Privacy Policy

Your data, simply explained.

Last updated: May 2026


The short version

Folio does not sell your data. It does not run ads. It does not embed third-party trackers. It collects only what is necessary to operate a blogging platform.

What we collect

  • Email address — used to send your magic sign-in link. Stored in our database.
  • Your name and handle — displayed on your profile and posts. Set by you.
  • Your posts and drafts — stored in our database. Published posts are publicly readable.
  • Session token — stored in a cookie to keep you signed in. Expires after 30 days.
  • Uploaded images — stored in Cloudflare R2 object storage.

We do not collect passwords (there are none), payment details, or location data.

Cookies

Folio sets one cookie: a secure, HTTP-only session token. It is not used for tracking — only for keeping you signed in. No third-party cookies are set.

Third-party services

  • Resend — used to send magic-link sign-in emails. Your email address is transmitted to Resend for this purpose. Resend privacy policy.
  • Cloudflare — CDN, tunnel, and R2 storage. Requests pass through Cloudflare's network. Cloudflare privacy policy.

Data retention

Your account and posts are kept for as long as your account exists. If you wish to delete your account and all associated data, email [email protected] and we will remove everything within 30 days.

Analytics

Folio does not use Google Analytics or any third-party analytics service. Basic server-side view counts may be tracked per post for authors' own dashboards — these are not shared with any third party.

Contact

Questions about this policy? [email protected]