Folio
Privacy
What Folio does with your documents, in plain terms — including the parts that are less convenient to say.
Atualizado pela última vez em 15 September 2026
The short version. Fourteen of the eighteen tools do their work inside your browser tab, and the file never leaves your machine — we could not read it if we wanted to. Three send it to a server and delete it as soon as the result is on its way back to you: PDF to Word, which needs a converter, OCR PDF, which needs a server to read the text off a scan, and the editor when you download, which sends the original file and your edits so the PDF can be rebuilt in its own fonts. You do not need an account for any of those. eSign, the last one, sends a PDF for other people to sign: it needs an account, and it keeps the file, and a record of who signed it, in that account.
Your documents
The tools that run in your browser
Editing text, merging, splitting, extracting, deleting, organising, compressing, protecting, unlocking and turning images into a PDF all happen in JavaScript, in the tab. The file is read into memory on your own machine and the result is written back out there. Nothing is transmitted to us, so there is nothing for us to keep, lose or hand over. Close the tab and the document is gone.
PDF to Word
Converting a PDF to a .docx needs software that cannot run in a browser, so this one tool uploads. The file travels over an encrypted connection, is written to a temporary directory on the server, converted, and that directory is deleted as soon as the response has been sent. We do not keep the PDF you uploaded.
The converted .docx is kept only if you are signed in and saving is on — it is on by default for signed-in accounts, and you can turn it off in your settings. If a conversion is saved, we also record the original PDF's filename and size alongside it, so the saved file is identifiable in your list. Signed out, nothing is saved at all.
eSign: sending a PDF for signature
A signature request needs the document for as long as it is open, and a record of what happened to it afterwards, so this tool keeps both. The PDF you send is uploaded to your account, and the request keeps its own copy of it so the record does not depend on you keeping the file. When everyone has signed, the signed PDF is added to your files.
For each person you ask to sign we store the name and email address you give us, the picture of their signature, the name they type, and, when they open, sign or decline, the time, IP address and browser identification string. Those details are written into the request's audit trail and printed on the certificate page of the signed PDF, which is the point of it: the record is evidence of who signed and when. We email a signer only about that request — the invitation, a reminder you send, and the finished copy.
Requests and their audit trails are kept for as long as your account is. Deleting your account withdraws any request still open, tells the people still waiting, and removes the requests with it.
Files and drafts you choose to keep
With an account you can keep results and let the editor autosave what you are working on. Saved files are stored as the actual bytes, and kept until you delete them; a deleted file is purged within about a day. Autosaved drafts are a compressed copy of the document you have open, and are deleted automatically 30 days after you last touch them.
Your account
If you create one, we store:
- Your email address and the name you give.
- Your password as an Argon2id hash. We never store the password itself and cannot recover it.
- If you sign in with Google: the identifier Google gives us for your account, your email address, your name and your profile picture URL. We ask Google for nothing beyond that, and we do not store any Google access token.
- A profile picture, if you upload one.
- Counters for how much storage your saved files and drafts are using.
You can delete your account from your settings. Your saved files and drafts are removed with it.
A note about profile pictures
An uploaded picture is stored as you supplied it and is served to anyone who has its address. We do not currently strip embedded metadata, so if the image is a photograph straight off a phone or camera it may still carry the location and time it was taken. If that matters to you, upload a picture that has been through an editor first.
Sessions, addresses and logs
Staying signed in uses a cookie that holds a random token — not your identity, and not anything readable. Against each active session we record the IP address and browser identification string it was created from, so that a stolen session can be recognised. Those records expire 30 days after the session was issued.
To stop automated abuse we count requests against an IP address for the length of the rate-limiting window, at most about an hour, after which the record deletes itself.
Ordinary server logs record events such as a sign-in or a completed conversion, and those lines can contain an IP address, an email address or an uploaded file's name. They exist so that faults and attacks can be investigated.
Cookies and analytics
Folio sets two cookies, and only once you sign in: one holding your session token and one carrying a value that protects against cross-site request forgery. There are no advertising cookies and nothing is sold to anyone.
We use Google Analytics, loaded through Google Tag Manager, to count page views and see which tools get used. It tells us that a page was viewed; it is not given your documents, and it cannot be, because for fourteen of the eighteen tools they never leave your machine, and the ones that do upload never pass them to it.
Your theme choice, and any files you keep without an account, are stored in your own browser and never sent to us.
We send email only for account matters — confirming an address, resetting a password, and telling you when your address has been changed — and for the signature requests and share links you send: to the people you address them to, and to you as they are opened and signed. Each carries a short code and no tracking of any kind — no pixels, no remote images, no click tracking. We do not send marketing email.
Who else sees anything
Folio runs on hosting and storage providers, and uses a mail provider to deliver the account emails above. They process data on our behalf and for no purpose of their own. Beyond Google Analytics, described above, nothing is shared with third parties, and nothing is ever sold.
How long things are kept
| What | How long |
|---|---|
| Files used by the in-browser tools | Never received |
| A PDF uploaded to PDF to Word | Deleted as soon as the result is sent back |
| Files you save to your account | Until you delete them, then purged within about a day |
| A PDF sent for signature, its signed copy and its audit trail | Until you delete your account (the signed copy in your files until you delete it) |
| Autosaved drafts | 30 days after you last touch them |
| Session records, with IP and browser string | 30 days from when the session was issued |
| Codes emailed for verification or reset | 10 minutes |
| Rate-limiting counts against an IP | Up to about an hour |
| Your account | Until you delete it |
Your rights
You can see and change what is on your account, download the files you have saved, and delete the account outright, all from your settings. If you want a copy of what is held about you, or want it erased, ask and we will do it.
Children
Folio is not directed at children under 13, and we do not knowingly hold an account for one.
Changes
If this policy changes in a way that affects what happens to your documents, the date at the top changes with it.