1. Collection data stored on your device
- Front and back photos of cards you capture or choose from Photos.
- Card names, series, tags, collection dates, and notes you enter.
- Collector name, avatar, and display preferences you set in the app.
This content is stored locally on your device by default, and Folio does not upload it to a developer server. You can manually export a complete library backup and import it on a device. Folio does not currently provide automatic cloud backup or cross-device sync.
2. Account, phone number, and CloudBase
The mainland China version allows the on-device library to be used without signing in. When you choose to sign in, purchase or restore Folio Pro benefits, or manage the account, you can use a +86 phone number and SMS code for sign-in or registration. If the number is not registered, verification creates a Folio account. Tencent CloudBase identity services in the Shanghai region process the phone number. The app stores the session in the device Keychain and does not display the phone number publicly.
Folio creates a stable internal UID and stores account mappings, device records, consent records, and a limited set of product events in Shanghai. Events include successful sign-in, first card creation, successful capture, and paywall presentation. They support account security, troubleshooting, and product improvement, and do not contain card names, card or photo content, notes, search text, contacts, or raw verification codes.
The mainland China Release build currently does not enable TelemetryDeck and does not send these account events to an overseas analytics service. We will update this policy and in-app disclosure before that practice changes.
In versions that support it, Anonymous Usage Analytics is off by default. Only after you turn it on will Folio create a random installation identifier and send the app version, event time, and these events to Tencent CloudBase in Shanghai: session started, onboarding started, capture started, first card created, capture succeeded, onboarding completed, card opened, search opened, search submitted, search result opened, paywall viewed, and purchase started. Some events include only predefined entry-point, plan, count, position, or duration buckets; no free text is sent. Folio does not backfill activity from before consent or include your phone number, Folio account UID, card names, photos, notes, search text, language, or location.
Raw anonymous events are retained for no more than 180 days. Irreversible aggregates that meet the minimum sample threshold may be retained for up to 24 months. You can turn analytics off in Settings at any time; Folio then stops sending events, clears its pending local queue, and requests deletion of raw events associated with that random installation identifier. Aggregates already formed above the minimum sample threshold may remain because they cannot be traced back to an installation and contain neither an installation identifier nor a Folio account identifier.
3. Camera and Photos access
Camera access is used only to capture physical cards. Photos access is used only to select images you choose to import. Folio does not read or collect other photos without your action. You can change permissions at any time in iOS Settings.
4. App Store purchases and subscriptions
Apple processes Folio Pro purchases, payment, renewal, refunds, and transaction verification through the App Store. To prevent entitlements from being shared with the wrong Folio account, Folio associates the internal UID with verified transactions using Apple's appAccountToken and reads product, subscription status, and expiration. Folio does not receive your Apple Account password or full payment-card details. Apple's handling of payment information is governed by its own Privacy Policy.
Once server-side subscription notifications are enabled, Folio will also validate Apple's signature and app identity, then record the transaction ID, product, purchase or renewal time, refund or revocation status, and available account association for administrator-only aggregate reporting and notification-gap checks. An in-app “purchase successful” message is not counted as a verified transaction. Folio does not receive payment amounts or card details for this reporting.
5. Retention and account deletion
While an account exists, we retain records needed for sign-in, security, subscription association, and product operation. In Folio's account screen, choose “Delete Folio Account,” request a second SMS code, and confirm permanent deletion. After verification, the authentication account is deleted and records associated with the Folio UID enter a deletion queue planned to complete within seven days, except for minimal records required by law or security obligations.
Deleting the Folio account does not delete local cards, photos, or notes and does not automatically cancel an App Store subscription. Export any local content you need and cancel the subscription separately through Apple. Uninstalling Folio removes the local collection and session, but it is not a substitute for deleting the cloud account.
If in-app deletion fails or remains incomplete for more than seven days, contact support. Do not send an SMS code, Apple Account password, or full transaction credential.
6. Tracking, advertising, and sale of data
Folio does not show third-party ads, track you across apps or websites, or sell personal data. Folio does not use identifiers for advertising tracking.
7. Changes and contact
If our data practices materially change, we will update this page and its effective date. For privacy, account, or deletion questions, visit Folio Support or email lujuncheng1225@gmail.com.