Privacy Policy
Last updated: September 2026
Folio is a financial and costing app for small business owners, built for independent restaurants and food businesses. It connects to your bank and credit card accounts so it can categorize your transactions and show you your cash position, profit and loss, product costs, and runway. This policy explains what we collect, why, and what we do not do with it.
The short version. We collect the financial data you ask us to import, the documents you choose to upload, and the email and password you sign up with. We use them to run the app for you. We do not sell your data, we do not share it for advertising, and we do not move money.
Information we collect
Account information
Your email address, a name if you provide one, and a password, which we store only as a bcrypt hash. We never store your password in a readable form and cannot recover it.
Financial account data
When you connect a bank or credit card, we receive, through Plaid:
- Account names, types, and balances
- Transaction history, including date, amount, merchant, and category
- The name of the financial institution
We do not receive or store your online banking username or password. Those are entered directly with Plaid and are never visible to Folio.
Information you create in the app
Categories, tags, notes, manually entered transactions, and product costing data such as ingredients, recipes, prices, and inventory counts.
Documents you import
Photos, PDFs, spreadsheets, and typed descriptions you choose to import, such as recipes, menus, receipts, supplier invoices, point-of-sale sales reports, and settlement statements from delivery platforms like DoorDash, Uber Eats, and Fantuan, along with the items and figures we extract from them.
Technical information
IP address and device information associated with sign-in attempts, kept for security purposes such as detecting unusual access.
Information from our website
If you ask for help getting started on this website, we collect your name and the email address or phone number you give us.
How we use your information
- To import, categorize, and display your transactions
- To calculate the summaries the app exists to provide, such as profit and loss, cash position, margins, runway, and product costs
- To authenticate you, including sending one-time sign-in codes by email
- To process subscription payments, through Stripe
- To run the AI features you use, described in the next section
- To contact you about getting started, if you asked us to on this website
We do not sell your personal information. We do not share it with advertisers. We do not use your financial data to build profiles for anyone other than you.
AI features
Some features send specific data to an AI provider to produce a result. Each one sends only what it needs:
- Category suggestions. A transaction’s merchant name, amount, and date, together with examples of categories and tags you have already confirmed, are sent to Anthropic or Google to suggest a category.
- Document import. When you import a photo, PDF, or typed description, its contents are sent to Google’s Gemini to read the items and figures in it. Spreadsheet statements are read on our own servers.
- Cost assistant. Messages you type to the cost assistant, and any document you attach, are sent to Google’s Gemini to understand your request. Answers about your costs are calculated on our servers.
We do not send your password, bank credentials, or account numbers to AI providers.
Plaid
Folio uses Plaid to connect to your financial institutions. When you link an account, you interact with Plaid directly and enter your credentials into Plaid’s interface, not ours. Plaid handles that data according to its own End User Privacy Policy, which we encourage you to read.
Folio receives an access token from Plaid that allows us to retrieve your account and transaction data. That token is stored on our servers and is never exposed to the app on your device.
Service providers
We rely on a small number of providers, each for a specific purpose:
- Plaid: connecting to your financial institutions
- Google Cloud: hosting our servers, our database, and this website
- Stripe: subscription payments. Card details go to Stripe directly and are never stored by Folio
- Resend: delivering sign-in codes by email
- Anthropic and Google: the AI features described above
How your data is protected
- All traffic between the app and our servers uses TLS 1.2 or better
- Data is encrypted at rest with AES-256
- Sign-in requires a password plus a one-time code sent to your email
- Credentials on your device are stored in the iOS Keychain
- Access tokens are used only to sync the accounts you connected
Data retention and deletion
We keep your data for as long as your account exists. You can delete your account at any time from the app, under the Me tab. Deleting your account removes your transactions, accounts, and profile from our systems, and revokes our access to your financial institutions.
You can also disconnect an individual bank without deleting your account, which stops any further data being retrieved from that institution.
Encrypted database backups are retained for 30 days. Deleted data remains in those backups until they are overwritten, so deletion is complete across all our systems within 30 days.
You can ask us to delete a request you sent through this website at any time. Full details are in our Data Retention and Disposal Policy (PDF).
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information. The app provides export and deletion directly; for anything else, email us and we will help.
Children
Folio is intended for business use by adults. We do not knowingly collect information from anyone under 18.
Changes to this policy
If we make material changes, we will update the date at the top of this page and notify you in the app. Continuing to use Folio after a change means you accept the updated policy.
Contact
Questions about this policy or your data: privacy@zerooneo.com