Privacy Policy
Last updated: February 19, 2026
FolioBase ("we," "us," or "our") operates the knowledge extraction platform at foliobase.digital. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our platform. FolioBase captures voice recordings, written narratives, and documents, then processes them through AI systems to create structured outputs. Please read this policy carefully.
1. Information We Collect
We collect nine categories of personal data. The sensitivity level reflects the nature of knowledge extraction — you are sharing what you know, believe, and remember.
Name, email address, password hash, and third-party OAuth profile. Used for authentication and communication.
Organization name, tenant type (business, family, or community), engagement status, and channel. Used for multi-tenant separation and tenant-specific prompts.
Raw audio from AI-guided voice interviews, browser recordings, uploaded recordings, and live sessions. Your actual voice and spoken words are captured, stored, transcribed, and processed by AI.
Structured text from voice sessions, AI chat conversations, and diagnostic sessions. These are text representations of everything you said during extraction.
Playbooks, scorecards, HOTT canvases, meeting rhythms, clarity prisms, story segments, and wisdom gems generated by AI from your transcripts. May contain trade secrets (business tenants) or private family information (family tenants).
Payment processor customer ID, subscription plan, voice minute usage, and purchase history. We never receive, store, or transmit raw payment card numbers.
Session timestamps, extraction channel used, voice minutes consumed, IP address, and user agent. Used for analytics, billing accuracy, and security monitoring.
Family member names, relationships, birth and death dates. May include data about deceased persons, minors, and individuals who are not platform users.
Contact information, waitlist status, and beta invite codes. Used for lead nurturing and engagement tracking.
2. How We Use Your Information
We use your information solely to operate and deliver the FolioBase platform:
- —Extract knowledge from voice recordings, documents, and conversations through AI processing
- —Generate structured outputs (playbooks, scorecards, stories, wisdom gems) from your transcripts
- —Deliver approved outputs to your connected workspace
- —Sync encrypted data to the Folio HQ desktop application
- —Manage your account, organization membership, and subscription billing
- —Send transactional emails including magic link invitations and session notifications
- —Monitor platform health, track errors, and maintain security through audit logging
3. AI Processing Disclosure
FolioBase processes your data through three separate AI systems. Each serves a distinct role in the extraction pipeline. Your data is not used to train AI models by any of these processors.
Conducts AI-guided voice interviews via real-time connection. Receives your voice audio during the session and delivers conversation transcripts after the call ends.
Analyzes extraction transcripts and generates structured outputs — playbooks, scorecards, HOTT canvases, meeting rhythms, clarity prisms, story segments, and wisdom gems. Transcripts are processed via API; the provider does not retain input data beyond the API request lifecycle.
Transcribes uploaded audio files and meeting recordings with speaker diarization. Audio files are deleted after transcription delivery.
A complete list of named subprocessors is available upon written request to [email protected].
4. Third-Party Data Processors
We share personal data with the following categories of service providers, each receiving only the data necessary for its function. A complete list of named subprocessors is available upon written request to [email protected].
Primary database — stores all structured data including accounts, transcripts, and outputs. Encrypted at rest.
Object storage — stores voice recordings, uploaded documents, and encrypted sync payloads. Encrypted at rest.
AI voice interviews — receives real-time audio and delivers transcripts.
AI processing — analyzes transcripts to generate structured outputs.
Audio transcription — converts uploaded audio to text with speaker identification.
Payment processing — handles all subscription billing and payment card processing under PCI DSS Level 1 certification.
Transactional email — delivers magic link invitations, notifications, and session summaries.
Output delivery — syncs approved outputs to your connected workspace, when enabled by you.
CRM — tracks engagement status and deal progression. Server-side only; no client-side tracking.
Authentication (OAuth), calendar integration, and meeting recording capture. Read-only access.
Error tracking — captures error stack traces for platform monitoring. Configured with PII scrubbing; 90-day retention.
5. Data Handoff to External Systems
Connected Workspace: When you approve outputs and sync them to your connected workspace, that data leaves FolioBase's infrastructure. Once in your connected workspace, the data is governed by the connected workspace provider's privacy policy and your own account settings. FolioBase is not responsible for data stored within your connected workspace.
