Privacy policy
Last updated: 5 October 2026. In force from 5 October 2026.
The short version
Folio is self-hosted software. When you run your own Folio, your pages, accounts and files live on your servers, and Evergreen does not receive them. This policy covers the little we do hold: this website, the public demo, and the Folio connector for AI clients such as Claude and ChatGPT.
| Where | What happens to your data |
|---|---|
| Your own Folio instance | Stays on your servers. We never receive it, and we cannot read it. |
| This website | No analytics, no cookies, no forms, no ads. Our web server keeps ordinary access logs. Some images and videos load from GitHub and YouTube. |
| Public demo (demo.foliowiki.online) | Runs on our server. Shared login, shared data, reset regularly. Do not enter personal data or keys. |
| Connector (Claude, ChatGPT) | Talks to a Folio instance, normally yours. Tokens are stored on that instance. On the demo, that means our server. |
| Folio AI assistant | Uses your own Cursor key. Questions and page text go to Cursor, a third party, not to us. |
1. Who we are
Folio is a project of the Evergreen team. For the website and the public demo, the data controller is EVERGRIN ENTERPRAIZ, TOV, Creative State of Senator, BC Senator, Kniaziv Ostrozkykh str, 32/2, Kyiv 01010, Ukraine ("Evergreen", "we", "us").
You can reach us at tech@evergreens.in.ua.
2. What this policy covers
This policy covers three things we operate:
- the website at foliowiki.online;
- the public demo at demo.foliowiki.online;
- the Folio connector: the MCP server and the OAuth sign-in that let AI clients such as Claude and ChatGPT reach a Folio instance, and the listings of that connector in AI client directories.
It does not cover a Folio instance run by you or your organisation. Whoever runs an instance decides what it stores and why, and answers for it. If you use a Folio run by your employer or another organisation, ask them for their privacy notice.
Sites we link to, such as GitHub, YouTube, Anthropic, OpenAI and Cursor, have their own policies.
3. Your own Folio instance
Folio is open source (MIT licence) and runs on your infrastructure. Your pages, tables, files, accounts, tokens and Git repositories are stored there. We have no access to them and we do not receive a copy.
To our knowledge Folio does not send usage statistics or any other data to Evergreen. The assistant analytics page that Folio includes is local: it shows your own instance's data to your own administrators.
4. This website
foliowiki.online is a static site. It has no accounts, no forms, no comments and no newsletter.
What we collect
- Server access logs. Our web server (nginx) records, for each request: your IP address, the time, the page requested, the response status, the amount of data sent, the referring page and your browser's user-agent string. We use them to keep the site running and to find abuse and errors. We keep them for 14 days.
- Nothing else. We do not use analytics or tracking scripts, advertising, fingerprinting, or cookies.
What stays on your device
- If you pick a light or dark theme, your browser remembers it in local storage under the key
folio-theme. It never leaves your device, and you can delete it in your browser settings.
Content from other companies
- Screenshots on the pages load from GitHub (raw.githubusercontent.com). GitHub sees your IP address and browser details when they load.
- Video preview images load from YouTube (i.ytimg.com), which is run by Google. Google sees your IP address and browser details when they load.
- The video itself loads only when you press play, from YouTube's privacy-enhanced domain (youtube-nocookie.com). From that moment YouTube's own terms and privacy policy apply to the video.
- Links to GitHub, the author's site and other sites open those sites, which have their own policies.
5. The public demo
The demo at demo.foliowiki.online is a real Folio instance that we run so you can try it without installing anything. It holds invented data about a fictional company called Acme.
How it works, and what that means for you
- Shared login. Visitors use a shared demo account. Anything one visitor sees or changes, another visitor can see and change.
- Data is reset. We reset the demo to its starting state every 24 hours. Anything you add, including tokens and connections you create, is deleted by a reset, and may disappear sooner.
- Do not enter personal data or secrets. No real names or contact details of other people, no passwords, no API keys, no tokens for other services, no confidential business information. Assume that everything you type into the demo is public.
- Where it runs. On a server rented by Evergreen from Hetzner Online GmbH, in Germany. The data does not leave the EU unless you send it to a third party yourself (see sections 6 and 7).
What we process on the demo
- What you type or upload: pages, table rows, comments, files, and tokens you create.
- A session cookie that keeps you signed in. It is strictly necessary for the demo to work, and is not used for tracking.
- Server logs, as in section 4, including the IP address.
- Records the Folio software keeps of actions, such as who changed a page and when. On the demo, "who" is the shared account.
We use this only to run the demo, keep it secure and fix problems. We do not read demo content to profile visitors, and we do not sell or share it. Because the demo is shared and reset, it is not a place to keep anything.
6. The Folio connector: Claude, ChatGPT and other AI clients
Folio includes an MCP server (the /mcp address of a Folio instance). An AI client such as Claude or ChatGPT can connect to it, with your permission, to search and read pages and, if you allow it, to change them. Signing in uses OAuth 2.1 (with PKCE), so that you approve the connection on a consent screen of your Folio instance and never give your password to the AI client.
Where it runs
- If you connect an AI client to your own Folio instance, the connector runs there. We are not in the path. We do not run a relay or proxy between the AI client and your instance, and we do not see the traffic.
- If you connect an AI client to our demo, the connector runs on our demo server and this policy's section 5 applies as well.
