Foliohouse Privacy Policy
1. Who we are, and what this covers
Foliohouse ("Foliohouse," "we," "us," "our") is a relationship-memory tool built for relationship-dependent sales professionals — real estate agents, insurance agents, and direct sales / MLM professionals — who need to capture, retain, and act on the details of their client conversations.
Foliohouse is operated by Deeply Fundamental Labs Pte. Ltd., a private limited company registered in Singapore (UEN 202631191C) ("Deeply Fundamental," "the Company").
Contact: privacy@foliohouse.app for all privacy-related questions, rights requests, regulatory inquiries, or concerns about how your data — or your clients' data — is handled. A postal correspondence address is available on request to verified rights-requesters and regulatory authorities; please reach us by email first so we can coordinate.
This policy covers the Foliohouse web application, the Foliohouse backend service, and the foliohouse.app website. It applies to every Operator who creates a Foliohouse account, and to how Client Conversation Data captured through that account is handled, regardless of where the Operator or their clients are located.
2. Two kinds of data this policy covers
Foliohouse sits between two different people, and this policy treats their data differently. We name the distinction here, early, because it governs almost everything that follows.
Operator Account Data — the account information of the paying professional who signs up for Foliohouse (the "Operator"): name, email address, phone number, and, in the future, once billing exists, payment details. The Operator controls this data directly, and Foliohouse is the data controller for it under Singapore's Personal Data Protection Act (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).
Client Conversation Data — content captured about, or with, an Operator's own clients: the people the Operator serves professionally, who never create a Foliohouse account of their own. This includes WhatsApp messages an Operator forwards, voice and text debrief recordings an Operator makes about a client interaction, and content synced through Coexistence sync.
For Client Conversation Data, Foliohouse acts only as a processor, on the Operator's behalf. The Operator is the data controller of their own client relationships, and is responsible for their own legal basis for capturing and processing that data (see Section 4 of our Terms of Service). This distinction matters most when it comes to rights requests — see Section 9 below.
3. Information we collect
Account data. Name, email address, and phone number provided at sign-up; in the future, billing information, if paid plans are introduced.
WhatsApp-forwarded content. Message text (and, where applicable, media) that an Operator manually forwards to Foliohouse. This content reaches us only because the Operator forwards it themselves — see Section 5.
Voice and text debriefs. Recordings or written notes an Operator creates about a client interaction, along with any transcript generated from them.
Coexistence sync content. Conversation data synced through the Coexistence sync channel, on a less frequent, "close" tempo rather than an immediate one.
Structured extractions. From the content above, our processing pipeline (Section 7) derives structured signals — facts, summaries, and other extracted detail — for the Operator's own use.
Client-facing room content. Where an Operator chooses to publish a clearance-filtered subset of the above into a shared "room," that subset is rendered for the named client to view.
We do not collect any of this information from your clients directly, and your clients never interact with Foliohouse as account holders of their own.
4. How we use it, and on what basis
We use Operator Account Data to create and administer your account, operate the Foliohouse service, and communicate with you about your account.
We use Client Conversation Data solely to provide the service to the Operator who captured it: storing it as fidelity, extracting structured signals from it, and rendering the clearance-filtered subsets the Operator chooses to share.
Legal basis (Singapore PDPA / GDPR, where applicable): processing is carried out under the Operator's consent and for the performance of our contract with the Operator (our Terms of Service), and, for the aggregate product-improvement use described in Section 11 of our Terms of Service, under our legitimate interest in improving the service.
5. WhatsApp forwarding — how content actually reaches us
Foliohouse's WhatsApp capture channel works by manual forwarding: an Operator forwards a message they have already received, from their own WhatsApp, to Foliohouse. This is not an API integration with WhatsApp or Meta. Meta Platforms, Inc. and WhatsApp never transmit data to Foliohouse, never receive data from Foliohouse, and are not a subprocessor of ours in any capacity (see Section 8). The forwarded content reaches us the same way any message forward reaches any recipient — because the Operator chose to send it.
6. Fidelity storage: append-only by design
Once conversation content is captured, Foliohouse stores it as "fidelity" — a verbatim, append-only record that is never edited after the fact. This is a deliberate design choice, not an oversight: it exists so the record an Operator (and, eventually, a client) relies on cannot be silently altered, which we treat as a matter of integrity and auditability.
