Privacy Policy

Last Updated: 2026-09-15

Attorney-review notice: This policy has not yet been reviewed by a qualified attorney. The operator intends to obtain professional legal review before marketing to EU users at scale.

1. Key Changes in This Update

This is the first published Privacy Policy for Foliosio. There is no previous version; all provisions are new.

Phase 8 fixer (2026-09-15): corrected fabricated backup retention claim, fixed Supabase Auth persistence disclosure, removed unsupported GPC claim, fixed GDPR Art. 6 controller/processor distinction for AI topic clustering, added automated decision-making logic description, added DPO statement, completed CCPA 11-category coverage, corrected transfer mechanisms for Anthropic and Supabase, fixed broken anchor and cross-links.


2. Who We Are

Foliosio ("Foliosio", "we", "us", or "our") is a customer-support software provider established in the European Union. We operate the website at foliosio.com and the Foliosio helpdesk application (collectively, the "Service").

For the purposes of EU GDPR and UK GDPR, Foliosio is the data controller of personal data collected through our website, account registration, and billing. When workspace operators ("Customers") use Foliosio to manage their end-users' support requests, Foliosio also acts as a data processor on behalf of those Customers.

Contact: foliosio@proton.me

Data Protection Officer: Foliosio has not designated a formal Data Protection Officer at this time, as we do not consider our current processing to meet the mandatory designation thresholds under GDPR Art. 37(1). Privacy-related concerns and rights requests are handled by our privacy contact at foliosio@proton.me. We will review this position before processing EU personal data at scale and appoint a DPO or equivalent privacy officer as required.

EU Art. 27 Representative: Foliosio is established in the European Union; a separate EU Art. 27 representative is not required.

UK Art. 27 Representative: Foliosio currently processes UK residents' data on an occasional, low-risk basis. A UK representative under UK GDPR Art. 27 will be appointed before processing UK personal data at commercial scale.


3. Information We Collect

A. Account and identity data (workspace operators)

B. Billing data (workspace operators)

C. Support interaction data (end-users of workspace operators)

D. Interaction and audit metadata

E. Technical identifiers

F. Google Fonts

This website loads fonts from the Google Fonts CDN. Your browser transmits your IP address and browser type to Google as part of that request. See Google's privacy policy at policies.google.com/privacy for details.


4. How We Use Your Information

We process personal data for the following purposes, each with the identified lawful basis under EU GDPR Art. 6 and UK GDPR.

PurposeLawful basis (Art. 6 GDPR)Detail
Providing and operating the ServiceArt. 6(1)(b) -- contract necessityCreating and maintaining your account, processing messages, delivering AI-generated draft responses
Payment processing and billingArt. 6(1)(b) -- contract necessityCharging subscription fees, issuing invoices, processing cancellations
Rate limiting and abuse preventionArt. 6(1)(f) -- legitimate interestsUsing IP-based rate limiting to protect Service availability and security
Internal product analyticsArt. 6(1)(f) -- legitimate interestsReviewing aggregated audit log data to understand product usage; no third-party analytics SDKs are used
AI topic clustering (workspace operator analytics)Art. 28 -- processor activity on operator's instructions (no independent Art. 6 basis required from Foliosio)Grouping customer message content into topics for workspace operator analytics; conversation content is transmitted to Anthropic when this feature is enabled. Foliosio acts as a data processor for this purpose; workspace operators are the controllers responsible for identifying a lawful basis.
Security and fraud preventionArt. 6(1)(f) -- legitimate interestsDetecting abuse, verifying webhook signatures, enforcing subscription entitlement limits
Legal obligation complianceArt. 6(1)(c) -- legal obligationResponding to lawful requests from authorities; retaining billing records as required by law
AI draft generation for support responsesArt. 6(1)(b) -- contract necessity (for operators); processing on behalf of operators for their end-usersTransmitting support conversation content to Anthropic to generate reply suggestions; in auto-mode, AI responses are sent to end-users without prior human review

When support tickets contain special-category data (GDPR Art. 9), workspace operators -- as data controllers -- must identify a valid Art. 9 basis. Foliosio processes such content only as a processor acting on the operator's instructions.


