Skip to main content

Trust

Security

Connected context stays scoped, encrypted, and reviewable — before anything moves.

Access model

Sign-in (Google) is identity only. Each source — Gmail, Calendar, Drive, Outlook — is connected separately through its own OAuth grant, scoped to only what that feature reads. Disconnecting a source revokes its token immediately; nothing is read without an active, revocable grant.

Read-only by default

Foldera observes and drafts. It never sends an email, edits a file, or takes any action on a connected account unless you explicitly approve that specific move.

Encryption

Signal content and OAuth tokens are encrypted separately at the storage layer. Data in transit uses TLS.

Data retention

Extracted signals older than 180 days are purged automatically by a scheduled job. Deleting your account removes your data according to the same retention policy.

Sub-processors

Supabase (database), Vercel (hosting), Anthropic (language model), Resend (transactional email), and Stripe (billing) run core product infrastructure. None of them receive your data for any purpose beyond serving your Foldera account.

Never trained on

Your content is not used to train models. It is processed to generate your outputs and nothing else.

Security questions: support@foldera.ai. Full data-handling terms: Privacy Policy.