Folloop

Privacy Policy

Last updated: 10 September 2026 · Effective: 1 September 2025

Folloop ("Folloop", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our budgeting application and related services (collectively, the "Service"). Please read it carefully. By using the Service you agree to the practices described here.

1. Who We Are

Folloop is operated by Epront Media Limited, from Ireland, within the European Union. For users in the European Economic Area and the United Kingdom, Epront Media Limited is the data controller of your personal data under the General Data Protection Regulation (GDPR) and the UK GDPR, and our lead supervisory authority is the Irish Data Protection Commission. You can reach us at privacy@folloop.app about anything in this policy.

Contact: privacy@folloop.app

2. Data We Collect

  • Account data: email address, display name, and (if you use a third-party sign-in) your OAuth identifier from Google.
  • Financial data: envelope names, budget amounts, transaction descriptions, merchants, and amounts you enter manually. We never request or store your bank credentials, card numbers, or account balances. Folloop has no bank connection: everything it holds, you entered or imported yourself.
  • Receipt photos: if you attach or scan a receipt, the photo is stored with the transaction it belongs to. If you use Scan Receipt, the photo is also sent to Anthropic to read the merchant, amount and date. We count how many scans each account makes in a month, to apply the monthly limit — who scanned and when, and nothing else.
  • Device and usage data: our hosting providers keep ordinary server logs, including IP address and browser type, for security and reliability. Folloop itself runs no analytics: there is no tracking script, no product analytics service, and no record of which pages you visit or what you tap.
  • Storage on your device: what keeps you signed in, plus your theme and hub preferences and a cached copy of your own data so the app opens quickly. See Section 7.

3. How We Use Your Data

  • Providing and maintaining the Service.
  • Authenticating your identity and keeping your account secure.
  • Sending transactional emails (e.g. email confirmation, password reset).
  • Complying with legal obligations.

We do not sell your personal data to third parties. We do not use your financial data for advertising purposes.

4. Legal Bases (GDPR)

For users in the EEA/UK, we process personal data on the following legal bases:

  • Contract (Art. 6(1)(b)): to provide the Service you signed up for.
  • Legitimate interests (Art. 6(1)(f)): security monitoring, fraud prevention, and service improvement.
  • Consent (Art. 6(1)(a)): optional marketing communications — you can withdraw at any time.
  • Legal obligation (Art. 6(1)(c)): when required by applicable law.

5. Sharing Your Data

We share data only with:

  • Supabase, Inc. — our database and authentication infrastructure provider, acting as a data processor.
  • Vercel, Inc. — our hosting provider.
  • Google LLC — if you use Google Sign-In.
  • Anthropic, PBC — reads the receipt photos you choose to scan. A photo is sent only when you use Scan Receipt.
  • GitHub, Inc. — keeps our nightly database backups for 90 days. Each backup is encrypted before it is stored, with a key GitHub does not have, so it cannot read them.
  • Functional Software, Inc. (Sentry) — error reporting, hosted in the EU. When the app hits an error, a report of what failed is sent so we can fix it: the error, the page it happened on, and the browser and device type. It does not include your transactions, budgets, name or email, and sign-in tokens are removed from it.
  • Law enforcement or regulators when required by a valid legal process.

All processors have signed Data Processing Agreements and maintain appropriate technical and organisational security measures.

6. Data Retention

We retain your account data for as long as your account is active. You may delete your account at any time from Settings → Delete account, which removes your profile, your hub memberships, and any hub where you are the only member, immediately and permanently. There is no analytics store to retain anything in.

7. Cookies and local storage

Folloop sets no tracking or advertising cookies, and there is nothing to consent to. What it does keep on your device is what it needs to work: the token that keeps you signed in, your theme and hub preferences, and a cached copy of your own budget so the app opens without waiting. All of it stays in your browser and none of it is sent anywhere. Clearing your browser data for this site removes the lot and signs you out.

8. International Transfers

Your data may be transferred to and processed in the United States. For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or on an adequacy decision where applicable.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to processing.
  • Data portability — receive your data in a machine-readable format.
  • Lodge a complaint with a supervisory authority. Ours is the Irish Data Protection Commission (dataprotection.ie), and you may also complain to the Data Protection Authority where you live, or to the ICO in the UK.
  • California residents (CCPA/CPRA): right to know, delete, correct, and opt out of sale of personal information. We do not sell personal information.

To exercise any right, email privacy@folloop.app. We will respond within 30 days.

10. Security

We use TLS encryption in transit, encryption at rest, and row-level access controls enforced inside the database rather than by the app. Folloop itself has not been independently audited; the hosting providers we build on — Supabase and Vercel — publish their own certifications, which are theirs rather than ours. No system is completely secure, so we encourage you to use a strong, unique password.

11. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via an in-app notice at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact

Folloop
privacy@folloop.app