Portal Property Insights

Privacy policy

Last updated 7 October 2026. Applies to the Portal Property Insights Chrome extension and the service it connects to at pi.cypherpress.com.

Who we are

The extension and its service are provided by Cypherpress. We are the data controller for the account and usage data described below. You can reach us at pi@cypherpress.com.

What we collect

DataWhenWhy
Email address and password When you sign in or create an account. To identify you and show your private data. The password is sent once over HTTPS and is never stored by the extension.
Sign-in session tokens After you sign in. To keep you signed in without asking for your password each time.
Listing details from the page When you open a listing on Rightmove, Zoopla or OnTheMarket. The listing ID and property type are sent to our service so it can return sale history, EPC data, comparables and any matching records of yours. On Zoopla and OnTheMarket the request also includes the postcode or outcode, the agent’s reference and brand, and the property or energy certificate identifiers (UPRN or EPC), where the page shows them. This request is made when a listing opens, whether or not you are signed in. Other features send what you enter or choose, such as a postcode for an evidence search.
Content you create When you use the features. Favourites, hidden listings, saved comparable evidence, and team membership and invitations, so they are there next time you sign in.
Client records you import Only if you upload a CSV file. To show you when a listing matches one of your clients. See client data you upload.
Technical request data Whenever the extension contacts our service. Like any web service, our server receives your IP address and request details so it can respond. We do not log user activity.

We do not collect your browsing history, the content of other tabs, or anything from websites other than the three supported listing sites. We do not use analytics or advertising trackers in the extension.

What is stored in your browser

The extension uses Chrome’s extension storage for the following:

  • Local storage on this device: your email address, your account brand code, account settings returned at sign-in, and your sign-in session tokens.
  • Sync storage: a list of email addresses you have signed in with, so you can switch accounts quickly. Chrome syncs this through your Google account if you have Chrome sync turned on. It contains no passwords or tokens.
  • Session storage: the identifier of a pop-up window the extension opened, which is cleared when the browser closes.

In Incognito windows the extension keeps your sign-in only in memory. It is never written to disk and is lost when the private window closes, so you may need to sign in again.

How we use it

We use your data only to provide the features you see in the extension: signing you in, returning property information, matching listings to your records, and saving what you choose to save. We also use technical request data to keep the service secure and working.

We do not sell your data. We do not use it for advertising, and we do not use it to decide whether anyone is creditworthy or should be given a loan.

Chrome Web Store user data policy

The use of information received through Chrome extension APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the single purpose described on the home page. It is not transferred to others except to provide that purpose, to comply with the law, or as part of a merger or sale of the business. People do not read your data except with your consent, to investigate abuse or a security problem, or to comply with the law.

Who we share it with

We share data only with service providers who host and operate our service, under contracts that require them to protect it. We may also disclose data where the law requires it.

Sale history and EPC data come from public UK datasets held on our own servers. Listing details are not sent to Rightmove, Zoopla, OnTheMarket or any other third party by the extension.

Client data you upload

If you import client records, they are your data. You are the controller of that personal data and we process it on your behalf, only to show you matches. You are responsible for having a lawful basis to hold and use it, and for telling your clients about it as the law requires. Records are visible to the members of your own team account and not to other customers.

Keeping and deleting data

  • In your browser: sign out from the account menu to clear your session. Removing the extension deletes everything it stored locally.
  • Client records you imported: you can delete some or all of them yourself while signed in, using Manage clients in the account menu and choosing Delete data.
  • Closing your account: email pi@cypherpress.com from your account address and ask us to close it. When an account is closed, the data linked to it is deleted immediately.

Security

All communication between the extension and our service uses HTTPS. Passwords are used only at the moment you sign in. Sign-in sessions are short-lived and renewed with a separate token. No system is perfectly secure, so please use a strong, unique password.

Your rights

Under UK data protection law you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to move it. To use any of these, email us and we will reply within two working days. If you are unhappy with our response you can complain to the Information Commissioner’s Office.

The service is for business use by adults and is not directed at children.

Changes and contact

If we change what the extension collects or how we use it, we will update this page and the date at the top before the change takes effect. For questions about this policy, contact pi@cypherpress.com.