Privacy Policy
Version 2.0, effective 2026-10-05
This Privacy Policy explains how Folio ("we", "us") collects, uses and protects personal data when you use the resume builder at https://foliocv.pages.dev. We collect as little as possible: you can build a resume without an account, and nothing you type leaves your browser until you sign in.
1. Who is responsible (data controller)
[Operator name — individual or company], [Postal address], [Country of the operator]. Contact for any privacy matter: [contact e-mail].
If the law of your country requires a representative or a data protection officer and we appoint one, their details will be listed here.
2. What data we process
- Your Telegram account: when you open the Mini App, Telegram passes us — signed by Telegram — your Telegram user ID, first and last name, username, language and a link to your profile photo. We use them to create and identify your account. We never receive your phone number, contacts or Telegram messages.
- Resume content you save to your account: everything you enter (contact details, work history, education, photo and other information). Please do not include sensitive data (health, religion, political views, ID numbers) unless you really want it in your resume.
- Usage analytics (only with your consent): anonymous events such as page visit, resume created, sign-in or download, the template used, the interface language and where you came from (referrer website or campaign tag). They are linked to a random browser identifier and, if you are signed in, to your account ID.
- Messages: in-app notifications and the messages our bot sends you in Telegram (payment confirmations, view notifications, review results, occasional announcements), and your notification settings.
- Payments (VIP and reviews) are made in Telegram Stars inside Telegram. We store order records — what was bought, the number of Stars, status, dates, Telegram's payment identifier and whether a subscription renews. Card and payment details are handled by Telegram and its payment providers and never reach us.
- Resume reviews: the copy of the resume and the note you submit with an order are shown to the assigned HR expert, who writes the feedback stored with the order.
- Files you export: PDF, Word and other files are generated on your device and passed through our server to your chat with the bot; we do not keep them. For a text PDF a copy of the resume is stored for one hour so that your browser can print it, and then deleted.
- Public links: if you publish a resume, a copy of it is stored and the page is visible to anyone who has the link. If you protect the page with a password, we store only a salted cryptographic hash of it, never the password itself. An optional expiry date is stored with the page.
- Visitors of public pages: to give the page owner statistics we record, for each view or PDF download, the time, the approximate country (from the visitor's time zone, or determined by our hosting provider from the IP address for the owner's notification), the referring site or campaign tag (e.g. a QR code), the device type and the browser language. We do not store visitors' IP addresses and do not set cookies; a session-only flag in the browser prevents counting the same visit twice. This information cannot identify a visitor.
- Technical logs: our infrastructure providers (Cloudflare, Google Firebase) automatically process IP addresses and request logs to deliver the service and keep it secure.
- Account security: each time you open the app we record the device it runs on — its model and operating system, Telegram version, browser engine, screen, time zone, languages, graphics chip, a technical device identifier computed from these characteristics — together with the IP address, the approximate location derived from it (country, region, city) and the network provider, with the dates of the first and the last launch. This is used only to protect accounts and payments from fraud and abuse (for example, one person creating many accounts to get free features), is visible only to Folio administrators and is deleted together with your account.
3. Why we use it and on what legal basis
We do not sell or rent personal data, do not share it for cross-context behavioural advertising and do not use it for automated decisions that have legal or similarly significant effects on you.
- To provide the service — sign you in through Telegram, store and sync your resumes, generate files and public links, process payments (performance of a contract, GDPR Art. 6(1)(b)).
- To keep accounts and the service secure (error monitoring, abuse and fraud prevention) and to block accounts that violate the Terms (our legitimate interest, Art. 6(1)(f); you can object, see section 8).
- To improve the product — aggregated usage analytics (your consent, Art. 6(1)(a), which you can withdraw at any time).
- To send you messages through the bot: about your account, payments and reviews (performance of the contract) and occasional announcements about the service (legitimate interest — you can stop them at any time by blocking the bot).
- To comply with legal obligations and respond to lawful requests (Art. 6(1)(c)).
4. Who receives the data (processors)
Each processor is bound by a data processing agreement and may use the data only on our instructions.
- Google LLC / Google Ireland Ltd. — Firebase Authentication (sign-in with a token issued by our server) and Cloud Firestore. Firestore data is stored in: European Union (europe-west).
