← Back to Folio
PRIVACY

Your data in Folio

Folio is operated by Rishi Challa. Privacy contact: goodrishi@yahoo.com.

Updated October 8, 2026.

Google sign-in

Folio receives your verified email address and Google account identifier to create or reopen your library. It requests only identity and email access. It does not request access to Gmail, Drive, Contacts, or your Google files. Google access tokens and identity tokens are used during sign-in and are not retained. Your Google identifier connects your books and audio credits across devices.

iPhone purchases

Apple processes iPhone in-app payments. RevenueCat validates App Store purchases and receives your Folio account identifier, purchase history, subscription status and app/device metadata needed for billing. Folio does not send your documents, audio, highlights, email or name to RevenueCat. Verified audio balances and paid access sync across your Folio account. Folio retains transaction references to prevent duplicate credits and support refund review. Apple handles App Store payment information and refund requests.

Apple sign-in

When you choose Sign in with Apple, Folio uses Apple’s verified email address (which may be a private relay address) and account identifier to create or reopen your library. Apple sign-in requests identity, name and email access; Folio does not retain an Apple-provided name. Identity tokens and authorization codes are used during sign-in and are not retained. A short-lived verified identity handoff is cleared when sign-in completes or expires. Connecting Apple to an existing library requires proof of access to that library.

Public page measurement

We count visits, sample plays and try-document clicks on a fixed list of public pages. If you continue into Folio in the same browser tab, a temporary page label lets us count upload attempts and first playback for up to 24 hours. We do not include document text, filenames, private URLs, search terms or referrers in these events, or attach account identifiers to them. Individual events are retained for 30 days and daily aggregate counts for 90 days. A daily keyed hash of the network address limits anonymous event submissions; raw addresses are not stored in this measurement system. The temporary page label uses session storage. These measurements respect the browser’s Do Not Track setting.

Your documents and audio

Uploaded documents, generated audio, library information, and sharing links are stored using Cloudflare Workers, D1, and R2. A local Mac operated by Folio extracts document text and generates narration. That processor keeps working files and cached narration chunks so interrupted conversions can resume. Standard books are retained in cloud storage for one year; books marked permanent have no automatic expiration.

Your narration voice

Unlimited members can upload their own voice recording and its transcript, hear a generated preview, and save the approved voice to their private account. In-app recording requires microphone permission and stays in your browser until you select Upload and hear sample. Closing the voice setup screen discards that local recording. Recordings pass through Cloudflare private storage and are processed on the Mac operated by Folio using a local speech model. We do not send recordings to a paid voice-generation service. Drafts expire after 24 hours. Approved voice references and their transcripts stay saved until replaced or deleted. Temporary reference recordings on the Mac are removed after processing. A replaced reference may remain while an unfinished book still needs it, then is removed automatically. Finish or cancel unfinished books before deleting their saved voice. Deleting a voice prevents future use of that reference; it does not delete existing narrated books or copies already shared or downloaded. Unlimited is required for setup and new narration; saved voices remain available for renewal after a subscription ends.

Document type

Folio may use small excerpts from the beginning, middle and end of extracted text to suggest whether a file is a book or another document. Classification runs through our existing local inference service on the Folio Mac. It does not send your document to TypeSafe or another classification provider. The suggested label is saved with your library item, and you can change it.

Read-along and document questions

Read-along uses extracted text and saved narration timing. When you ask a question, Folio sends your question and selected passages through Cloudflare and an encrypted Tailscale connection to a local model on the Mac operated by Folio. AI can make mistakes; source excerpts are shown for checking. Word lookup sends only the selected word to FreeDictionaryAPI.com, with Free Dictionary API (dictionaryapi.dev) as a fallback; a short passage excerpt goes to the same local model for its contextual explanation. Dictionary definitions may be cached publicly; contextual explanations stay in temporary memory in your browser. Questions and answers are not saved as chat history. We keep daily usage counters to control costs and abuse. Saving a book offline also saves its available read-along text on your device.

