Folioh · Policies
Security
A case file deserves controls that are understandable and inspectable, not just a promise of privacy.
Last updated: 4 October 2026
Encryption and access
Traffic to the service uses encryption in transit (HTTPS/TLS). Hosted data and stored files are encrypted at rest by infrastructure providers. Folioh is not end-to-end encrypted: authorized service infrastructure must process records to display and export them. Case-scoped access rules restrict records to accepted case members, and attachments are stored privately rather than as public files. Account credentials should never be shared.
Evidence integrity
At upload, the app computes a SHA-256 fingerprint for each attachment and stores it with the record. Later amendments preserve the original entry and append dated changes. Exports can include hashes, upload times, available capture metadata, and revisions. A hash helps detect a changed file; it does not independently prove origin, accuracy, or admissibility.
Subprocessors and external services
- Lovable Cloud — hosting, managed database, private file storage, and transactional email.
- Stripe — subscription and payment processing; Folioh does not store full card numbers.
- CourtListener / Free Law Project — optional in-app case-number lookup. Federal dockets and a limited set of state courts; most family matters require manual entry.
Provider infrastructure can use additional subprocessors. Ask Support@folioh.com for the current detailed list before submitting sensitive material if you need a contractual assessment.
Retention and deletion
A canceled or expired plan makes the case read-only rather than deleting it. You can delete individual attachments where the app permits. For complete case or account deletion, contact us from your registered email; we will verify ownership, address legal retention obligations, and confirm completion. Provider backups and billing records may outlast active records for operational or legal reasons. We do not promise instant removal from every backup.
Breach response
If we discover unauthorized access to case information, we will investigate scope, contain the incident, work with our providers, and notify affected users and regulators where applicable law requires. Notification will describe what we know, what we are doing, and what you can do. No universal notification deadline is promised; legal deadlines vary by jurisdiction.
Report a concern
Send suspected vulnerabilities or security incidents to Support@folioh.com. Please do not include someone else’s case data in your report.