Privacy Policy

Last updated: July 2026

This policy explains what happens to your data when you visit this website, buy folo, and use the app. The short version: this website sets no cookies and uses only privacy-friendly, cookieless analytics. folo records locally, recognizes speakers on-device, and uses the globally selected transcription and summary backends described below.

1. Who is responsible

The controller is Nico Hülscher, Boverstraße 19C, 45473 Mülheim an der Ruhr, Germany — [email protected] (see also the Impressum).

2. This website

The site is a static website and sets no cookies. It does not track you across sites or build any profile of you, and the brand fonts are self-hosted, so your browser makes no request to Google Fonts or any external font service.

For aggregate, privacy-friendly usage statistics we use Cloudflare Web Analytics, configured to exclude visitors from the EU. Visitors from the EU are therefore not measured by Cloudflare Web Analytics. It is cookieless and stores nothing on your device; for non-EU visitors it records only anonymous, aggregate metrics (such as page views, referrer, country and device type) without cross-site tracking or advertising identifiers.

We also load our self-hosted Umami tracker from umami.kveik.studio for every visitor, including visitors from the EU. Umami records anonymous page views, referrer, country, browser, operating system and device type. It uses no cookies or cross-site tracking; sessions are represented by an anonymous hash derived from the IP address, user agent and website ID. The legal basis for both analytics services is our legitimate interest in understanding and improving the site (Art. 6(1)(f) GDPR).

The site is hosted by Cloudflare Pages. When you load a page, the host automatically processes technical connection data (your IP address, browser/user-agent, requested URL, timestamp) in server logs, which is necessary to deliver the site securely (Art. 6(1)(f) GDPR). Cloudflare, Inc. is based in the USA, so hosting (and, for non-EU visitors, analytics) may involve a transfer of personal data to the United States, safeguarded by the EU–U.S. Data Privacy Framework (to which Cloudflare is certified) and/or the EU Standard Contractual Clauses; you can request a copy of these safeguards from us. See cloudflare.com/privacypolicy.

3. Buying folo

Checkout is handled by Paddle (Paddle.com Market Ltd, UK, with its US affiliate Paddle.com Inc.), which acts as our Merchant of Record and reseller. When you buy, the data you enter (name, email, billing/country and payment details) is processed by Paddle to take payment, handle EU VAT, and send your invoice. Paddle is an independent controller for that data; see its privacy policy at paddle.com/legal/privacy. Where checkout involves transfers outside the EU/EEA (to the UK and the USA), these are safeguarded by adequacy decisions and the EU Standard Contractual Clauses as set out in Paddle's privacy policy. We receive only the order information needed to issue your license key and to fulfil and support your purchase.

4. The folo app

folo is built to keep your meetings private:

  • Recording captures system audio and your microphone locally on your Mac. Nothing joins your call — there is no bot and no server-side recording.
  • Transcription runs on-device with WhisperKit, Apple’s SpeechAnalyzer or NVIDIA Parakeet. If ElevenLabs Scribe is selected globally in Settings instead, folo uploads the meeting audio to ElevenLabs; speaker separation stays on-device.
  • Speaker recognition is on-device. Voice profiles you create are stored in a local speaker database on your Mac.
  • App storage is local. Audio is deleted after transcription by default, and transcripts live in a local database under your control. Optional processors receive only the data described below.

Transcripts and voice profiles remain on your Mac until you delete them; we set no retention period because we hold no copy.

5. Processing backends

The transcription and summary backends are selected globally in Settings, not per meeting. Apple Intelligence, Ollama and Local MLX process summaries locally. ElevenLabs Scribe receives meeting audio when it is selected as the transcription backend and uses your own ElevenLabs API key, which folo stores in the macOS Keychain.

Cloud (Claude Haiku 4.5) sends transcript text directly to Anthropic using your Anthropic API key, which folo stores in the macOS Keychain. Claude Code (Anthropic cloud via local CLI) sends transcript text to Anthropic through the locally installed claude CLI. That CLI handles its own authentication; folo stores no Anthropic API key for Claude Code mode. The providers process received data under their own terms.

Ask AI uses the same selected summary backend. With Cloud (Claude Haiku 4.5) or Claude Code, folo sends your question, prior Ask AI turns and meeting context to Anthropic. For a single meeting, that context can be the full transcript or relevant transcript passages when the transcript is longer. A cross-meeting question sends relevant transcript passages and may also include open action items from multiple meetings. With a local summary backend, the question, prior turns and meeting context stay on your Mac.

6. MCP client access

When you enable Settings → MCP, the local kveik MCP integration lets connected clients such as Claude or Cursor search and read meeting metadata (title, time, duration and participants) and project data from the shared local graph. The current graph projection does not expose meeting audio or transcripts. The MCP also lets a client list and invoke actions registered by suite apps and set up Døgn tracking; those tools can change suite or project state. Data returned by the integration is handed to the connected client. Further processing by that connected client is governed by its privacy settings and terms. Only connect clients you trust and review requested actions before allowing them.

7. Configured webhooks

When you add a webhook, folo sends the meeting events you select to that user-added HTTPS endpoint. The payload contains the local numeric ID, suite UUID when available, title, start, end, duration, language, attendees and status; assignment events also contain the engagement ID. Webhook payloads do not contain audio, transcripts or summaries.

8. Recording responsibly

You are responsible for recording lawfully. Depending on your jurisdiction and the participants’ location, you may need the consent of everyone in the meeting before recording. In many jurisdictions, including Germany, recording a conversation without the consent of all participants can be a criminal offence (e.g. § 201 of the German Criminal Code). folo is designed for consent-first recording, but obtaining that consent is your responsibility.

9. Software updates

The app checks for updates so it can keep itself signed, notarized and current. When it checks, it contacts the update feed (hosted on Cloudflare) via the Sparkle update framework, which necessarily sees your IP address and app/OS version. This is used only to serve the correct update and is based on our legitimate interest in shipping secure software (Art. 6(1)(f) GDPR). You can disable automatic update checks in the app.

10. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing based on legitimate interests. You also have the right to lodge a complaint with a supervisory authority. To exercise any of these, contact [email protected]. Note that recordings, transcripts and speaker data held only inside the app on your Mac are under your direct control — we have no copy of them.

11. Changes to this policy

We may update this policy as the product or our providers change. The current version always lives at this URL, with the “last updated” date above.