Sharing and offline listening

Anyone with a private listening link can play or download its audiobook and view the text covered by its narration. Revoking the link prevents future access through that link, but cannot remove copies someone already saved. Offline audio is stored in the listener’s browser on their device. Playback position and preferences are stored locally and sync to your private account in Cloudflare D1 when you are signed in. The iPhone app stores offline downloads on your phone and account tokens in the iOS Keychain. We also store device names and expiring mobile authorization, session, and audio-access records. Clearing website data can remove these local copies and settings.

Book clubs

Clubs are invite-only. Club names, membership names, readiness check-ins, messages, meeting polls, votes and attendance are stored in Cloudflare D1. Members can read club conversations and listen to books the host adds, including their narrated text. Email addresses and private library contents are not shown to other members. Private Highlights, including your notes, sync to your private account in Cloudflare D1 when you are signed in. They are not shown to club members unless you choose to send one to club chat. Hosts can moderate messages, remove members, reset invitations and close a club. Leaving a club keeps your prior messages; remove your messages before leaving if you prefer. Closing a club deletes its club records, not the host’s original books. Removing access cannot erase previously downloaded audio or copies of messages.

Synced highlights and deletion

Signed-in accounts sync listening positions, playback speed, highlights and note text between the web app and iPhone. Cloud sync records stay until deleted or until an account deletion request is completed. Deleting a synced highlight removes its note from the current cloud record and older replay snapshots once your device syncs; a content-free deletion marker remains to prevent stale devices from restoring it. Deleting or expiring a book removes its cloud listening positions and note text in the same way. Operation snapshots used to retry sync requests are removed after 24 hours by scheduled cleanup. Changes made offline remain on that device until it reconnects. Signing out stops sync; browser copies may remain until you clear website data.

Payments

Stripe hosts card checkout and processes payment information. Folio stores purchase references, subscription identifiers, paid-through dates, cancellation status, audio-credit records and payment reconciliation data; it does not receive your full card number. Agent payments using USDC have public blockchain transaction records.

Transactional email

Folio uses Resend to send payment confirmation emails to your account email address. An email queue stores the address and message until the provider accepts delivery, then clears the address and message. Delivery status records are removed after 30 days. A legacy email sign-in implementation is disabled. Folio does not currently send marketing email.

Security and operational records

We keep account and session identifiers, sign-in security records, hashed IP-based rate-limit identifiers and daily feature-usage counters to operate the service and prevent abuse. Browser sessions expire on the server after one year. Authentication states expire after 10 minutes. Rate-limit records are removed after a day by scheduled cleanup. Cloudflare request observability and local processor diagnostics may record request metadata and error information. We do not intentionally log document text, questions, answers, notes, recordings, payment fields or credentials. Platform log and backup retention depends on provider settings; contact us for deletion requests affecting those records. Folio records a limited set of first-party operational events, such as job status changes, sign-in completion, playback and download outcomes, and browser or sync failures. Browser events contain only an action name, use no persistent analytics identifier, and are not queued while offline. Diagnostic event records expire after 30 days; daily totals and incident history expire after 90 days. Short-lived, daily-rotating hashed account identifiers limit event submission and expire within two days. The private operations dashboard is restricted to the configured operator. No session replay, advertising pixels, third-party browser analytics or remote font services are included in the app.

Age eligibility

Folio is for people aged 13 and older. Folio does not ask for or store your age or date of birth during sign-in. If you are under 13, do not create an account or upload content. A parent or guardian who believes a child submitted information can contact us to request restricted access and deletion. See age and parent support.

Cookies and browser storage

Folio uses cookies for library sessions and sign-in security, and browser storage for listening position, settings, library recovery keys, and explicitly saved offline audio. These records support the app’s features. Folio does not use advertising cookies or sell personal information.

Questions and deletion requests

Contact goodrishi@yahoo.com for privacy questions or account and uploaded-file deletion requests. Requests are reviewed by the operator. We may ask for limited information to verify account ownership or parental authority before restricting access and deleting account data. Payment records may need to be retained for payment reconciliation or applicable recordkeeping obligations. Deleting cloud files does not automatically erase processor working files before their local expiry; ask us to remove those copies as part of your deletion request. Provider backups and logs may expire on their own retention schedules. Local copies on other devices must be removed on those devices.