folio.

Privacy at Folio

Last updated: 13 September 2026. Contact support@usefolio.site with privacy questions or account-data requests.

Information you provide

Folio stores your account name, email address, login identity, and session information. If you choose email and password, authentication stores a password hash. When you sign in with Google or GitHub, that provider supplies your basic profile and verified email address.

We also store the websites, search queries, reference facts, reports, evaluation inputs, and results you choose to save. Account-bound reports and evaluation records are private by default.

GitHub sign-in

When available, GitHub sign-in requests profile and email access. Linking GitHub to an existing Folio account is an explicit choice in Settings. Folio stores the linked identity and encrypted OAuth tokens; these permissions do not include repositories. GitHub tokens and identity details are not published with evaluations or sent to evaluation providers.

You can revoke Folio's authorization in your GitHub application settings. Revoking authorization does not delete your saved Folio account or reports.

Google Search Console

Signing in with Google and connecting Search Console are separate choices. Connecting Search Console grants read-only access to properties available to your Google account. When you request an import, Folio reads property identifiers and search performance such as clicks, impressions, queries, pages, and average position.

Folio uses this data to display and retain your private reports. Search Console tokens and reports are not automatically sent to an AI provider, used to train our own models, or published in the developer-tool directory. We do not sell Google user data.

Google client credentials remain on the server. OAuth access and refresh tokens are encrypted in storage. Disconnecting Search Console removes Folio's stored Google tokens while preserving your Google login identity and saved reports. You can separately remove Folio's authorization in your Google account.

Evaluation providers and hosting

Cloudflare hosts the deployed application and database. When you explicitly start an OpenAI evaluation, OpenAI receives the query and evaluation inputs needed for that run. These may include captured public website content and evidence you select. Sandboxed research can search and retrieve public sources. Folio records the provider, model, execution context, and available usage details.

DataForSEO receives a website lookup only when you request that lookup. Viewing saved reports does not start a new lookup or evaluation. Public websites may receive ordinary HTTP requests when you ask Folio to capture their pages.

Cookies and operational records

Authentication uses cookies to maintain your session. Folio also retains the operational records needed to authenticate requests, enforce access and usage limits, diagnose failures, and recover interrupted work. Our own content and user controls distinguish sample data from measured observations.

Retention, downloads, and your choices

Saved account records remain until removed through available product controls or a support-assisted request. Some report types do not yet offer an individual delete button. Contact support@usefolio.site to request access, correction, or deletion of your account data.

Deleting evaluation evidence can retain limited quota records needed to enforce usage limits. It does not delete copies you downloaded or provider-side records. Disconnecting an integration does not erase its saved reports. Provider retention and processing also follow that provider's own policies.

Publication

The public developer-tool directory contains independently sourced descriptions and explicitly generated public-page observations. Publishing an eligible technical audit is a separate action. It does not publish your Google reports, private queries, reference facts, or private agent evidence.

Back to Folio