Privacy Policy
Last updated 2026-09-21
Foliary's role
Foliary handles conversations between two people. You are one of them. The other person has never heard of us.
That shapes everything below. For your own account details you are our customer and this policy governs what we do. For the contents of your conversations, you are the data controller and we are your processor — we hold that material on your instructions, we do not decide what to do with it, and our obligations to you are set out in the Data Processing Agreement. Whether you are permitted to send us your conversations in the first place is a question about your relationship with the people you talk to, not about your relationship with us. The Terms of Service §3 says so in plain words.
What we collect
Your account
- Your email address, used to sign in and to email you.
- Your name, and a business name if you give one.
- A password, stored only as a hash by our authentication provider. We never see it.
- Your time zone, so dates read correctly.
- The short description of your business you may write in the app, which is used to improve transcription accuracy and conversation sorting.
Your billing
Handled by Stripe. We never see or store your card number. We store the Stripe customer and subscription identifiers, your subscription status, the price you are on, and when your paid period ends. Stripe's own privacy policy governs what Stripe holds.
Your conversations
When you connect Foliary to Voxer, Voxer sends us each message in your conversations as it arrives. For each message we store:
- the message text, or — for a voice message — a transcript of what was said, plus a short AI-written summary and the recording's length;
- who sent it, as the name and account identifier Voxer supplies, and any name you give them yourself in Foliary;
- which conversation it belongs to, that conversation's name and members, and the category it has been sorted into;
- when it was sent;
- a link to the original audio or image, hosted by Voxer. We do not copy the audio or the picture onto our systems; we keep the address Voxer gave us. ⚠️ Those addresses are Voxer's and are not access-controlled — anyone holding one can open it. That is a property of Voxer, not of Foliary, and it is why Foliary never gives those links to an AI assistant.
We capture from the moment you connect, not before. We do not import your history unless you ask us to and pay for that separately.
Notes to yourself are never captured. Voxer only sends us conversations that involve at least one other person.
What we do not collect
No advertising identifiers, no tracking pixels, no third-party analytics in the app, no location data, no browsing history. We do not buy data about you and we do not sell data about anyone.
What we do with it
| Purpose | What happens |
|---|---|
| Transcription | Voice messages are converted to text by our AI provider. |
| Summaries | Longer transcripts are summarized. |
| Sorting | Once a day, conversations are categorized as client, team, partner, mentor or ignore. You can change any of them. |
| Serving it back | Through the app, through an AI connection you authorize, and/or as a synced folder of notes. |
| Running the service | Sending you a sign-in link, a welcome, a password reset, and telling you if something breaks. |
| Billing | Taking payment and keeping your subscription current. |
We do not use your conversations to train AI models, and our providers do not train on them on our behalf. Content sent to our AI provider through its business API is not used to train its models and is retained only briefly for abuse monitoring before deletion.
A human at Belim & Co can technically read your conversations, because we operate the database. We access customer conversation content only to fix a fault you have reported or where we are legally required to, and not otherwise. We will tell you when we do, except where we are legally barred from saying so.
Who else touches it
Our sub-processors, what each one gets, and where:
| Sub-processor | What it handles | Where |
|---|---|---|
| Supabase | The database: your account, your messages, transcripts, summaries | United States |
| Google Cloud | Receiving messages, transcription jobs, the AI connection | United States |
| OpenAI | Transcription and summarization of voice messages; conversation sorting | United States |
| Vercel | Hosting app.foliary.co | United States |
| Stripe | Payments | United States, and Stripe's own global infrastructure |
| Postmark | Transactional email | United States |
| Cloudflare | Domain name resolution only — no traffic passes through it | — |
Everything is hosted in the United States, and Foliary is sold to customers in the United States.
Voxer is not our sub-processor. It is yours: your relationship with Voxer is your own, we receive what Voxer sends us because you told Voxer to send it, and we have no other access to your Voxer account.
How long we keep it
- Your conversations: for as long as your account is open, and for 30 days after you cancel. After that they are deleted. You can export them during those 30 days — see Terms §8.
- Raw incoming messages are held in a short-term log for 30 days and then deleted automatically. That log exists so a message is never lost if processing fails.
- Billing records are kept for 7 years, which is what US tax and accounting practice requires.
- Your account, until you close it.
Your rights
Depending on where you live, you may have the right to see the personal data we hold about you, to correct it, to delete it, to get a copy in a portable form, and to object to some processing. Write to support@foliary.co and we will respond within 30 days.
If you are not our customer but someone they talk to, and you want to know what is held or want it deleted: the material belongs to the customer's account, not to us, so we will pass your request to them and support them in answering it. Tell us at support@foliary.co and we will act within 30 days.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.
Security
- Every account's data is isolated at the database level, and that isolation is tested automatically before every release.
- Your Voxer connection address is stored only as a one-way hash — we cannot display it again, which is why replacing it means issuing a new one.
- Connections are encrypted in transit; data is encrypted at rest by our hosting providers.
- Access to production systems is limited to personnel who need it.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data we will tell you within 72 hours of becoming aware of it.
Children
Foliary is for business use and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
We will post changes here and, for anything material, email you before it takes effect.
Contact
support@foliary.co Belim & Co, 132 Veterans Ln, Unit A #320, Doylestown, PA 18901, United States