One consequence of this design: while an account remains open, individual fidelity entries cannot be edited, corrected, or selectively deleted on request. The record stands in full, as captured, for as long as the account remains open; the way to remove a given piece of content is to close the account, at which point the entire fidelity store is deleted (see Section 9). We disclose this plainly because it differs from how many products handle individual data-correction requests, and we want you to know it going in.
7. AI-based processing (Anthropic)
Foliohouse uses the Anthropic API (Claude models) to extract structured signals from captured conversation content — this is the "processing pipeline" referenced in Section 3.
Anthropic does not train its models on the content we send through the API. As of this policy's publication, Anthropic's standard commercial API terms retain inputs and outputs for no more than 30 days before automatic deletion, absent a separate arrangement. This is Anthropic's standard commercial retention period as of this policy's publication; if Deeply Fundamental enters a zero-data-retention agreement with Anthropic, this section will be updated to reflect that arrangement.
8. Who we share data with (subprocessors)
We use a small, fixed set of subprocessors to operate Foliohouse. As of this policy's publication, the complete list is:
| Vendor | Purpose |
|---|---|
| Supabase | Database and file storage |
| Vercel | Application hosting |
| Anthropic | AI-based extraction and processing (Section 7) |
We do not share Client Conversation Data or Operator Account Data with any party outside this list. In particular: Meta Platforms, Inc. and WhatsApp are not a subprocessor of Foliohouse's, in any respect. WhatsApp never receives, transmits, or has access to any Foliohouse data — see Section 5.
9. Deletion and retention
Account-level deletion. An Operator may request deletion of their entire Foliohouse account — including all Client Conversation Data captured within it — at any time, by emailing privacy@foliohouse.app. This is currently a manual process, fulfilled directly by our team; self-serve deletion inside the product is planned but not yet available. We honor verified deletion requests within 60 days of receipt.
Requests from clients directly. Because clients do not hold their own Foliohouse accounts, a client who wants their data removed from an Operator's fidelity store should generally raise that request with their Operator first, since the Operator controls that relationship and is its data controller. That said, if a client contacts us directly, we will honor a verified request within the same 60-day window — a direct client request is not a dead end.
Retention while active. Fidelity is retained for as long as the Operator's account remains open, consistent with Section 6.
10. Site analytics and tracking
As of this policy's publication, foliohouse.app uses no cookies and no tracking or analytics of any kind.
We plan to introduce privacy-respecting analytics in the future: cookieless site analytics (such as Plausible, which collects no personal data and sets no cookies), and, once an in-product dashboard exists, product usage telemetry run in a privacy-preserving configuration. We commit to updating this policy with full specifics — what is collected, how, and why — before any such tracking begins.
11. Your rights
Singapore PDPA. If you are located in Singapore, you may request access to, and correction of, your personal data, withdraw consent to its processing (subject to legal or contractual restrictions), and lodge a complaint with the Personal Data Protection Commission (PDPC) if you believe we have not handled your data appropriately.
GDPR (EU-based visitors and users). If you are located in the EU, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data.
- Restrict our processing of it.
- Object to specific processing.
- Receive your data in a portable format.
- Lodge a complaint with your national supervisory authority.
Because Operator Account Data and Client Conversation Data are controlled differently (Section 2), the practical path for exercising these rights differs too: Operators may exercise rights over their own account data directly by contacting us; clients whose conversations are captured within an Operator's fidelity store should generally start with their Operator, per Section 9, though we will honor a verified direct request within 60 days regardless.
Note on fidelity: because captured fidelity is append-only while an account is active (Section 6), a rectification request for an individual entry generally cannot be fulfilled by editing that entry — it is fulfilled at the account level as described in Section 9.
Rights requests are directed to privacy@foliohouse.app.
12. Eligibility
Foliohouse is a business tool for professional use. You must be at least 18 years old and authorized to act on behalf of your business to create an Operator account.
13. Changes to this policy
When we make a material change to this policy — a new subprocessor, a new category of data collected, a change to retention, or a change to your rights — we will revise the Last revised date above and take reasonable steps to notify active Operators.
14. Contact
Email privacy@foliohouse.app for any privacy question, rights request, or concern — whether you are an Operator, a client whose conversation was captured, or a regulator.