Folio HQ Desktop App: Encrypted payloads synced to the Folio HQ desktop application transfer data custody to your local device. Data is encrypted in transit and at rest on the device. Once on your device, you are the data custodian. FolioBase is not responsible for the security of locally stored data.
6. Data Retention
We retain data according to the following schedule:
| Data Category | Retention Period |
|---|---|
| Account identity | Account lifetime + 30 days |
| Organization data | Account lifetime + 90 days |
| Voice recordings | Configurable per organization; default 2 years |
| Extraction transcripts | Same as voice recordings |
| Structured AI outputs | Account lifetime |
| Payment & billing | 7 years (tax/accounting requirements) |
| Usage metadata & audit logs | 2 years (audit); 90 days (error monitoring) |
| Family relationship data | Account lifetime; cascading deletion |
| CRM & marketing | Until conversion or 1 year |
7. Children's Data
FolioBase does not knowingly collect personal information from children under 13. Family tenants may invite family members of any age, but participants under 13 are currently prohibited from using the platform. If we become aware that we have collected data from a child under 13 without verified parental consent, we will delete that data within 30 days. If you believe a child under 13 has provided us with personal information, please contact us immediately.
8. International Data Transfers
FolioBase is hosted in the United States. All data processors are US-headquartered. Our encrypted object storage may replicate data globally for performance. By using FolioBase, you consent to the transfer and processing of your data in the United States. International participants, including family and community members invited from outside the US, consent to US data processing by accepting their invitation and using the platform.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- —Access — Request a copy of all personal data we hold about you. We will provide a JSON export within 30 days.
- —Deletion — Request deletion of your account and all associated data, including voice recordings in cloud storage. Deletion cascades to all related records and is completed within 30 days.
- —Portability — Download your data in a portable format (JSON for structured data, original format for voice recordings).
- —Correction — Request correction of inaccurate personal data.
- —Restrict Processing — Pause AI processing of your extraction sessions. Raw transcripts are retained but not sent for AI structuring.
- —Withdraw Consent — Revoke voice recording consent at any time via account settings. Revocation stops future sessions but does not retroactively delete existing recordings (deletion is a separate right).
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
10. Do Not Sell My Personal Information
FolioBase does not sell your personal information. We do not share personal data with third parties for their own marketing or advertising purposes. We do not use your voice recordings, transcripts, or AI outputs to train AI models or for any purpose beyond delivering the FolioBase service. This disclosure satisfies the California Consumer Privacy Act (CCPA) requirement.
11. Security
We implement defense-in-depth security: TLS encryption in transit (automatic TLS encryption), encryption at rest (encrypted cloud database and encrypted object storage), strict Content Security Policy headers, role-based access controls with organization-scoped database queries, time-limited signed URLs for file access (15 minutes for documents, 60 minutes for recordings), and comprehensive audit logging. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy when we add new data categories, processors, or AI systems. Material changes will be communicated via email with 30 days' notice before taking effect. The revision date at the top of this page will be updated. Continued use of FolioBase after the notice period constitutes acceptance.
Contact
For questions about this document or to exercise your data rights:
FolioBase
Privacy: [email protected]
Support: [email protected]
Terms of Service
Last updated: February 19, 2026
These Terms of Service ("Terms") govern your use of the FolioBase knowledge extraction platform at foliobase.digital ("Platform"). By creating an account or using the Platform, you agree to be bound by these Terms. If you do not agree, do not use the Platform.
1. Service Description
FolioBase is a knowledge extraction platform that captures voice recordings, documents, and written narratives, then processes them through AI to create structured outputs including playbooks, scorecards, HOTT canvases, meeting rhythms, clarity prisms, story segments, and wisdom gems. The Platform serves three tenant types — business, family, and community — through a unified portal with tenant-specific labels and prompts. The Platform is currently in beta.
2. Eligibility
- —You must be 18 or older to create an organization (Org Admin/Owner role).
- —Team members with full access must be 13 or older.
- —Participants under 13 are currently prohibited. Future support for minors in family tenants will require verifiable parental consent.
- —FolioBase is a US-based service. International participants may use the Platform but agree to US jurisdiction.
3. Account Rules
- —One account per email address.
