Effective 6 September 2026 · Policy version 1.2 · Folio for Android and iOS
The rest of this document says the same thing precisely, because that is what a privacy policy is for.
Folio is published and operated by the Folio developer (“we”, “us”), an individual developer rather than a registered company.
For the purposes of the EU General Data Protection Regulation, we are the data controller for the information described in sections 3, 7, 8 and 9.
You can reach us about anything in this policy at codeplay.md@gmail.com.
Everything you type into the app — full name, email address, phone number, postal address, date of birth, profile photo, work history, education, skills, languages, certificates, references, projects and any custom sections — is written to a database inside the app’s private storage on your own device.
That information:
The one exception is the PDF import feature in section 7, which uploads a file you pick so that its text can be read back as fields. Nothing else in the app sends your CV anywhere, and import only runs when you start it.
Apart from that, we cannot look at your CV, share it, sell it, lose it in a breach of our systems, or hand it to anyone who asks us for it.
If your device’s own backup service is switched on — Google One backup on Android, or iCloud Backup on iPhone and iPad — your device may include the app’s data in that backup. That backup belongs to you and is governed by Google’s or Apple’s privacy policy, not by ours. You control it in your device settings.
To keep Folio working and to understand which parts of it are worth improving, the app sends a limited amount of technical and usage information to Google’s Firebase platform. Firebase acts as our processor; we are the controller.
| What | What it contains | Why |
|---|---|---|
| Crash reports (Firebase Crashlytics) |
The technical details of a crash: the error, the point in the code it happened, your device model, operating system version, available memory and storage, and a random installation identifier | To find and fix the crash |
| Performance data (Firebase Performance Monitoring, Android only) |
How long the app takes to start, how long screens take to appear, device model and OS version | To find what is slow |
| Usage statistics (Google Analytics for Firebase) |
Which screens are opened; which CV template is chosen and from which category; which language the CV is written in; which app interface language is set; whether an export finished or was cancelled; whether a paywall or a video offer was shown and what was chosen; a random app-instance identifier; device model, operating system, and the country your IP address resolves to | To learn which templates and languages people actually use, and where the app is confusing enough that people give up |
Three points about the table above:
To be explicit, Folio does not:
On Android, advertising and the advertising identifier are covered by section 9. That is the one place where those words do not apply, and it applies only when you choose to watch a video.
If you add a photo to your CV, the app asks your device for access to your photo library, and you can refuse. The photo you pick is cropped on the device and saved into the app’s private storage as part of your CV. It is never uploaded. We have no access to it and no copy of it. Removing the photo in the app, or deleting the CV, removes it.
If a PDF you import under section 7 contains a photograph, that photograph is part of the file you upload and is handled as the rest of that file is.
When you export a CV, the app renders the PDF on your device and hands the finished file to your operating system’s own save or share screen. The file does not pass through us. Where it goes next — your Downloads folder, an email, a messaging app, a cloud drive — is your choice, and from that point the file is governed by whatever service you sent it to.
The app records that an export happened, with the template number, the CV language and whether it completed or was cancelled. It does not record the file, its contents, its name or where you sent it.
Folio can read an existing CV out of a PDF so that you do not have to retype it. This is the one feature where your CV leaves your device, so it is worth being exact.
When you choose a PDF and confirm the import:
folio.api.mireyarosca.md. Your own file name is not sent with it.Import runs only when you start it. It is never triggered in the background, and the app never scans your device for documents on its own.
Folio offers Folio PRO, which unlocks every template, removes the Folio line from the exported page, and removes advertising. Buying it is optional and the app is usable without it.
We never see your payment details. The purchase itself is made with the Apple App Store or Google Play. They charge your store account, they hold your card and billing information under their own privacy policies, and they tell us only whether a purchase succeeded.
To keep your PRO status correct across your devices and after a reinstall, the app uses RevenueCat, Inc. as its purchase processor. RevenueCat receives:
RevenueCat does not receive any part of your CV. Its handling of the above is described at https://www.revenuecat.com/privacy.
If you never buy anything and never restore a purchase, there is nothing for this section to apply to.
On iPhone and iPad there is no advertising in Folio, and this section does not apply.
On Android, Folio can offer you a short video to watch in exchange for one clean export, as an alternative to buying PRO. Advertising in Folio works in a way worth stating plainly:
The videos are supplied by Google AdMob. When you choose to watch one, AdMob receives the information it needs to select and measure an ad: your device’s advertising identifier, IP address, device and operating system details, and the fact that an ad was requested, shown and watched to the end. Google’s handling of that is described at https://policies.google.com/technologies/partner-sites.
Consent, where the law requires it. In the European Economic Area, the United Kingdom and Switzerland, you are asked through Google’s certified consent form whether you agree to personalised advertising. That form is shown before the first video, not when you open the app, because most people never ask for a video at all. If you refuse, or if consent cannot be obtained, no ad is requested and you keep the other way out of the export screen. Your answer is remembered between sessions, and you can change or withdraw it at any time — see section 15.
Your advertising identifier is a resettable device-level identifier that belongs to you. You can reset it or switch off ad personalisation entirely in Settings → Google → Ads on your device, and that setting overrides anything chosen inside the app.
