Folvi
HomePricingFAQContact
Sign inGet started

Legal & trust

Privacy Policy

Last updated: October 7, 2026

Plain English summary: We collect what we need to run your portfolio, do not sell your personal data, and let you request account erasure at any time. Folvi uses service providers in multiple jurisdictions, so your data may be processed outside your country.

On this page

1. What we collect2. How we use your data3. Third-party services4. Message security5. File storage6. Geo-detection and regional pricing7. Your rights8. Cookies9. International processing and data transfers10. Automated decision-making11. Privacy rights under applicable law12. Data retention and account deletion13. Inactive accounts14. Complaints and escalation15. Changes to this policy16. Contact

1. What we collect

When you create a Folvi account, we collect your name, email address, and profile information you voluntarily provide (bio, location, LinkedIn URL, skills, etc.). When visitors view your portfolio, we log anonymised view events. Messages sent through Folvi are securely encrypted.

2. How we use your data

We use your data solely to operate the Folvi service: to display your public portfolio, to send you email notifications (if enabled), and to improve the platform. We do not sell your data to any third parties. We do not use your data for advertising.

3. Third-party services

Folvi uses the following third-party services:

  • Supabase — authentication, user management, and database storage
  • Resend — transactional email delivery
  • Polar — payment processing and subscriptions
  • Vercel — hosting and deployment
  • Cloudflare — DNS management, CDN, R2 storage, and CAPTCHA protection
  • Google Drive, Dropbox, and Microsoft OneDrive — optional connected storage when you choose to connect an account

Each provider has its own privacy policy and may process data in countries other than your own. Payment information is handled entirely by Polar — Folvi never stores your card or banking details. For connected storage accounts, Folvi stores the encrypted OAuth credentials and connection metadata needed to maintain the connection and accesses provider files only within the scopes you authorize.

4. Message security

All messages sent through your Folvi portfolio are transmitted securely over HTTPS and stored in our database. Access to messages is restricted so that only the sender and recipient can read them. You can delete your account and all associated messages at any time.

5. File storage

Files you upload (project thumbnails, SCORM packages, videos, PDFs, images) are stored securely. Thumbnails are publicly accessible. Media files are served via authenticated URLs. Files may be deleted if your account is closed.

6. Geo-detection and regional pricing

To provide region-specific pricing, Folvi uses country or region metadata derived from your network request. Folvi does not need to store your raw IP address in your account profile for this purpose, although infrastructure providers may process request metadata and logs as part of operating and securing their services. Billing is handled by Polar using Folvi's current regional pricing configuration.

7. Your rights

You may request deletion of your account and all associated data at any time from Account → Data & privacy. If you have questions about the data we hold, contact us at privacy@folvi.org.

8. Cookies

Folvi uses essential session cookies managed by Supabase for authentication. We do not use tracking or advertising cookies.

9. International processing and data transfers

Folvi relies on third-party infrastructure and service providers that operate in multiple jurisdictions. Folvi does not represent that personal data of Indian residents is stored or processed exclusively in India. Depending on the service, provider configuration, and the features you use, personal data may be stored or processed outside India.

Current service providers include Supabase for database and authentication, Vercel for application hosting, Cloudflare for CDN and R2 object storage, Resend for transactional email, Polar for billing, and — when you connect them — Google Drive, Dropbox, or Microsoft OneDrive. Provider infrastructure locations and subprocessors may change over time.

Cross-border processing is carried out only as needed to operate Folvi and is subject to applicable law and the contractual or technical safeguards available for the relevant provider and jurisdiction. Indian law may restrict transfers to particular countries or categories of data, and other sector-specific laws may impose stricter requirements. Contact privacy@folvi.org if you have questions about Folvi's current providers or international processing.

10. Automated decision-making

Folvi does not currently use automated decision-making or algorithmic profiling that significantly affects you. If this changes in the future, we will update this policy and provide you with the ability to opt-out of such processing.

If you have concerns about automated decisions affecting your account, please contact privacy@folvi.org.

11. Privacy rights under applicable law

If the General Data Protection Regulation (GDPR) applies to you, applicable rights may include access, rectification, erasure, data portability, restriction, and objection. If the California Consumer Privacy Act (CCPA) or a similar law applies to you, applicable rights may include requests to know, delete, or correct personal information and rights concerning the sale or sharing of personal information. Folvi does not sell your personal information.

To exercise a privacy right, contact privacy@folvi.org. Folvi may request information reasonably necessary to verify your identity, authority, or the scope of the request.

Folvi responds within the period required by the law that applies to the request. By way of example, GDPR requests are generally handled within one month, subject to extensions permitted by GDPR, while CCPA requests to know, delete, or correct are generally handled within 45 calendar days, subject to extensions permitted by California law.

12. Data retention and account deletion

While your account is active: Folvi retains account data, portfolio content, uploaded files, messages, and related service records for as long as they are needed to provide and secure the service, support billing or account operations, or meet applicable legal obligations.

When you delete your account: The Account → Data & privacy erasure flow removes live Folvi account and product data, associated Folvi-owned storage, and authentication access through Folvi's account-erasure workflow. The workflow completes through multiple deletion stages rather than promising instantaneous removal from every system.

After erasure completes: Folvi's durable erasure record is scrubbed of profile and user identifiers, confirmation email, and continuation inventory, and retains only non-personal operational evidence that the erasure lifecycle completed. Personal data is retained beyond erasure only where applicable law requires it or an explicitly approved compliance-retention policy applies.

Technical records: Security, reliability, billing, or compliance records may have separate retention needs. Folvi does not currently apply or promise a universal 90-day log-retention period or 30-day backup-retention period.

13. Inactive accounts

Folvi does not currently delete Free accounts solely because they have been inactive for three months. Any future inactivity-based deletion policy will be reflected in the applicable terms and privacy notice and applied with any notice required by law.

14. Complaints and escalation

If you have a privacy concern or complaint, contact privacy@folvi.org. Folvi handles privacy grievances and rights requests within the period required by applicable law rather than promising one universal response deadline for every jurisdiction.

Where applicable law gives you a right to complain to a data-protection or other competent authority, you may exercise that right after completing any internal grievance step that the applicable law requires.

15. Changes to this policy

We may update this Privacy Policy as Folvi, our providers, or applicable legal requirements change. The current version and effective date will be published on this page. Where applicable law requires additional notice, consent, or another step before a change takes effect, Folvi will follow that requirement.

For questions about a policy change or a prior version, contact privacy@folvi.org. Folvi does not promise a fixed public archive or retention period for superseded policy versions unless applicable law requires one.

16. Contact

For privacy-related enquiries, complaints, or rights requests, email privacy@folvi.org.

Folvi

© 2026 Folvi. Portfolios for learning & development work.

PrivacyTermsTakedownAccessibility