- —You are responsible for securing your credentials and all activity under your account.
- —Third-party OAuth sessions inherit the authentication provider's account security.
- —Magic link invitation tokens expire after 72 hours (team invitations) or 30 days (family invitations).
- —Beta invite codes are non-transferable.
4. Acceptable Use
You agree not to:
- —Upload content you do not have the right to share.
- —Use extraction sessions to generate outputs that infringe on others' intellectual property.
- —Extract knowledge from employees without their informed consent (business tenant responsibility).
- —Attempt to reverse-engineer the voice interview, AI processing, or transcription provider systems through extraction sessions.
- —Upload malicious content, viruses, or harmful code.
- —Attempt unauthorized access to Platform systems or other users' data.
- —Interfere with the Platform's operation or other users' access.
- —Resell, redistribute, or sublicense access to the Platform or its outputs.
5. Content Ownership
You own your content. Voice recordings, transcripts, and structured outputs are the intellectual property of the organization that created them. FolioBase receives a limited license to process, store, and deliver content as part of the service. We do not use your content for AI model training, marketing, or any purpose beyond delivering the service.
AI-generated outputs (playbooks, scorecards, clarity prisms, HOTT canvases, meeting rhythms, story segments, wisdom gems) are generated by AI from your transcripts. You own the outputs. FolioBase makes no claims on AI-generated content. The underlying platform methodology, frameworks, and analytical processes remain FolioBase's intellectual property.
6. Voice Recording & AI Processing Consent
Voice recording consent: Every extraction session involving voice recording will display a consent prompt before recording begins. You must affirmatively consent (button click) before any audio is captured. The consent states: "This session will be recorded. Your voice and words will be stored, transcribed, and processed by AI to create structured outputs."
AI processing acknowledgment: Before your first extraction session, you must acknowledge that your transcripts will be processed by three AI systems (voice interview provider, AI processing provider, and transcription provider). This is a one-time acknowledgment separate from these Terms.
Multi-participant consent: When you invite someone to an extraction session, the invitee must independently consent to recording and AI processing before the session begins. Your consent does not cover invited participants. Each person whose voice is recorded must individually consent.
7. Business Trade Secret Acknowledgment
Business tenant users acknowledge that extraction sessions may capture proprietary business processes. While FolioBase encrypts and protects this data, no system is immune to breach. You are responsible for deciding what knowledge to extract. Users warrant that they have the right to share any knowledge they extract. Employees extracting business knowledge must have authorization from their employer.
8. AI Output Disclaimer
AI-generated outputs are derived from your input and may contain errors, omissions, or misinterpretations. You must review all outputs before approving them for connected workspace delivery or Folio HQ sync. FolioBase is not liable for decisions made based on AI-generated content. Our services do not constitute legal, tax, accounting, or investment advice.
9. Payment Terms
Subscription billing is handled by our payment processor:
- —Business: $79/month (90 voice minutes included).
- —Family: $29/month (45 voice minutes included).
- —Community: $39/month (60 voice minutes included).
- —Additional voice minute packs available as one-time purchases.
- —Billing cycle is monthly. Unused voice minutes do not roll over.
- —Failed payments trigger subscription suspension after a grace period.
- —No refunds for partial months.
10. Third-Party Delivery Disclaimers
Connected Workspace: Approved outputs synced to your connected workspace leave FolioBase's infrastructure. We are not responsible for data loss, unauthorized access, or policy violations within your connected workspace after sync.
Folio HQ Desktop: Data synced to the desktop application is encrypted in transit and at rest on your device. Once on your device, you are the data custodian. FolioBase is not liable for data loss due to device failure, theft, or user negligence.
11. Limitation of Liability
FolioBase is provided "as is" during the beta period. To the maximum extent permitted by law, FolioBase shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the Platform.
Our total liability for any claim shall not exceed the amount you paid us in the 12 months preceding the claim. FolioBase is not liable for losses caused by AI processing errors, connected workspace sync failures, or third-party service outages.
12. Beta Terms
FolioBase is currently in invite-only beta. Beta users accept that the service may have bugs, feature gaps, and downtime. Beta pricing and features may change. FolioBase may terminate the beta program at any time. Beta users will receive 14-day notice before any pricing changes take effect on their accounts.