- Cloudflare, Inc. — hosts the app and runs our server functions (sign-in check, payments, files sent to your chat, link previews); processes IP addresses and request logs.
- Telegram (Telegram FZ-LLC and its affiliates) — the Mini App platform, the bot and Telegram Stars payments; files and messages from the bot are delivered through Telegram under Telegram's Privacy Policy (telegram.org/privacy).
- Independent HR experts — see the resume copy and note of the review orders assigned to them, only to write the review.
- Functional Software, Inc. (Sentry) — receives technical error reports (error message, code location, browser and OS, page address without parameters). Reports contain no account data, no resume content and no IP address.
- Administrators of the service — can view account data and resumes to provide support and to enforce the Terms. Access is restricted to designated accounts.
5. International transfers
Our providers may process data outside your country, including in the United States. Transfers from the EU/EEA, UK and Switzerland rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses with additional safeguards.
6. How long we keep data
- Account data and resumes — until you delete them or your account. You can do this yourself at any time on the Account page.
- Analytics events — up to 14 months, then deleted or fully anonymised.
- Published public pages and their visit statistics — until you unpublish them or delete the resume or account.
- Data of blocked accounts — kept as long as necessary to keep the block effective and to defend legal claims.
- Copies stored for text PDFs — 1 hour. Payment records — as long as tax and accounting law requires.
- Error reports — up to 90 days.
- Provider logs are deleted on the providers' standard cycles.
7. Cookies and local storage
We use local storage and IndexedDB of the app's browser view for things that are strictly necessary: resumes kept on this device, the interface language, the sign-in session (Firebase), your consent choice and, on public resume pages, a session-only flag that prevents counting the same view twice. These are strictly necessary and do not require consent.
Analytics is switched on only if you accept it in the consent banner. You can change your choice at any time on the Profile page. We do not use advertising or third-party tracking cookies.
8. Your rights
Depending on where you live, you have the right to: access your data and get a copy; correct it; delete it ("right to be forgotten"); restrict or object to processing (including processing based on legitimate interests such as security data); data portability; withdraw consent at any time without affecting earlier processing; and not be discriminated against for exercising your rights.
Self-service: on the Profile page you can get all your data (JSON, sent to your chat with the bot), change notification and analytics settings, unpublish public links and delete your account and all associated data. For anything else write to [contact e-mail]. We answer within one month (GDPR / UK GDPR), 45 days (CCPA/CPRA) or 10 working days (Russian Federal Law No. 152-FZ), as applicable.
You also have the right to lodge a complaint with a supervisory authority — in the EU the authority of your country of residence, in the UK the ICO, in Ukraine the Ukrainian Parliament Commissioner for Human Rights, in Georgia the Personal Data Protection Service, in Russia Roskomnadzor.
9. California residents (CCPA/CPRA)
Categories collected in the last 12 months: identifiers (name, Telegram username and ID), professional and education information you put in resumes, internet or electronic activity (usage events) and inferences — none. Sources: you, Telegram and your device. Purposes: as described in section 3. We do not sell or share personal information and do not use sensitive personal information for purposes that would require a right to limit.
10. Users in the Russian Federation, Ukraine and Georgia
By creating an account you give consent to the processing of your personal data for the purposes described above (Federal Law No. 152-FZ "On Personal Data", Law of Ukraine "On Personal Data Protection", Law of Georgia "On Personal Data Protection"). The consent is valid until you withdraw it — by deleting your account or writing to [contact e-mail].
Personal data is stored by Google Firebase and processed by Cloudflare outside these countries (see section 4), which constitutes a cross-border transfer. Please note: Russian law requires that the personal data of citizens of the Russian Federation be initially recorded in databases located in Russia; this service does not currently provide such storage.
11. Children
The service is not intended for children under 16. We do not knowingly collect their data; if you believe a child has created an account, contact us and we will delete it.
12. Security
Data is encrypted in transit (HTTPS) and at rest by Google Cloud. Access rules ensure that every user can read only their own data; administrator access is limited to designated accounts. No method of transmission or storage is 100% secure — if a breach affecting your rights occurs, we will notify you and the competent authority as required by law.
13. Changes
We may update this policy. Material changes will be announced in the app or by a message from the bot before they take effect. The version and effective date are shown at the top.