Your data.
Our responsibility.
What we collect.
When you join the FolioSpace waitlist, we collect:
- Your email address — to contact you about the launch.
- Your role (optional) — to understand who FolioSpace is for.
- Your IP address — used only to prevent spam and abuse, then discarded within 24 hours. We do not retain IP addresses once the join request has been processed.
- If you arrive via a tagged link, the referral source (for example
utm_source=twitter) — so we can tell which channels send us the most useful people, not to track you across the web.
That's it. No third-party trackers, no analytics scripts, no fingerprinting.
How we use it.
We use your email for exactly two things:
- Send you a welcome email confirming you're on the list.
- Send you one launch email when FolioSpace goes live, plus an optional reminder or two before that.
We do not sell, rent, or share your email with anyone. Ever.
Where it lives.
Email addresses are stored in a Postgres database hosted on Neon (US East region). Welcome and launch emails are sent via Resend, a transactional email provider. Both services are GDPR-compliant and use TLS in transit.
Your rights.
You can ask us to delete your data at any time. Reply to any FolioSpace email with "delete" and we'll remove your record within 7 days. You can also email us directly at foliospace.in@gmail.com.
If you're an Indian resident, the Digital Personal Data Protection Act 2023 gives you the right to access, correct, and erase personal data held about you. The above deletion process satisfies that.
What we collect once you sign up.
If you create a FolioSpace account, we additionally collect and store:
- Account basics — display name, email, slug, phone (optional), role (optional), bio (optional), public/private flag.
- Avatar — uploaded photos are stored on Cloudinary (US). If you link LinkedIn, we copy your LinkedIn profile photo to Cloudinary on every sync and label it with
avatar_provider='linkedin'. If you unlink LinkedIn, the photo is removed from Cloudinary andavatar_provideris cleared. If you uploaded the photo yourself (avatar_provider='cloudinary'or'manual'), unlinking LinkedIn will not delete it. - LinkedIn (OAuth) — when you click Connect LinkedIn, we request the
openid profile emailscope only. Two LinkedIn endpoints are then called with your bearer token:GET https://api.linkedin.com/v2/userinfo— OpenID Connect userinfoGET https://api.linkedin.com/v2/me?projection=(id,localizedFirstName,localizedLastName,localizedHeadline,vanityName,profilePicture(displayImage~:playableStreams))— basic profile projection
sub— your LinkedIn user ID (stored associal_accounts.provider_uid)email— your primary LinkedIn email (stored associal_accounts.email)name,given_name,family_name— from/v2/userinfo;nameis copied tousers.display_nameonly on your first signupemail_verified— boolean flaglocale(e.g.en_IN) andzoneinfo(e.g.Asia/Kolkata) — language and timezonepicture— your LinkedIn profile photo URL; we download this and re-upload it to Cloudinary as your folio avatar (labelledavatar_provider='linkedin')localizedFirstName,localizedLastName,localizedHeadline— your first name, last name, and professional headlinevanityName— your LinkedIn vanity slug, used to derive your public profile URL (https://www.linkedin.com/in/<vanityName>)access_token,scope,expires_at,last_synced_at— stored on thesocial_accountsrow; the access token is Fernet-encrypted at rest
users.rolefield is empty), your LinkedIn headline is also copied intousers.roleand truncated to 60 characters. We do not capture, and the OAuth scope does not allow us to capture, any of the following:- Work experience / positions history
- Education history
- Skills, endorsements, recommendations
- Connections, followers, contact list
- Posts, articles, comments, shares, reactions
- Messages or InMail
- Job applications or recruiter activity
- Advertising data, audience insights, conversion tracking
- Ad targereting / matched audiences
- GitHub (OAuth) — when you click Connect GitHub, we fetch your public repos, contribution graph, and basic profile (login, name, bio, avatar URL) via the public REST API. Your access token is Fernet-encrypted at rest. We do not read your private repos, gists, or issues.
- Gravatar enrichment — once per email verification, we look up
api.gravatar.comusing a SHA-256 hash of your email and copy any job title, bio, and linkedin_url you have published there into your FolioSpace profile — only filling fields that are currently empty.
You can disconnect any provider at any time from /<your-slug>/manage. Disconnecting removes the OAuth identity and (for LinkedIn) the mirrored avatar; data you copied into your own profile (name, role, bio, phone, linkedin_url) is kept — it's yours. Disconnecting does not call the provider's revocation endpoint; you can also revoke FolioSpace from LinkedIn or GitHub directly.
How long we keep it.
If you joined the waitlist but never signed up for an account, we plan to delete waitlist-only emails 90 days after public launch. We'll send a final reminder before deletion. If we miss the 90-day mark for any reason, you can still ask us to delete your record at any time using the process in Your rights above — your email is never used for marketing during this period.
Children's privacy.
FolioSpace is not directed at children under 13. We do not knowingly collect data from anyone under 13. If a parent or guardian believes their child has signed up, email us and we'll delete the record.
Changes to this policy.
If we ever change this policy in a material way, we'll email everyone on the list with the diff and a link to the updated version. We'll never change it silently.
Get in touch.
Questions, complaints, or data requests: foliospace.in@gmail.com. We reply within 48 hours.