5. How We Share Your Information

We do not sell or share your personal data for advertising or cross-context behavioral advertising purposes. We share data only with the sub-processors listed below, as required to operate the Service.

Sub-processorEntity countryProcessing locationPurposePrivacy / DPA
Supabase, Inc.United StatesEU or US (configured in Supabase project dashboard; verify region before EU data processing)Authentication, database, real-time eventssupabase.com/privacy
Anthropic, PBCUnited StatesUnited StatesAI draft generation; topic clustering (when AI features are enabled)anthropic.com/legal/privacy
Stripe, Inc.United States; EU entity: Stripe Technology Company Limited (Ireland)EU and USSubscription billing, payment processingstripe.com/privacy
Google LLCUnited StatesUnited StatesOAuth authentication ("Continue with Google")policies.google.com/privacy
Resend, Inc.United StatesUnited States (EU region available; verify which region is provisioned)Transactional email delivery (support replies to end-users)resend.com/legal/privacy-policy
Upstash, Inc.United StatesConfigurable (determined by operator's Upstash Redis instance region)Distributed rate limitingupstash.com/trust/privacy.pdf
Vercel, Inc.United StatesGlobal edge networkWeb application hostingvercel.com/legal/privacy-policy

We may also disclose personal data: (a) to comply with applicable law or legal process; (b) to enforce our Terms of Service; (c) to protect the rights, property, or safety of Foliosio, our customers, or the public; (d) in connection with a merger, acquisition, or sale of substantially all of our assets, with prior notice to affected users.


6. International Data Transfers

Foliosio is established in the European Union. Several of our sub-processors are located in countries outside the EU/EEA. Where we transfer personal data to such countries, we rely on one or more of the following safeguards:

We have carried out, or will carry out before processing begins, Transfer Impact Assessments for transfers relying on SCCs to US entities, in accordance with post-Schrems II obligations.


7. Data Retention

Data categoryRetention period
Account data (email, workspace name)Duration of subscription; hard-deleted immediately on workspace deletion via cascade. Supabase and Vercel may retain infrastructure-level database snapshots per their respective data processing agreements.
Support conversation data (messages, visitor records)Duration of the workspace subscription; deleted immediately on workspace deletion via cascade
Billing records (Stripe)Stripe retains billing records as required by applicable financial and tax law (typically 7 years); the Stripe customer object is deleted when you delete your account
Audit log dataRetained for the lifetime of the workspace; no automatic purge TTL currently exists; deleted on workspace deletion
Rate-limit counters (Upstash Redis)Expire at end of rate-limit window (15 minutes for auth routes; 1 hour for other routes)
Supabase Auth identityDeleted from our application database and from Supabase Auth on account deletion
AI draft dataCleared when a draft is sent or superseded; deleted on workspace deletion

Account deletion: When you delete your account, your workspace and all associated data are hard-deleted from our application database immediately via cascade deletion. We do not use a soft-delete or tombstone pattern. Foliosio's application deletes your data immediately on request. Infrastructure-level snapshots retained by Supabase and Vercel are governed by their respective data processing agreements.


8. Your Rights

EU and UK GDPR Rights

If you are in the EU or UK, you have the following rights regarding your personal data:

End-users of workspace operators: If you are an end-user (a visitor interacting with a business's Foliosio-powered support widget), contact that business to exercise your rights regarding your support conversation data. Foliosio processes that data as a processor on the operator's behalf. There is currently no self-service erasure mechanism for end-user visitor records; this is a known limitation.

How to exercise rights: Send a request to foliosio@proton.me. We will respond within 30 days (GDPR Art. 12).

Right to complain: EU users may contact the data protection authority in their member state. UK users may contact the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.

California Residents (CCPA/CPRA)

Categories of personal information collected (Cal. Civ. Code § 1798.140):

We do not sell or share personal information for cross-context behavioral advertising. We do not sell or share your personal information. No opt-out mechanism is required, but you may contact foliosio@proton.me to exercise any applicable rights.

Your rights under CCPA/CPRA:

How to exercise California rights: Email foliosio@proton.me with "California Privacy Request" in the subject line. We respond within 45 days. Requests may be submitted through an authorized agent with written authorization from the consumer.


