Privacy Policy for Folio
Folio is a private journaling app: diaries, a planner, tasks, people, a document archive, and a memo feature. This policy describes every piece of information the app handles, where it goes, and what you can do about it.
The short version: everything you write lives on your own device. A few optional features — signing in, cloud backup, shared memos, reminders, the weather line on the home screen — send specific, limited data off the device. Each is listed below. Nothing is sold, and nothing is shared with advertisers. Folio contains no analytics, no crash reporting, and no advertising SDKs of any kind.
1. What stays on your device
Unless you turn on one of the optional features in section 2, everything you create in Folio is stored only on the device you created it on:
- diaries, journal pages, and the photos attached to them
- planner events, tasks, and reminders
- people and their profile photos
- archive documents, scans, and captured photos
- memos you have not shared
- your settings, including your chosen colour palette and text preferences
Text and settings are held in the app's own local storage; photos, scans, and audio are held in the device's IndexedDB store. Neither is readable by other apps. If you delete Folio, or lose or reset your device, this data is gone unless you had cloud backup switched on or your device's own OS-level backup preserved it.
2. Optional features that send data off the device
2.1 Signing in (Firebase Authentication)
Creating an account stores your email address and an authentication record with Google Firebase, operating as our processor. Your password is never stored by us in any readable form — Firebase handles it. An account is only required for the Memo feature and for cloud backup; the rest of Folio works fully signed out.
2.2 Memo (Cloud Firestore)
Memo is the one feature that is inherently networked, because it lets you send a memo to another person. When you use it, the following is stored in Google Cloud Firestore:
- your account profile record (
users/{uid}): your email, display name, and the notification settings the server needs to reach you - memos you write in Memo, including ones you keep private to your own account
- your memo contacts and contact requests you send or receive
- memos and routes you share, which by design are readable by the people you shared them with
A memo someone else sent you belongs to them; deleting your account removes what you created and leaves theirs in place.
2.3 Google Drive backup
If you connect Google Drive, Folio writes a single backup file into your Drive's app data
folder — a hidden area of your own Drive that only Folio can see. This uses the
drive.appdata scope, which is the narrowest Drive permission there is: it gives Folio no
ability to see, open, or list any other file in your Drive, only the one file it created.
The backup contains your Folio data (section 1) so that you can restore it on a new device. It is written to your Drive, not to us — we operate no server that receives it and we cannot read it.
You can turn on Backup Encryption (Settings → Cloud Backup), which encrypts the backup with AES-256-GCM using a key derived from a passphrase you choose. That passphrase is never transmitted and never stored anywhere in readable form. If you lose it, backups made with it cannot be recovered by anyone, including us.
Disconnecting Drive stops future backups. Deleting your account deletes the backup file from your Drive.
2.4 Push notifications
If you allow notifications, the device registers with Firebase Cloud Messaging and Folio stores the resulting device token on your account record, so a memo sent to you can reach your phone. The token identifies a device installation, not you personally. Reminders you set yourself (planner, tasks, memo) are scheduled locally on the device and involve no network.
2.5 The home screen weather line
If you grant location permission, Folio uses your device's coordinates to fetch a city name and the current temperature from two third-party services:
- BigDataCloud (
api.bigdatacloud.net) — turns coordinates into a city name - Open-Meteo (
api.open-meteo.com) — returns the current temperature
Your coordinates are sent to those services for that lookup, and are not stored by Folio or sent anywhere else. No account is involved, and no identifier of yours is attached. Denying location permission simply removes the weather line; nothing else changes.
3. Device permissions and why they are asked for
| Permission | Used for | Optional? |
|---|---|---|
| Camera | Scanning documents into Archive, and capturing photos for entries, people, and the archive | Yes — only prompted when you use those features |
| Microphone | Voice recordings attached to entries | Yes |
| Photos / files | Attaching an existing picture or document | Yes |
| Location | The weather line described in 2.5 | Yes |
| Notifications | Reminders you set, and memos sent to you | Yes |
| Biometrics (Face ID / fingerprint) | Unlocking the app, if you enable App Lock. Verified by the operating system; Folio never receives your biometric data | Yes |
Photos, scans, and recordings stay on the device unless included in a Drive backup you turned on, or attached to a memo you chose to share.
4. What Folio never does
- No analytics, telemetry, crash reporting, or advertising SDKs — none are bundled.
- No selling or sharing of personal information with third parties for their own purposes.
- No access to your contacts, your other Drive files, your call logs, or your messages.
- No profiling, and no automated decision-making about you.
5. Keeping and deleting your data
Data on your device lasts until you delete it. Deleted diaries, planner items, people, and archive files go to Recently Deleted for 30 days first, then are removed permanently.
Settings → Account → Delete Account deletes everything immediately and without a grace period: your Firestore records (profile, private memos, contacts, and the shared memos, routes, and contact requests you created), your Google Drive backup file, your Firebase authentication account, and everything stored on the device. It cannot be undone.
You can also disconnect Drive, revoke Folio's Drive access from your Google Account at myaccount.google.com/permissions, turn off notifications, or deny any permission, at any time, without losing the rest of the app.
6. Children's privacy
Folio is not directed at children under 13 and we do not knowingly collect information from them. If you believe a child has created an account, contact us and it will be deleted.
7. Where data is processed
Firebase Authentication, Cloud Firestore, and Firebase Cloud Messaging are operated by Google and may process data on servers outside your country. Google Drive backups are stored in your own Google account. The weather lookups in 2.5 are served by BigDataCloud and Open-Meteo.
8. Changes to this policy
If Folio adds a feature that changes what leaves your device, this policy will be updated before that feature ships, and the "last updated" date above will change.
9. Contact
Questions, requests, or complaints about this policy: kapileswarsingh@gmail.com