This document outlines our commitment to safeguarding the security and privacy of the data you entrust to us. Here you will find detailed information about how we host and manage our services, our compliance with international security standards, our data protection practices, and the measures we take to ensure the integrity and availability of our systems.

Folge Desktop App

The Folge desktop application is designed with a local-first approach:

  • Local data: All guides, screenshots, and documentation you create are stored locally on your device. We do not have access to this data unless you choose to publish it to Folge Cloud.
  • Optional cloud publish: You may explicitly publish or resync guides to Folge Cloud. Only when you use “Publish” or “Resync guide” is that content sent to our cloud infrastructure.
  • License validation: For paid licenses, the app may periodically validate your license key over the network. This does not transmit your documentation.
  • Updates: The app may check for updates via HTTP requests. Blocking these requests does not affect core app functionality.
  • Crash reporting: We may use third-party services (such as Sentry) for crash and diagnostic reporting. Personal data is excluded or anonymized. See our Privacy Policy for details.

Hosting

Folge consists of two main offerings: the Folge desktop application and Folge Cloud. Their hosting and infrastructure differ as follows:

  • Folge Desktop App: Runs entirely on your local machine (Mac or Windows). Your guides and documentation are stored on your computer’s file system. No content is uploaded to our servers unless you explicitly choose to publish to Folge Cloud.
  • Folge Cloud: Our cloud hosting for published guides and help centers is provided by:
    • DigitalOcean: Application hosting, compute, and related infrastructure for the cloud service.
    • Amazon S3 (EU): Storage of assets (images, media, and other files) in the European Union.
  • Marketing website (folge.me): The main website is hosted separately; for details on which third-party services may receive personal information, see our Privacy Policy.

Folge Cloud

Folge Cloud hosts published guides and help-center content so you can share them with your team or customers.

  • Application hosting: The cloud application is hosted on DigitalOcean infrastructure.
  • Asset storage: Images, media, and other static assets are stored on Amazon S3 in the EU, in compliance with European data residency requirements.
  • Access control: You can protect published content with password protection and control who has access to your help centers and guides.

Compliance Certifications

Our infrastructure providers maintain recognized security and compliance certifications:

  • DigitalOcean: SOC 2 Type II and SOC 3 Type II certified; ISO 27001 certified data centers; Cloud Security Alliance (CSA) STAR Level 1. More info.
  • Amazon Web Services (S3): SOC 2 compliant; ISO 27001, ISO 27017, ISO 27018, and other internationally recognized certifications; supports GDPR and EU data protection requirements. More info.

Data Storage

  • Folge Desktop App: Data is stored only on your local device. We do not store or process your guides on our servers unless you publish them to Folge Cloud.
  • Folge Cloud: Published guide content, help center data, and user-provided titles and descriptions are processed and stored on our cloud infrastructure. Application data is hosted on DigitalOcean. Files and assets are stored in Amazon S3 in the European Union (EU). Backups are retained in line with our operational and legal requirements.
  • Data deletion: You may request removal of your cloud data at any time by contacting us at hello@folge.me. We will process deletion requests in line with our data retention and backup policies.

Security Measures

  • Encryption in transit: All data in transit between your device and our services is encrypted using TLS/SSL.
  • Encryption at rest: Amazon S3 encrypts data at rest by default. Our cloud infrastructure follows industry practices to protect stored data.
  • Access control: Access to production systems and live user data is restricted to authorized personnel. We use strong authentication and security protocols to safeguard infrastructure and data.
  • Third-party access: We do not sell your data. Access to user data by third parties is limited to service providers necessary to operate our services (e.g. hosting, email). Where feasible, contractors work with test or anonymized data. For details on third-party services that may receive personal information, see our Privacy Policy.

Changes to This Document

We may update this Security and Compliance document from time to time to reflect changes in our services or practices. We encourage you to review this page periodically. For questions about security or compliance, contact us at hello@folge.me.

For terms of use and privacy practices, please see our Terms of Service and Privacy Policy.