Privacy Policy
Last Updated: 2026-09-15
1. Key Changes in This Update
This is the first published Privacy Policy for Foliosio. There is no previous version; all provisions are new.
Phase 8 fixer (2026-09-15): corrected fabricated backup retention claim, fixed Supabase Auth persistence disclosure, removed unsupported GPC claim, fixed GDPR Art. 6 controller/processor distinction for AI topic clustering, added automated decision-making logic description, added DPO statement, completed CCPA 11-category coverage, corrected transfer mechanisms for Anthropic and Supabase, fixed broken anchor and cross-links.
2. Who We Are
Foliosio ("Foliosio", "we", "us", or "our") is a customer-support software provider established in the European Union. We operate the website at foliosio.com and the Foliosio helpdesk application (collectively, the "Service").
For the purposes of EU GDPR and UK GDPR, Foliosio is the data controller of personal data collected through our website, account registration, and billing. When workspace operators ("Customers") use Foliosio to manage their end-users' support requests, Foliosio also acts as a data processor on behalf of those Customers.
Contact: foliosio@proton.me
Data Protection Officer: Foliosio has not designated a formal Data Protection Officer at this time, as we do not consider our current processing to meet the mandatory designation thresholds under GDPR Art. 37(1). Privacy-related concerns and rights requests are handled by our privacy contact at foliosio@proton.me. We will review this position before processing EU personal data at scale and appoint a DPO or equivalent privacy officer as required.
EU Art. 27 Representative: Foliosio is established in the European Union; a separate EU Art. 27 representative is not required.
UK Art. 27 Representative: Foliosio currently processes UK residents' data on an occasional, low-risk basis. A UK representative under UK GDPR Art. 27 will be appointed before processing UK personal data at commercial scale.
3. Information We Collect
A. Account and identity data (workspace operators)
- Email address, used for authentication and account communications
- Workspace name
- Authentication credentials managed by Supabase Auth; we do not receive or store raw passwords
- For Google OAuth sign-ins: email address and display name supplied by Google
B. Billing data (workspace operators)
- Stripe customer ID and subscription status, stored in our database
- Billing address and payment card details, collected and stored directly by Stripe; we never receive or store raw payment card numbers
C. Support interaction data (end-users of workspace operators)
- Email address and display name, when submitted via contact form or inbound email
- Message body content of support conversations
- Session token: a randomly generated, 32-byte pseudonymous identifier assigned per widget session
- Page URL of the page where the support widget was opened; used for automation rule evaluation and outbound webhook delivery; not persisted in our application database
D. Interaction and audit metadata
- Conversation channel (widget, email, or contact form)
- Email thread identifiers and subject lines
- Flags indicating whether a message was AI-generated or edited from an AI draft
- AI generation counter: the number of AI drafts generated per conversation
- Audit log events including draft generation (with token counts), billing events, data export requests, and account deletion
E. Technical identifiers
- IP address, used transiently for rate limiting via Upstash Redis; not stored in our application database; may be held in Upstash Redis for the rate-limit window (up to 1 hour)
- Supabase authentication session cookies
- Browser localStorage keys for UI preferences; none contain personal data
F. Google Fonts
This website loads fonts from the Google Fonts CDN. Your browser transmits your IP address and browser type to Google as part of that request. See Google's privacy policy at policies.google.com/privacy for details.
4. How We Use Your Information
We process personal data for the following purposes, each with the identified lawful basis under EU GDPR Art. 6 and UK GDPR.
| Purpose | Lawful basis (Art. 6 GDPR) | Detail |
|---|---|---|
| Providing and operating the Service | Art. 6(1)(b) -- contract necessity | Creating and maintaining your account, processing messages, delivering AI-generated draft responses |
| Payment processing and billing | Art. 6(1)(b) -- contract necessity | Charging subscription fees, issuing invoices, processing cancellations |
| Rate limiting and abuse prevention | Art. 6(1)(f) -- legitimate interests | Using IP-based rate limiting to protect Service availability and security |
| Internal product analytics | Art. 6(1)(f) -- legitimate interests | Reviewing aggregated audit log data to understand product usage; no third-party analytics SDKs are used |
| AI topic clustering (workspace operator analytics) | Art. 28 -- processor activity on operator's instructions (no independent Art. 6 basis required from Foliosio) | Grouping customer message content into topics for workspace operator analytics; conversation content is transmitted to Anthropic when this feature is enabled. Foliosio acts as a data processor for this purpose; workspace operators are the controllers responsible for identifying a lawful basis. |
| Security and fraud prevention | Art. 6(1)(f) -- legitimate interests | Detecting abuse, verifying webhook signatures, enforcing subscription entitlement limits |
| Legal obligation compliance | Art. 6(1)(c) -- legal obligation | Responding to lawful requests from authorities; retaining billing records as required by law |
| AI draft generation for support responses | Art. 6(1)(b) -- contract necessity (for operators); processing on behalf of operators for their end-users | Transmitting support conversation content to Anthropic to generate reply suggestions; in auto-mode, AI responses are sent to end-users without prior human review |
When support tickets contain special-category data (GDPR Art. 9), workspace operators -- as data controllers -- must identify a valid Art. 9 basis. Foliosio processes such content only as a processor acting on the operator's instructions.
