Foly · foly.in
Privacy Policy
Last updated: October 11, 2026
Foly gives you portfolio sites, a jobs board and career tools in one place. This policy explains what we collect, why, how long we keep it, and how to ask for deletion. Contact: support@foly.in.
1. Data we collect
- Account data. Email address and, if you set one, a password (stored hashed). If you use “Continue with Google”, we receive your name, email address and profile picture from Google to create and secure your account.
- Content you provide. Your profile, projects, experience, writing, links, resumes, cover letters, job preferences and settings — the same record that fills your portfolio, resumes and applications.
- Job activity. Saved roles, searches and applications you choose to prepare or track. We never submit an application without your approval.
- Messages. Notes visitors send through your portfolio’s contact form, and job-application emails you choose to forward to Foly for tracking.
- Analytics. If you connect your own Google Analytics property we read its reports for you (see §2). We also keep first-party visit counts for your portfolio so the dashboard works when no GA property is connected.
- Technical logs. Standard server logs (pages requested, timestamps, coarse device/browser info) for security, debugging and abuse prevention.
2. Google user data — what we access and why
Foly uses two separate Google grants. Sign-in stays basic; Analytics access is only requested when you explicitly connect it, in context.
- Sign in with Google (scopes:
openid,email,profile). Used only to authenticate you, verify your email address and link the Google account to your Foly account. We do not request offline access for sign-in and store no Google refresh token for it. - Google Analytics connection (optional) (scopes:
openid,email,https://www.googleapis.com/auth/analytics.readonly,https://www.googleapis.com/auth/analytics.edit). Requested only when you connect a GA4 property in Settings. Used only to list your Analytics accounts/properties, link the property you pick, and fetch its reports for your dashboard — i.e. we read your Google Analytics to show you your own reports. The refresh token is stored encrypted and used only for those tasks. Platform administrators may view those reports when you ask for support. - Revoking. Disconnect any time in Dashboard → Settings → Analytics, and also at myaccount.google.com/permissions. Disconnecting deletes the stored refresh token on our side; already-pulled report aggregates remain part of your dashboard history until you delete your account.
- What we do not touch. Foly does not request Gmail scopes and does not read, send or delete your Gmail. Application emails are tracked only when you forward them to your Foly address.
Google user data is used only for the feature you granted it for, never sold, and shared only with the service providers needed to run Foly (hosting, database, email delivery). AI features send only the text needed for the task you asked for (e.g. drafting a cover letter from a posting).
4. How we use data
- Provide, secure and improve Foly: accounts, portfolios, jobs board, resumes and career tools.
- Publish only what you publish: drafts stay private to you until you publish them.
- Send service messages (sign-in links, receipts, security notices). No marketing email without consent.
- Prevent abuse, debug errors and measure aggregate performance.
6. Retention and deletion
We keep account and content data while your account is active and for a short backup window after deletion. Delete your workspace any time from Dashboard → Settings, or write to support@foly.in from your account email with “Delete my data” and we will delete your account data and confirm. Published portfolios stop being served immediately; search engines and caches may take time to drop copies. We may retain narrow security logs as required by law.
7. Your rights
Ask us for access, correction, export or deletion of your personal data at support@foly.in. Where the GDPR or India’s DPDP Act applies, you have the rights those laws grant, including withdrawing consent for optional processing such as the Analytics connection.
8. Security
Traffic is served over HTTPS, passwords are hashed, OAuth tokens are stored encrypted, and access is scoped per workspace. No method is perfectly secure; use a unique password and keep your Google account’s 2-step verification on.
9. Children
Foly is not for children under 13 (or the minimum age in your country). We do not knowingly collect their data.
10. Changes
When this policy changes materially we will note the new date above and, for significant changes, notify signed-in users by email or in the dashboard before it takes effect.
11. Contact
Foly · https://foly.in · privacy and data requests: support@foly.in.