Skip to content

Security

Private by default. Plain about the rest.

What protects your account and your notes today, described precisely and without overstating it.

In short

  • You verify your email before you can open Folevi.
  • You can turn on two-step verification with an authenticator app, with one-time recovery codes. We recommend it.
  • Data is encrypted in transit (TLS, with HSTS) and at rest by our hosting providers.
  • Nothing is public unless you create a link. Links can expire, require a password, and be revoked instantly.
  • You can export everything, and you can delete your account.
  • Folevi is not end-to-end encrypted, and our admin tools cannot display your notes.

Your account

Email verification

Before you can open Folevi, you confirm that you own your email address. That address is where we send security notices, so it has to be real and yours.

Two-step verification

You can add a second step to signing in: a time-based one-time code (TOTP) from an authenticator app. It’s optional, and we recommend it. With it on, a stolen password alone isn’t enough to get into your account. Turn it on or off any time in Settings → Security.

When you set it up, you receive a set of one-time recovery codes. Each code works once, for the moment you lose your phone. Keep them somewhere safe and separate from your password.

Encryption

In transit. Every connection to Folevi, from your browser or the Mac app, uses TLS. Our sites send HTTP Strict Transport Security (HSTS) so browsers refuse to connect without encryption.

At rest. Your data is encrypted at rest by our hosting and infrastructure providers (see subprocessors below). On the Mac, your notes are stored locally so you can work offline; they’re protected by your Mac’s own security, such as FileVault if you use it.

Folevi is not end-to-end encrypted

We think you should know this clearly and early. In an end-to-end encrypted app, the service can’t read your data at all. Folevi is not built that way, on purpose: our servers need to process your content so that search works across devices, so shared links can show a page to someone you invited, so real-time sync can merge edits, and so we can help if something goes wrong.

If you need notes that no service provider could ever read, a tool with end-to-end encryption is the better choice for that material. We would rather tell you than let you assume.

Sharing

  • Everything is private by default. Public links are off until you create one for a specific page.
  • A link can have an expiry date, after which it stops working.
  • A link can require a password.
  • You can revoke a link at any time. It stops working immediately.

Who can see your notes

You, and the people you deliberately share with. Folevi’s internal admin tools are for managing accounts (for example, account status), and they have no content viewer: there is no screen that displays your pages or blocks.

Our sync logs record technical identifiers, revision numbers and status codes only. They never contain block text, titles, attachment names or contents, sign-in tokens or email addresses.

Export and deletion

You can export any page as Markdown, HTML or PDF, or download everything in your Personal (or, for owners and admins, a workspace) as a ZIP archive. Your writing is never locked in.

You can delete your account at any time. Deletion starts a 7-day grace period in case it was a mistake; after that, your account and its content are deleted permanently.

This website

folevi.com loads no third-party scripts, trackers, advertising pixels or remote fonts. A strict Content Security Policy only allows code from Folevi itself, and pages can’t be embedded in other sites.

Subprocessors

These companies process data on our behalf to run Folevi.

ProviderPurposeWhat it processes
ConvexDatabase and backendYour account record, workspaces, pages, blocks, tasks, uploaded files and the sync operations that keep your devices up to date.
VercelWeb hostingServes folevi.com and the web app. Processes requests to our servers, including IP addresses and standard request logs.
MailtrapTransactional emailYour email address and the content of the emails we send you, such as verification, security notices and share invitations. Open and click tracking is turned off.
Google (Gemini API)Foli (AI assistant)Only when you use Foli: your request and the notes it needs to answer (the open note, or notes found by search that you can already read). Never sent while Foli is off.
PolarPayments (merchant of record)For paid plans and AI credit packs: your email address, billing details, the plan or pack, and internal account ids that link a payment to your account or workspace. Never the content of your notes. Card numbers go straight to Polar; Folevi never sees or stores them.

Reporting a vulnerability

If you believe you’ve found a security problem in Folevi, please email security@folevi.com. Include what you found, the steps to reproduce it, and what an attacker could do with it. We read every report and will reply to confirm we’ve received yours.

While you investigate, please:

  • Only use accounts and workspaces you own or have permission to test.
  • Don’t access, change or delete other people’s data. If you reach any by accident, stop and tell us.
  • Avoid anything that degrades the service for others, such as load testing or spam.
  • Give us a reasonable chance to fix the issue before you share details publicly.