5. How We Share Your Information
We do not sell or share your personal data for advertising or cross-context behavioral advertising purposes. We share data only with the sub-processors listed below, as required to operate the Service.
| Sub-processor | Entity country | Processing location | Purpose | Privacy / DPA |
|---|---|---|---|---|
| Supabase, Inc. | United States | EU or US (configured in Supabase project dashboard; verify region before EU data processing) | Authentication, database, real-time events | supabase.com/privacy |
| Anthropic, PBC | United States | United States | AI draft generation; topic clustering (when AI features are enabled) | anthropic.com/legal/privacy |
| Stripe, Inc. | United States; EU entity: Stripe Technology Company Limited (Ireland) | EU and US | Subscription billing, payment processing | stripe.com/privacy |
| Google LLC | United States | United States | OAuth authentication ("Continue with Google") | policies.google.com/privacy |
| Resend, Inc. | United States | United States (EU region available; verify which region is provisioned) | Transactional email delivery (support replies to end-users) | resend.com/legal/privacy-policy |
| Upstash, Inc. | United States | Configurable (determined by operator's Upstash Redis instance region) | Distributed rate limiting | upstash.com/trust/privacy.pdf |
| Vercel, Inc. | United States | Global edge network | Web application hosting | vercel.com/legal/privacy-policy |
We may also disclose personal data: (a) to comply with applicable law or legal process; (b) to enforce our Terms of Service; (c) to protect the rights, property, or safety of Foliosio, our customers, or the public; (d) in connection with a merger, acquisition, or sale of substantially all of our assets, with prior notice to affected users.
6. International Data Transfers
Foliosio is established in the European Union. Several of our sub-processors are located in countries outside the EU/EEA. Where we transfer personal data to such countries, we rely on one or more of the following safeguards:
- Standard Contractual Clauses (SCCs) adopted by the European Commission under GDPR Art. 46(2)(c): confirmed for transfers to Supabase, Anthropic, and Stripe.
- International Data Transfer Agreement (IDTA) issued by the UK ICO for UK-to-third-country transfers: UK Addendums confirmed for Supabase and Anthropic; Stripe's UK Data Bridge status should be verified at dataprivacyframework.gov (LIVE-VERIFY).
- EU-US Data Privacy Framework (DPF): Stripe is DPF-certified. Anthropic is not DPF-certified; EU-bound transfers rely on Standard Contractual Clauses (SCCs) and adequacy decisions. Supabase is not DPF-certified; EU-bound transfers rely on Standard Contractual Clauses (SCCs); you may select an EU hosting region.
- Adequacy decisions where the recipient country has received an adequacy finding from the European Commission.
We have carried out, or will carry out before processing begins, Transfer Impact Assessments for transfers relying on SCCs to US entities, in accordance with post-Schrems II obligations.
7. Data Retention
| Data category | Retention period |
|---|---|
| Account data (email, workspace name) | Duration of subscription; hard-deleted immediately on workspace deletion via cascade. Supabase and Vercel may retain infrastructure-level database snapshots per their respective data processing agreements. |
| Support conversation data (messages, visitor records) | Duration of the workspace subscription; deleted immediately on workspace deletion via cascade |
| Billing records (Stripe) | Stripe retains billing records as required by applicable financial and tax law (typically 7 years); the Stripe customer object is deleted when you delete your account |
| Audit log data | Retained for the lifetime of the workspace; no automatic purge TTL currently exists; deleted on workspace deletion |
| Rate-limit counters (Upstash Redis) | Expire at end of rate-limit window (15 minutes for auth routes; 1 hour for other routes) |
| Supabase Auth identity | Deleted from our application database and from Supabase Auth on account deletion |
| AI draft data | Cleared when a draft is sent or superseded; deleted on workspace deletion |
Account deletion: When you delete your account, your workspace and all associated data are hard-deleted from our application database immediately via cascade deletion. We do not use a soft-delete or tombstone pattern. Foliosio's application deletes your data immediately on request. Infrastructure-level snapshots retained by Supabase and Vercel are governed by their respective data processing agreements.
