated by authentication and row-level security so agencies only reach their own portals.
  • Traffic to Portalize uses HTTPS/TLS. Supabase encrypts database storage at rest at the infrastructure layer.
  • Portal config, clients, and views live in the same database. Cached Notion responses are short-lived and scoped to the portal and client.

Authentication

  • Agencies sign in with email/password or Google via Supabase Auth.
  • Clients use passwordless magic links — no Notion account required. Link expiry is configurable on paid plans.
  • Multi-tenant isolation: every API path scopes by portal (and client identity for portal data).

Subprocessors

We rely on these providers to run the product:

  • Supabase — auth and Postgres
  • Cloudflare — hosting and CDN
  • Stripe — payments (we do not store full card numbers)
  • Resend — transactional email (magic links, notifications)
  • Notion — source data you authorize
  • OpenAI — optional AI setup suggestions (schema metadata only)
  • PostHog and Google Analytics — marketing and agency product analytics (client portals are not tracked)

Retention and deletion

We keep account and portal data while your account is active. When you delete your account, we delete or anonymize personal data within 90 days except where law requires retention. Cancel a paid plan and your portal continues on Free forever within Free limits — details in pricing.

Compliance roadmap

We are not SOC 2 certified yet. Formal third-party audits are on the roadmap as the product matures. Until then, this page and our privacy policy are the source of truth for how we handle data.

Questions?

Security or data-handling questions from agencies evaluating Portalize — email us and we'll answer plainly.

hello@portalize.app