Four organisations receive data from Folio, each for one purpose and none of them for their own:
| Who | What they get | When |
|---|---|---|
| Google (Firebase) |
Crash, performance and usage data (section 3) | Always |
| Our import server and a language-model provider |
The PDF you chose, and the text extracted from it (section 7) | Only when you import a PDF |
| RevenueCat | A random app user id and your store receipt (section 8) | Only when you buy or restore PRO |
| Google (AdMob and its consent platform) |
Advertising identifier and ad request data (section 9) | Android only, and only when you choose to watch a video |
Their own terms:
These providers process data on servers that may be located outside the European Economic Area, including in the United States. Those transfers are covered by the European Commission’s Standard Contractual Clauses, which each of them incorporates into its data processing terms.
We use no attribution or install-tracking service, no customer data platform, and no analytics provider other than the one named above.
| Data | Kept for |
|---|---|
| Your CVs, on your device | Until you delete them or uninstall the app. We keep no copy and impose no expiry. |
| Crash reports | 90 days, then deleted automatically by Firebase Crashlytics |
| Performance data | 90 days, then deleted automatically by Firebase Performance Monitoring |
| Usage statistics | 14 months, then deleted automatically by Google Analytics. Aggregated totals, which cannot be traced to any installation, are kept longer. |
| A PDF you import, and its extracted text | Held in memory for the length of the request and not retained by us. The model provider’s retention is governed by its own terms. |
| Purchase records at RevenueCat | For as long as the app exists, so that a purchase can still be restored years later. That is the point of keeping them. |
| Ad request data at Google | Under Google’s own retention policy, linked to a resettable advertising identifier rather than to you |
Your CVs. Delete an individual CV from the home screen, or uninstall the app to remove all of them at once, along with the photos attached to them. Because the data lives only on your device, uninstalling is a complete deletion — there is nothing left anywhere else, and you do not have to ask us for it.
Anything you imported. There is nothing for us to delete: the file and its text are not retained once the import has finished. The CV it produced is on your device like any other, and you delete it the same way.
Diagnostics and usage statistics. Because these carry no identifier that we can link to you, we cannot search for “your” records in order to erase them, and neither can anyone else. What you can do instead is stop them being collected at all — see section 15 — and reinstall the app, which discards the old random installation identifier for good.
Purchases. A purchase record has to survive in order to be restorable, so we do not delete it on request by default. If you want it erased anyway, write to us with the store order number and we will have it removed, accepting that the purchase can no longer be restored afterwards.
Advertising. Reset or clear your advertising identifier in your device settings, as described in section 9.
If you want to ask us anyway. Write to codeplay.md@gmail.com and we will answer within 30 days, including when the honest answer is that we hold nothing that could be yours.
Under Article 6 of the GDPR:
Where the law in your country requires consent for any of the other purposes instead, we rely on that consent, and you can withdraw it using the controls in section 15.
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we relied on it.
If you are a California resident, you have the right to know what personal information is collected and for what purpose, to request its deletion, to request correction, to opt out of the sharing of personal information for cross-context behavioural advertising, and not to be discriminated against for exercising those rights.
We do not sell your personal information for money, and we never have. On Android, choosing to watch a video and consenting to personalised advertising may count as “sharing” for advertising purposes under California law. You opt out of it the same way you withdraw consent anywhere else: decline the consent form, switch off ad personalisation in your device settings, or buy PRO, which removes advertising outright. On iPhone and iPad there is no advertising and nothing to opt out of.
The practical answer for most of this is short, and it is the answer in section 12: your CV is on your device, the diagnostics that reach us are not linked to you, and the one upload the app makes is one you start and we do not keep.
To exercise any of these rights, write to codeplay.md@gmail.com.
You also have the right to complain to your national data protection authority. In the EU, a list is published at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Personalised advertising (Android). Switch ad personalisation off for the whole device in Settings → Google → Ads, which overrides any answer given inside the app, and reset your advertising identifier there at the same time if you want a clean slate. Buying PRO removes advertising entirely.
Android diagnostics. Open Settings → Google → All services → Usage & diagnostics on your device and turn it off. This stops Firebase collecting diagnostics from apps, including Folio.
iPhone and iPad. Open Settings → Privacy & Security → Analytics & Improvements and turn off “Share iPhone Analytics”.
Importing. Simply do not use the import feature. Nothing about it runs unless you start it.
Everything, at once. Uninstalling the app stops all collection immediately and discards the random installation identifier. Your saved CVs are deleted with it, so export anything you want to keep first.
Folio is a tool for job seekers and is not directed at children. We do not knowingly collect personal data from children, and the app is not listed in any store’s children’s category or family programme.
You should not use Folio if you are under 16, unless the law of your country sets a lower age for consenting to online services on your own — in the European Union this varies between 13 and 16 depending on the member state — in which case that lower age applies.
If you believe a child has used the app in a way that put their data in our hands, write to codeplay.md@gmail.com and we will look into it.
Your CV is held on your device and protected by the operating system’s own app sandbox and by whatever lock you have set on the device — so a screen lock is worth having.
Everything the app sends — diagnostics to Firebase, a PDF to our import server, a receipt to RevenueCat, an ad request to Google — travels over encrypted connections, and the app refuses unencrypted traffic outright. The import server holds a file only for the length of the request. No method of transmission or storage is perfectly secure, and we do not claim otherwise.
If we change what the app collects, we will update this page and change the effective date at the top before the new version of the app is released. Material changes — a new category of data, a new third party, or a new use of advertising — will be described here plainly rather than folded into the text, and the corresponding declarations in the Google Play Data safety form and the Apple App Store privacy label will be updated in the same release.
Previous versions of this policy remain available on request.
Questions, requests and complaints about this policy:
codeplay.md@gmail.com — the Folio developer
Please put “Privacy” in the subject line. We answer within 30 days.