Privacy policy
Last updated September 23, 2026
Folio is a research workspace for reading, highlighting and writing. This page explains what information Folio collects, why, who helps us process it, and the choices you have. We keep it short and specific to how Folio actually works.
What we collect
- Waitlist. If you join the waitlist, we store your email address, when you joined and which form you used, so we can invite you.
- Your account. When you sign in with Google or email, we receive your email address, a user ID and whether your email is verified.
- Your workspace. The notes, projects, tags, highlights, comments and chat history you create, and the sources you add — PDFs you upload, copies of web pages, YouTube transcripts and X posts you import.
- API keys you add. If you save an OpenAI or Anthropic key, it is encrypted before it is stored and is only used to make requests you ask for.
- Usage. Page views and a small set of product events (for example, creating a note, importing a source or sending a chat message), linked to your account, plus the number of AI tokens you use so we can apply plan limits.
- Billing. If you subscribe, payment is handled by Stripe. We store your subscription status and a Stripe customer ID; we never see or store your card number.
- Error reports. When something breaks, we record the error message, the page and your user ID so we can fix it.
How we use it
To run Folio for you: to store and sync your workspace, answer your questions, suggest subject tags, apply your plan, send you service emails (such as verification and invites), keep the service secure, and understand which features are useful. We don’t sell your information, and we don’t use your notes or sources to advertise to you.
The AI assistant
When you ask the assistant a question, Folio sends the relevant context — your selected passage, the highlights on that page, your current note and the recent conversation — to the AI provider you chose (OpenAI or Anthropic) to generate the answer. When you ask for subject tags, Folio sends the item’s title and an excerpt of its text. You can see exactly what was sent for any answer with “Inspect sent context”. On the bring-your-own-key plan, these requests are made with your key under your agreement with that provider.
Who helps us
- Google Firebase (Google Cloud) — sign-in, database and file storage for your workspace.
- Vercel — hosting the website and API.
- OpenAI and Anthropic — generating assistant answers and tag suggestions.
- Stripe — subscriptions and payments.
- PostHog — product analytics.
- Telegram — private alerts to the Folio team about errors and new waitlist signups.
These providers process information on our behalf and may store it outside your country.
Keeping and deleting your information
Your workspace is kept while your account is active. You can delete notes, sources, highlights and chats in the app at any time; deleting a note also deletes its sources, highlights and chats. To delete your account, leave the waitlist or get a copy of your information, email us and we’ll do it. Some records, such as billing history, may be kept where the law requires.
The Mac app
The upcoming Mac app keeps your notes as Markdown files in a folder on your computer. Anything it sends to an AI provider follows the same rules described above.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your information, to object to or restrict certain processing, and to complain to your local data protection authority. Email us to exercise any of these rights.
Changes
If we change this policy in a meaningful way, we’ll update the date above and, where appropriate, tell you by email or in the app.
Contact
Questions or requests: hello@getfolio.work.