Privacy

Last updated:

The short version

Your documents, questions, notes, meeting recordings and contracts never leave your computer. Folio runs its language model locally. There is no account, no sync, and no server that holds your content.

Two things do go out, and only these two:

  1. Web search, when youpick “Web” for a message. That question is sent to Tavily to search with. Nothing else about you goes with it.
  2. Anonymous usage statistics: which features get opened and how long the app is used. No content, no file names, no identifiers. The complete list is below.

What the usage statistics contain

Folio sends counts and labels to Aptabase, an open-source, privacy-first analytics service, hosted in the European Union.

There is no user id, device id, cookie, or account. Each run of the app gets a random session number that is thrown away and cannot be linked to any other session, to your machine, or to you.

Each event carries only: the event name below, your operating system and its version, your language setting, and the Folio version you are running.

app_started, app_exiting
The app opened and closed, so typical session length can be seen.
feature_opened
Which of the six features was opened (Notes, Library, Compare, Contracts, Chat, Meetings).
folder_picked
A folder was chosen. Not which folder.
index_started, index_finished
How many files were indexed, how many failed, how long it took.
chat_message_sent
That a question was asked, and whether it was aimed at the model, your documents, or the web. Never the question.
chat_answer_shown
That an answer came back, whether it carried citations, and how long it took.
contract_run_started
A contract review began: the jurisdiction (SG or MY) and the file type (docx or pdf). Not the file name.
contract_run_finished
Whether it completed, how many findings, how long it took.
contract_evidence_opened
That the evidence for a finding was read.
contract_revision_started, contract_revision_finished
How many findings were selected, and how many rewrites verified, fell back, or failed.
contract_report_exported
A PDF report was saved.
error_shown
That an error appeared, and in which feature. Never the error text, which often quotes file paths.

That is the whole list. It is generated from one file in the app, which is the only place in Folio that can send an event, and a test fails the build if any event tries to carry a file path, a file name, or a sentence.

Why it is collected

To find out which features are worth building on and where people get stuck. Nothing is sold, shared, or used for advertising.

Where your data actually lives

Everything Folio knows about your documents is in a local SQLite database in your application-support directory, and your notes are plain Markdown files in your Documents folder. Deleting the app and those two folders removes all of it. There is no copy anywhere else.