9. Google API Services -- Limited Use

Foliosio uses Google OAuth to allow users to sign in with their Google Account. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements (developers.google.com/terms/api-services-user-data-policy).

We request only the scopes necessary to authenticate you. OAuth scopes are configured in our Supabase project dashboard and are limited to the profile and email information needed for account creation.

We will not use or transfer Google user data for any purpose other than the following four permitted exceptions, reproduced verbatim from the Google API Services User Data Policy:

1. "To provide or improve your appropriate access or user-facing features that are visible and prominent in the requesting application's user interface and only with the user's consent"
2. "For security purposes (for example, investigating abuse)"
3. "To comply with applicable laws"
4. "As part of a merger, acquisition, or sale of assets of the developer after obtaining explicit prior consent from the user"

We do not transfer Google user data to advertising platforms, data brokers, creditworthiness assessment systems, or surveillance uses.


10. AI Features

Foliosio uses Anthropic's Claude API to power AI reply draft generation and message topic clustering.

What data is sent to Anthropic: When AI features are enabled for a workspace, the full message history of a support conversation (including end-user message content), the workspace name, and relevant knowledge base content are transmitted to Anthropic's API to generate draft responses. For topic clustering, batches of customer message bodies are transmitted to Anthropic. Customer support message content, which may include end-user personal data, is sent to Anthropic when AI features are enabled.

AI Act Art. 50 transparency (EU AI Act, in force August 2, 2025): Responses delivered through Foliosio's support widget may be AI-generated. In "auto-mode," AI-generated responses are sent to end-users without prior human review. The Service records whether each message was AI-generated. AI-generated responses should be independently verified before being relied upon for consequential decisions.

We do not train AI models on your content: Foliosio does not use Customer Data, conversation content, AI inputs, or AI outputs to train, fine-tune, or otherwise improve any AI model without prior written consent. This obligation is flowed down to Anthropic as a sub-processor. Verify Anthropic's current data handling policy at anthropic.com/legal/privacy.

Automated processing: In draft mode, AI outputs are reviewed by a human agent before sending. In auto-mode, AI responses are sent to end-users automatically; this constitutes automated processing of end-user communications. To disable AI features, set AI mode to "off" in workspace widget configuration, or contact foliosio@proton.me.

How AI auto-mode works: When workspace operators enable AI auto-mode, the conversation history and visitor message are transmitted to Anthropic's Claude API. Claude returns a text response, which Foliosio inserts as an agent message without human review. Foliosio's AI features do not make legal, financial, employment, or identity decisions about individuals.


11. Cookies and Local Storage

Cookies we use:

CookiePurposeStrictly necessaryDuration
sb-* (Supabase session)Authentication session managementYesSession and refresh token; managed by Supabase SSR library
foliosio_beta_accessPrivate beta access gateYes (required for beta access)Session

We do not use advertising, analytics, or third-party tracking cookies. We do not use third-party analytics trackers.

Browser localStorage: The following UI preference data is stored in your browser's localStorage. None of this data contains personal information.

KeyPurpose
foliosio-themeUI color theme preference
foliosio-widget-embeddedWidget preview mode flag
foliosio-checklist-dismissedOnboarding checklist dismissed state
foliosio-settings-advancedAdvanced settings panel expanded state

12. Children

Foliosio is not directed at persons under 18. We do not knowingly collect personal information from minors. If you become aware that a minor has provided personal information to us, contact foliosio@proton.me and we will promptly delete that information. We do not have technical age-verification mechanisms; this restriction is enforced through our Terms of Service.


13. Security

We implement reasonable technical and organizational measures to protect personal data, including:

No security measure is completely effective. In the event of a personal data breach, we will notify affected parties and supervisory authorities as required by applicable law (GDPR Art. 33/34: 72-hour notification to the lead supervisory authority; ICO notification for UK users).


14. Changes to This Policy

We will post any material changes to this Privacy Policy on this page and update the "Last Updated" date at the top. For material changes, we will notify you by email (where we have your address) or by prominent notice within the Service. Continued use of the Service after the effective date of any change constitutes acceptance of the revised policy.


15. Contact Us

For privacy-related inquiries, rights requests, and data concerns: