Legal
Privacy Policy
Last updated: 4 July 2025
Folio (“we”, “our”, “the service”) is a tool for publishing AI-generated HTML reports as shareable URLs. This policy explains what data we collect, why we collect it, and how long we keep it.
1. Who we are
Folio is operated as an independent service accessible at folio.ac. Questions about this policy can be sent to privacy@folio.ac.
2. Data we collect
When you publish a report
- The HTML content you submit.
- An optional title you provide.
- An optional password hash (SHA-256) if you choose to protect the report.
- Timestamp and expiry date.
When someone views a report
- Approximate country and city (derived from IP address via server-side lookup; the raw IP is not stored).
- Device type (mobile / tablet / desktop), browser name, and operating system — inferred from the User-Agent header.
- Time spent on the page (duration in seconds), measured client-side and sent when the tab closes.
- Timestamp of the view.
When you sign in
- Your Google account name, email address, and profile picture URL — provided by Google OAuth.
- An optional username you choose to claim.
- A personal API key generated on request (stored hashed-equivalent; displayed only once in the dashboard).
When you leave a comment
- The comment text you write.
- The position on the report where you placed it (percentage coordinates).
- Your user account (name, profile picture) and a timestamp.
3. How we use your data
- To serve published reports to anyone with the link.
- To show report authors analytics (views, countries, device types, average time on page) in their dashboard.
- To display comments on reports to viewers.
- To authenticate you via Google OAuth and maintain your session.
- To link API-published reports to your dashboard when you use your API key.
We do not sell data, serve ads, or use your data for any purpose beyond operating the service.
4. Data retention
- Published reports expire after 7–90 days (chosen at publish time). Expired reports and all associated views and comments are deleted.
- Account data (name, email, username) is kept while your account exists. You can request deletion by emailing us.
- View logs are deleted when the parent report is deleted.
5. Third-party services
- Google OAuth — used for sign-in. Subject to Google's Privacy Policy.
- Vercel — hosts the application. Receives standard web request metadata (IP, headers) per their privacy policy.
- Turso — hosts the database. Data is stored in their infrastructure and subject to their data processing terms.
No analytics platforms, advertising networks, or tracking pixels are used.
6. Cookies and sessions
We use a single session cookie to keep you signed in via NextAuth. If you password-protect a report, a separate cookie stores the verified status for that report so you are not prompted again on the same device.
No tracking cookies or third-party cookies are set.
7. AI integrations
Folio provides a publishing API used by AI tools (ChatGPT Custom GPT Actions, Claude Code MCP, and others). When an AI tool publishes a report on your behalf using your API key, the same data listed in section 2 applies. We have no visibility into the conversation that generated the content — we only receive and store what the tool sends us.
8. Your rights
You may request access to, correction of, or deletion of your personal data at any time by emailing privacy@folio.ac. We will respond within 30 days.
9. Changes to this policy
If we make material changes, we will update the date at the top of this page. Continued use of Folio after changes constitutes acceptance of the updated policy.
Questions? Email privacy@folio.ac.