8. Your Rights
EU and UK GDPR Rights
If you are in the EU or UK, you have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate personal data. Note: due to the technical complexity of AI language models, it may not always be possible to correct factual inaccuracies in AI-generated outputs.
- Right to erasure (Art. 17): Request deletion of your personal data, subject to legal exceptions.
- Right to restriction of processing (Art. 18): Request that we restrict processing in certain circumstances.
- Right to data portability (Art. 20): Receive your account data in a structured, machine-readable format where processing is based on consent or contract. Workspace owners can use the export function in account settings; on request via foliosio@proton.me.
- Right to object (Art. 21): Object to processing based on legitimate interests; we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent, withdraw at any time without affecting the lawfulness of prior processing.
- Right not to be subject to solely automated decision-making (Art. 22): Contact us if you believe an automated decision has had legal or similarly significant effects on you.
End-users of workspace operators: If you are an end-user (a visitor interacting with a business's Foliosio-powered support widget), contact that business to exercise your rights regarding your support conversation data. Foliosio processes that data as a processor on the operator's behalf. There is currently no self-service erasure mechanism for end-user visitor records; this is a known limitation.
How to exercise rights: Send a request to foliosio@proton.me. We will respond within 30 days (GDPR Art. 12).
Right to complain: EU users may contact the data protection authority in their member state. UK users may contact the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.
California Residents (CCPA/CPRA)
Categories of personal information collected (Cal. Civ. Code § 1798.140):
- A. Identifiers (name, email, IP address, session tokens) -- COLLECTED
- B. Customer records (Cal. Civ. Code § 1798.80(e), e.g. billing address) -- COLLECTED
- C. Protected classification characteristics (race, gender, etc.) -- NOT COLLECTED
- D. Commercial information (subscription plan, billing status) -- COLLECTED
- E. Biometric information -- NOT COLLECTED
- F. Internet or other electronic network activity (audit log events, widget session data, page URL) -- COLLECTED
- G. Geolocation data (precise) -- NOT COLLECTED
- H. Audio, visual, thermal, olfactory, or similar data -- NOT COLLECTED
- I. Professional or employment-related information -- NOT COLLECTED
- J. Education information -- NOT COLLECTED
- K. Inferences drawn from the above -- NOT COLLECTED
We do not sell or share personal information for cross-context behavioral advertising. We do not sell or share your personal information. No opt-out mechanism is required, but you may contact foliosio@proton.me to exercise any applicable rights.
Your rights under CCPA/CPRA:
- Right to know: Request disclosure of the categories and specific pieces of personal information collected, the sources, business purposes, and categories of third parties to which it is disclosed.
- Right to delete: Request deletion of personal information, subject to certain legal exceptions.
- Right to correct: Request correction of inaccurate personal information.
- Right to limit use of sensitive PI: We do not use sensitive personal information for secondary purposes beyond those permitted under CPRA.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
- Automated Decision-Making Technology (ADMT): Foliosio's AI features may constitute ADMT under the California Privacy Protection Agency's 2025 ADMT Regulations (effective January 1, 2026). You have the right to opt out of ADMT used for profiling with significant effects. Contact foliosio@proton.me to exercise this right or to disable AI features for your account.
How to exercise California rights: Email foliosio@proton.me with "California Privacy Request" in the subject line. We respond within 45 days. Requests may be submitted through an authorized agent with written authorization from the consumer.
9. Google API Services -- Limited Use
Foliosio uses Google OAuth to allow users to sign in with their Google Account. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements (developers.google.com/terms/api-services-user-data-policy).
We request only the scopes necessary to authenticate you. OAuth scopes are configured in our Supabase project dashboard and are limited to the profile and email information needed for account creation.
We will not use or transfer Google user data for any purpose other than the following four permitted exceptions, reproduced verbatim from the Google API Services User Data Policy:
We do not transfer Google user data to advertising platforms, data brokers, creditworthiness assessment systems, or surveillance uses.
