Security
Private by default. Plain about the rest.
In short
- You verify your email before you can open Folevi.
- You can turn on two-step verification with an authenticator app, with one-time recovery codes. We recommend it.
- Data is encrypted in transit (TLS, with HSTS) and at rest by our hosting providers.
- Nothing is public unless you create a link. Links can expire, require a password, and be revoked instantly.
- You can export everything, and you can delete your account.
- Folevi is not end-to-end encrypted, and our admin tools cannot display your notes.
Your account
Email verification
Before you can open Folevi, you confirm that you own your email address. That address is where we send security notices, so it has to be real and yours.
Two-step verification
You can add a second step to signing in: a time-based one-time code (TOTP) from an authenticator app. It’s optional, and we recommend it. With it on, a stolen password alone isn’t enough to get into your account. Turn it on or off any time in Settings → Security.
When you set it up, you receive a set of one-time recovery codes. Each code works once, for the moment you lose your phone. Keep them somewhere safe and separate from your password.
Encryption
In transit. Every connection to Folevi, from your browser or the Mac app, uses TLS. Our sites send HTTP Strict Transport Security (HSTS) so browsers refuse to connect without encryption.
At rest. Your data is encrypted at rest by our hosting and infrastructure providers (see subprocessors below). On the Mac, your notes are stored locally so you can work offline; they’re protected by your Mac’s own security, such as FileVault if you use it.
Folevi is not end-to-end encrypted
We think you should know this clearly and early. In an end-to-end encrypted app, the service can’t read your data at all. Folevi is not built that way, on purpose: our servers need to process your content so that search works across devices, so shared links can show a page to someone you invited, so real-time sync can merge edits, and so we can help if something goes wrong.
If you need notes that no service provider could ever read, a tool with end-to-end encryption is the better choice for that material. We would rather tell you than let you assume.
Sharing
- Everything is private by default. Public links are off until you create one for a specific page.
- A link can have an expiry date, after which it stops working.
- A link can require a password.
- You can revoke a link at any time. It stops working immediately.
Who can see your notes
You, and the people you deliberately share with. Folevi’s internal admin tools are for managing accounts (for example, account status), and they have no content viewer: there is no screen that displays your pages or blocks.
Our sync logs record technical identifiers, revision numbers and status codes only. They never contain block text, titles, attachment names or contents, sign-in tokens or email addresses.
Export and deletion
You can export any page as Markdown, HTML or PDF, or download everything in your Personal (or, for owners and admins, a workspace) as a ZIP archive. Your writing is never locked in.
You can delete your account at any time. Deletion starts a 7-day grace period in case it was a mistake; after that, your account and its content are deleted permanently.
This website
folevi.com loads no third-party scripts, trackers, advertising pixels or remote fonts. A strict Content Security Policy only allows code from Folevi itself, and pages can’t be embedded in other sites.
Subprocessors
These companies process data on our behalf to run Folevi.
| Provider | Purpose | What it processes |
|---|---|---|
| Convex | Database and backend | Your account record, workspaces, pages, blocks, tasks, uploaded files and the sync operations that keep your devices up to date. |
| Vercel | Web hosting | Serves folevi.com and the web app. Processes requests to our servers, including IP addresses and standard request logs. |
| Mailtrap | Transactional email | Your email address and the content of the emails we send you, such as verification, security notices and share invitations. Open and click tracking is turned off. |
| Google (Gemini API) | Foli (AI assistant) | Only when you use Foli: your request and the notes it needs to answer (the open note, or notes found by search that you can already read). Never sent while Foli is off. |
| Polar | Payments (merchant of record) | For paid plans and AI credit packs: your email address, billing details, the plan or pack, and internal account ids that link a payment to your account or workspace. Never the content of your notes. Card numbers go straight to Polar; Folevi never sees or stores them. |
Reporting a vulnerability
If you believe you’ve found a security problem in Folevi, please email security@folevi.com. Include what you found, the steps to reproduce it, and what an attacker could do with it. We read every report and will reply to confirm we’ve received yours.
While you investigate, please:
- Only use accounts and workspaces you own or have permission to test.
- Don’t access, change or delete other people’s data. If you reach any by accident, stop and tell us.
- Avoid anything that degrades the service for others, such as load testing or spam.
- Give us a reasonable chance to fix the issue before you share details publicly.