What the Folio instance receives from the AI client
- The sign-in request: the AI client's name and return address, and the permissions it asks for:
read, orreadandwrite. Write permission is optional on the consent screen, and you can allow read only. - After you approve: an access token, valid for 1 hour, and a refresh token, valid for 30 days and replaced each time it is used. They are tied to your Folio account and the permissions you gave. The instance stores them only as SHA-256 hashes, never as plain text, and they work only on the
/mcpaddress of that instance, not on the rest of its interface. You can see the connection under Settings, API tokens, Connected apps, and disconnect it there at any time; the app then loses access immediately. - A record that the connection was made and ended: which app, which permissions, and when it was last used.
- Each tool call the AI client makes: for example a search query, a page identifier, or the text it wants to write. The instance answers with the page or table content you have the right to see: the connection acts with your rights only.
What the AI provider receives
- Everything the instance returns to the AI client goes to the company running it (Anthropic for Claude, OpenAI for ChatGPT) and is handled under that company's terms and privacy policy. You decide what to connect. Give an AI client only the permissions it needs, and the
readpermission if it does not have to write. - Folio sends no page content to Anthropic or OpenAI by itself. Content leaves your instance only because the AI client you connected asked for it.
What Evergreen receives
- For your own instance: nothing.
- For the demo: what section 5 lists.
- When Anthropic or OpenAI review the connector for their directories, they use a test account on our demo. They may tell us about errors or abuse they find. We use that only to fix the connector.
7. The built-in assistant (Folio AI) and other third parties
Folio has an optional assistant in a side panel. It runs on the Folio server and uses your own Cursor API key (or a key your administrator set for everyone). Each person enters their key in their account settings on their instance.
- When you ask the assistant something, your question and the page text it reads to answer go to Cursor, a third party, and are handled under Cursor's terms and privacy policy.
- We do not receive the key, the questions or the answers, unless the instance is ours (the demo).
- On the public demo the assistant is switched off: no API key is configured there, and assistant runs are blocked in demo mode.
Other third parties named in this policy: Hetzner Online GmbH (hosting of our servers, acts for us under a hosting agreement), GitHub and YouTube/Google (content on this website), Anthropic and OpenAI (AI clients you choose to connect), and Cursor (assistant). We do not sell personal data, and we do not use it for advertising.
We may disclose data if the law or a competent authority requires it, or to protect the security of our services.
8. Why we use data, and on what basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Serve the website, keep it secure, find errors and abuse | Server logs, IP address | Legitimate interests (Art. 6(1)(f)) |
| Run the demo and the connector on it | What you type, session cookie, logs, tokens | Legitimate interests (Art. 6(1)(f)); the session cookie is strictly necessary |
| Answer messages you send us | Your email address and what you write | Legitimate interests (Art. 6(1)(f)), or steps you ask for before a contract (Art. 6(1)(b)) |
| Meet legal duties | Whatever the duty requires | Legal obligation (Art. 6(1)(c)) |
Our legitimate interest is running a free, open-source project and its demo safely. If you object, see section 11.
9. How long we keep data
| Data | How long |
|---|---|
| Website access logs | 14 days |
| Demo content, tokens and connections | Until the next demo reset (every 24 hours), at the latest |
| Demo server logs | 14 days |
| Emails to tech@evergreens.in.ua | Until your question is answered, then for as long as needed to follow up and for up to 12 months, unless the law requires longer |
| Your own instance | We keep nothing. You decide. |
We do not keep backups of the website, the demo or their logs. Demo data that has been reset cannot be restored.
10. Security
Our sites use HTTPS. Access to our servers is limited to the people who run them. Access and refresh tokens in the connector are stored only as hashes and expire (after 1 hour and 30 days). No system is perfectly secure, which is one more reason not to put personal data or secrets into the demo.
If you find a vulnerability, please report it privately, as described in our security policy. If something we hold about you is affected by a breach, we will tell you and the authorities as the law requires.
11. Your rights
If the GDPR applies to you (for example, you are in the European Economic Area), you have the right to:
- ask whether we hold personal data about you, and get a copy;
- have inaccurate data corrected;
- have data deleted;
- limit how we use it;
- receive it in a portable format;
- object to processing based on our legitimate interests;
- withdraw consent, where we rely on it;
- complain to a data protection authority, in the country where you live, work, or where you think a breach happened.
Ukrainian law gives people similar rights over their personal data, and you can complain to the Ukrainian Parliament Commissioner for Human Rights. Other countries have their own rules, and we will respect the ones that apply to you.
To use a right, write to tech@evergreens.in.ua. We may ask you to prove who you are. We answer within one month, as the GDPR requires.
Because the demo has a shared login and is reset regularly, we often cannot tell which entries are yours. Tell us where to look (a page title or the time) and we will look, or just wait for the next reset.
For data in a Folio instance run by someone else, ask the operator of that instance. We cannot see it.
12. Children
Our website and demo are meant for people who work with software and documents. They are not directed at children under 16, and we do not knowingly collect data from them. If you think a child has given us personal data, write to tech@evergreens.in.ua and we will delete it.
13. Changes to this policy
We may update this policy, for example when the connector changes or when we add a feature that handles data differently. The current version is always at foliowiki.online/privacy, with its date at the top. A change takes effect when it is published on this page. We do not send separate notices, so please check the page from time to time.
14. Contact
Privacy questions and requests: tech@evergreens.in.ua. Postal address: Creative State of Senator, BC Senator, Kniaziv Ostrozkykh str, 32/2, Kyiv 01010, Ukraine. Questions about using Folio are better asked through GitHub.