10. AI Features
Foliosio uses Anthropic's Claude API to power AI reply draft generation and message topic clustering.
What data is sent to Anthropic: When AI features are enabled for a workspace, the full message history of a support conversation (including end-user message content), the workspace name, and relevant knowledge base content are transmitted to Anthropic's API to generate draft responses. For topic clustering, batches of customer message bodies are transmitted to Anthropic. Customer support message content, which may include end-user personal data, is sent to Anthropic when AI features are enabled.
AI Act Art. 50 transparency (EU AI Act, in force August 2, 2025): Responses delivered through Foliosio's support widget may be AI-generated. In "auto-mode," AI-generated responses are sent to end-users without prior human review. The Service records whether each message was AI-generated. AI-generated responses should be independently verified before being relied upon for consequential decisions.
We do not train AI models on your content: Foliosio does not use Customer Data, conversation content, AI inputs, or AI outputs to train, fine-tune, or otherwise improve any AI model without prior written consent. This obligation is flowed down to Anthropic as a sub-processor. Verify Anthropic's current data handling policy at anthropic.com/legal/privacy.
Automated processing: In draft mode, AI outputs are reviewed by a human agent before sending. In auto-mode, AI responses are sent to end-users automatically; this constitutes automated processing of end-user communications. To disable AI features, set AI mode to "off" in workspace widget configuration, or contact foliosio@proton.me.
How AI auto-mode works: When workspace operators enable AI auto-mode, the conversation history and visitor message are transmitted to Anthropic's Claude API. Claude returns a text response, which Foliosio inserts as an agent message without human review. Foliosio's AI features do not make legal, financial, employment, or identity decisions about individuals.
11. Cookies and Local Storage
Cookies we use:
| Cookie | Purpose | Strictly necessary | Duration |
|---|---|---|---|
sb-* (Supabase session) | Authentication session management | Yes | Session and refresh token; managed by Supabase SSR library |
foliosio_beta_access | Private beta access gate | Yes (required for beta access) | Session |
We do not use advertising, analytics, or third-party tracking cookies. We do not use third-party analytics trackers.
Browser localStorage: The following UI preference data is stored in your browser's localStorage. None of this data contains personal information.
| Key | Purpose |
|---|---|
foliosio-theme | UI color theme preference |
foliosio-widget-embedded | Widget preview mode flag |
foliosio-checklist-dismissed | Onboarding checklist dismissed state |
foliosio-settings-advanced | Advanced settings panel expanded state |
12. Children
Foliosio is not directed at persons under 18. We do not knowingly collect personal information from minors. If you become aware that a minor has provided personal information to us, contact foliosio@proton.me and we will promptly delete that information. We do not have technical age-verification mechanisms; this restriction is enforced through our Terms of Service.
13. Security
We implement reasonable technical and organizational measures to protect personal data, including:
- HTTPS-only transmission
- Authentication session management via Supabase (HttpOnly session cookies)
- Password hashing via Supabase Auth for email/password accounts
- SHA-256 hashing for API keys; raw keys are shown only once at creation and are not re-derivable
- IP-based rate limiting on configured endpoints (where UPSTASH_REDIS_REST_URL is set)
- X-Frame-Options, X-Content-Type-Options, and Referrer-Policy security headers
- SSRF prevention controls on webhook and external URL inputs
- Timing-safe comparisons for secret verification
- Stripe webhook signature verification
No security measure is completely effective. In the event of a personal data breach, we will notify affected parties and supervisory authorities as required by applicable law (GDPR Art. 33/34: 72-hour notification to the lead supervisory authority; ICO notification for UK users).
14. Changes to This Policy
We will post any material changes to this Privacy Policy on this page and update the "Last Updated" date at the top. For material changes, we will notify you by email (where we have your address) or by prominent notice within the Service. Continued use of the Service after the effective date of any change constitutes acceptance of the revised policy.
15. Contact Us
For privacy-related inquiries, rights requests, and data concerns:
- Email: foliosio@proton.me
- Mailing address: Available on request; contact us by email
- EU supervisory authority: The data protection authority in your EU member state
- UK supervisory authority: Information Commissioner's Office (ICO) -- ico.org.uk/make-a-complaint
- Response time: We will respond to rights requests within 30 days (EU/UK GDPR Art. 12) or 45 days (CCPA/CPRA).