13. Termination
FolioBase may suspend or terminate accounts for Terms violations, non-payment, or abuse. You may close your account at any time through your account settings. Upon termination, data is retained for 30 days (recovery window), then permanently deleted per the data retention schedule. Voice recordings are purged within 30 days of account closure.
14. Governing Law
These Terms are governed by the laws of the United States. Disputes shall be resolved through good-faith negotiation first, and if necessary, through binding individual arbitration. Small claims court exception for claims under $10,000.
15. Changes to These Terms
Material changes will be communicated via email with 30 days' notice (14 days for beta-specific terms). Continued use after the notice period constitutes acceptance. When Terms change materially, you may be required to re-accept them.
Contact
For questions about this document or to exercise your data rights:
FolioBase
Privacy: [email protected]
Support: [email protected]
Data Handling
Last updated: February 19, 2026
This page explains how FolioBase handles your data throughout the knowledge extraction process — from the moment you speak or upload, through AI processing, to final delivery.
1. The Extraction Pipeline
Your data moves through a defined pipeline with human review before any output leaves the platform:
1. Capture
You share knowledge through AI-guided voice interviews, browser recording, file upload, or live sessions. Voice audio is transmitted securely and stored in encrypted cloud storage.
2. Transcription
Voice recordings are transcribed by our transcription provider (uploaded files) or voice interview provider (live interviews). The resulting text transcript is stored in our database alongside your account data.
3. AI Structuring
Transcripts are analyzed by our AI processing provider to generate structured outputs — playbooks, scorecards, stories, wisdom gems, and other formats specific to your tenant type.
4. Review & Approval
All AI-generated outputs are presented for your review before delivery. Nothing leaves the platform without explicit approval. You can edit, request changes, or reject outputs.
5. Delivery
Approved outputs can be synced to your connected workspace or Folio HQ desktop app. Once delivered, data governance transfers to the destination system or your local device.
2. Where Your Data Is Stored
Encrypted Object Storage
Voice recordings, uploaded documents, and encrypted sync payloads. Encrypted at rest. Access via time-limited signed URLs (15 minutes for documents, 60 minutes for recordings). No public bucket access.
Encrypted Cloud Database
Account data, organization records, extraction transcripts, structured outputs, billing records, and audit logs. Encrypted at rest and in transit. Per-organization query scoping prevents cross-tenant data access.
3. Data Classification
| Data | Sensitivity | Storage |
|---|---|---|
| Voice recordings | Critical | Encrypted object storage |
| Extraction transcripts | Critical | Encrypted cloud database |
| Structured AI outputs | High | Cloud database + connected workspace (after sync) |
| Family relationship data | High | Encrypted cloud database |
| Payment & billing | Moderate | Cloud database + payment processor |
| Usage metadata | Moderate | Cloud database + error monitoring |
| Account & org data | Standard | Encrypted cloud database |
4. Deletion Requests
You may request deletion of your data at any time. Upon receiving your request, we will:
- —Confirm receipt within 2 business days.
- —Delete all voice recordings and documents from encrypted object storage.
- —Remove all structured data from our database — account records, transcripts, outputs, and organization memberships.
- —Anonymize audit log entries related to your account.
- —Notify downstream processors (CRM provider, error monitoring service) of the deletion.
- —Complete the deletion within 30 days.
- —Send confirmation when deletion is complete.
5. Security Measures
- —Encryption in transit: All connections encrypted via TLS with automatic certificate management. HSTS enforced with 1-year max-age.
- —Encryption at rest: Both our encrypted cloud database and encrypted object storage encrypt data at rest.
- —Access controls: Role-based permissions (admin, owner, team member) with organization-scoped database queries preventing cross-tenant access.
- —Signed URLs: Voice recordings and documents are accessed via time-limited signed URLs, never via public bucket access.
- —Security headers: Strict Content Security Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and restrictive Permissions-Policy.
- —Audit logging: All state-changing actions are recorded in an append-only audit log with 2-year retention.
- —Input validation: Every API endpoint validates input with schema validation before processing.
Contact
For questions about this document or to exercise your data rights:
FolioBase
Privacy: [email protected]
Support: [email protected]