Privacy policy
This policy explains how Foliyo handles information when you use our website, CLI, MCP integration and hosted pages.
Last updated: 14 September 2026. This service is provided by Foliyo. Contact: hello@foliyo.io.
Information we collect
- Account and connection information: email address, workspace name, password hash and salt when you use a password, account creation details, sign-in sessions, OAuth client registrations and access credentials. If you use Google sign-in, we receive the identity information needed to verify your email and connect your account.
- Work you provide: page HTML and associated assets or URLs, titles, design guides, sender profiles, projects, recipient names and email addresses, access settings and replies submitted by readers. Content can contain personal information you choose to include.
- AI tool inputs: the content and arguments your AI tool sends to Foliyo to carry out your request. Foliyo does not retrieve your complete chat history. Data deliberately included in a tool call is received by Foliyo.
- Readership information: when tracking is enabled, page openings, timestamps, browser identifiers, browser user-agent information, referring URLs, reading duration and section activity. Personalized links and email gates can associate activity with a named recipient or email address.
- Payments and support: subscription and Stripe customer identifiers, plan and billing status, and information you send in support requests. Stripe handles payment details; Foliyo does not ask you to send card information through an AI tool.
- Technical information: requests necessarily pass through our hosting infrastructure, which can process IP addresses and operational logs for delivery, security and troubleshooting.
How we use information
We use information to authenticate you, publish and update your work, apply access restrictions, provide readership reports and notifications, process subscriptions, answer support requests and protect the service against misuse. We do not use Foliyo tool inputs to train our own AI model.
Who receives information
- People with access to your pages: published content is available to people permitted by your chosen access settings. An unrestricted page is accessible to anyone who obtains its URL. A private-looking URL is not a substitute for access restrictions.
- The publishing workspace: its authorized users and integrations can receive content, recipient information, replies and readership reports according to their permissions.
- Connected AI providers: when you use ChatGPT, Codex, Claude or another client, Foliyo returns requested tool results to that provider. Its separate policies govern its handling of your conversation and these results. Disconnecting Foliyo does not delete copies already returned to a provider.
- Service providers: Railway hosts the application; Resend delivers service emails, including verification and activity notifications; Stripe processes subscriptions; Zoho hosts our support inbox. Google handles sign-in if you choose it. Our pages can load fonts from Google Fonts.
- Destinations you configure: webhooks receive the event information you enable. External images, fonts and embeds within published content can send browser requests to their respective providers.
- Legal and security purposes: information may be disclosed where required by applicable law or needed to investigate abuse or protect users and the service.
Providers and recipients may process data outside your country. Foliyo does not offer a customer-selectable data-residency region.
Retention and deletion
Our current storage behaviour is as follows. Credential expiry is different from deletion of stored records.
- Account information, saved guides, senders, audiences and projects are retained while stored in your workspace, without a fixed automatic age-based deletion schedule. You can delete supported saved objects through the integration and request account-data deletion by contacting us.
- Published pages remain until deleted. Deleting a page removes its active page record and availability, but does not automatically erase its historical readership events or copies held by recipients and other providers.
- Readership events and related records currently have no automatic retention cutoff. Contact us to request removal of personal data. We do not claim that these records expire after a fixed number of days.
- Sign-in sessions expire after 30 days. OAuth authorization codes expire after 60 seconds and are removed when consumed. Email verification codes expire after 10 minutes. Expired records are not necessarily immediately erased from storage.
- Viewer and recipient cookies last up to one year, email-gate cookies up to 90 days and PIN-gate cookies up to 24 hours. You can remove cookies through your browser.
- Billing records, support correspondence and hosting-provider logs follow their operational and legal retention requirements. There is currently no single automated deletion timetable across these systems. Ask us about a specific record when making a deletion request.
Your controls
You can delete pages, change supported page settings, turn viewing analytics off for a page through the integration, revoke recipient links, remove saved workspace objects and revoke a connected tool's access in Settings. Revoking a connection prevents future authenticated access using that credential; it does not delete published work.
You can also request access, correction or deletion of personal information through hello@foliyo.io. We may verify your identity and the relevant workspace's authority before acting. If you received a Foliyo from someone else, contact that sender about their use of your data as well. Rights and exceptions depend on applicable law, including any right to object, restrict processing or complain to a supervisory authority.
Clearing cookies removes browser identifiers and saved sign-in or gate state. It does not erase server-side records or prevent all future page activity from being recorded. Avoid including confidential or sensitive personal information in support messages or unrestricted pages.
Policy changes
We will update this page when our practices change and revise its date. Contact us if you have questions about a change.
