Folivue
Privacy policy
What we collect, why we collect it, who else sees it, and what you can make us do about it.
Last updated 3 August 2026
Who is responsible
Folivue is operated by Age Otori Pte. Ltd. (UEN 201811354W), a company incorporated in Singapore, at 160 Robinson Road, #14-04 Singapore Business Federation Center, Singapore 068914 (“we”, “us”). This policy explains how we handle personal data under Singapore’s Personal Data Protection Act 2012 (the PDPA).
The PDPA requires us to designate a Data Protection Officer and to publish their business contact information. Ours is the company’s founder, reachable at hello@folivue.com. Write to them about anything on this page.
What we collect
If you sign in
Signing in to Folivue is done entirely through Google — there is no Folivue password, and we never see or store one. When you sign in, we store:
- Your Google profile basics: your name, your email address, whether Google reports that address as verified, and the URL of your Google profile picture.
- The link to your Google account: the account identifier Google gives us, the OAuth tokens that keep the connection working (access, refresh and ID tokens, and their expiry), and the scopes you granted.
- Sessions: for each sign-in, a session token and its expiry, plus the IP address and browser user-agent string the sign-in came from, and the times the session was created and last updated. We use the count and timing of these rows to understand how many people come back.
What you put into Folivue
- Your lists: the name you give each watchlist or portfolio, whether it is a watchlist or a portfolio, the display currency you chose for a portfolio, and the order they appear in.
- The symbols in your watchlists and when each was added.
- Your portfolio transactions: for each one, the symbol, whether it was a buy or a sell, the number of shares, the price (which you may leave blank), the currency that price was quoted in, any fees you entered, the execution date you gave it, and when you saved it.
This is your financial information and we treat it as sensitive. It is never sold, never used for advertising, and never shared with another user.
If you joined the mailing list before launch
Folivue kept a pre-launch signup list, and those records still exist. For each signup we hold the email address, whether marketing consent was given and when, the form or page it came from, the IP address and user-agent of the request, first-touch attribution (the referring site, any campaign tags in the link, and the page landed on), and the record of any unsubscribe. Where a signup later became an account, the two are linked. Some of these records were imported from an earlier email tool, Kit, and carry that tool’s subscriber identifier.
We also record when a welcome email was sent and when a record was last synchronised to our email provider, so that nobody is emailed twice and nobody is missed.
What we do not collect
- No payment details. Folivue takes no payments and has no card data.
- No passwords.Authentication is Google’s.
- No brokerage credentials or account connections. Portfolios are typed in by hand. Folivue cannot see, and never asks for, access to a real brokerage account.
- No advertising or analytics trackers. This application loads no analytics script, no advertising pixel and no third-party tag manager.
Cookies and local storage
Folivue sets three kinds of cookie, all of them necessary to run the site:
- The session cookie (
better-auth.session_token) keeps you signed in. It ishttpOnly, so page scripts cannot read it. - Short-lived sign-in cookies written during the round trip to Google, to protect the sign-in against cross-site request forgery.
- Two display hints that let a page paint correctly before the server has confirmed who you are.
fv_authrecords only that a session cookie is present (its value is the literal1);fv_listsrecords which layout your “Your lists” panel used last, so the placeholder reserves the right height. Neither identifies you, neither grants any access, and both are deleted when you sign out.
Your recent searches are kept in your browser’s local storage, on your device only. They are never sent to us and we have no copy of them. Clearing your browser’s site data removes them.
One thing worth being plain about: a page can make your browser fetch things from servers that are not ours, and you cannot see that happen. Folivue does it in exactly two places, and neither of them tells the recipient who you are.
- News thumbnails — on any page showing news, signed in or not. The small article images are not copied onto our servers; your browser fetches each one directly from the news source’s own image servers (today, Yahoo’s). That request reveals your IP address, your user-agent, and — because the referrer is not suppressed here — the address of the Folivue page you were reading. It carries no account, no name and no cookie of ours.
- Your profile picture — only if you are signed in. It is loaded straight from Google’s servers by your browser, with the referrer suppressed, so Google sees your IP address and user-agent but not which Folivue page you were on.
Typefaces are not a third one. Folivue serves its typeface from its own origin, so no page load fetches a font from Google’s font servers (fonts.googleapis.com, fonts.gstatic.com) or from anyone else. A signed-out visitor makes no request to Google at all until they choose to sign in. What each recipient above does with what it sees is governed by its own terms, not by this policy.
Why we collect it
Under the PDPA we may only collect, use and disclose personal data for purposes a reasonable person would consider appropriate, and only for purposes we have told you about. Ours are:
- To sign you in and keep you signed in. Google profile data, tokens and sessions.
- To provide the service. Storing your lists, symbols and transactions, and computing the figures shown from them.
- To keep the service secure and working. Session records (including IP address and user-agent) help us detect abuse and diagnose faults.
- To understand how Folivue is used.We keep an internal dashboard of signups: how many people joined, where they came from, how many came back, and — per person — how many lists, symbols and transactions they have. It shows those counts and never their contents. Nobody at Folivue browses what you hold.
- To email you about Folivue, but only if you asked us to. See below.
- To meet our legal obligations where the law requires it.
We do not use your data for any other purpose without telling you and, where the PDPA requires it, obtaining your consent.
Consent, and withdrawing it
By creating an account and using Folivue you consent to us handling your data for the purposes listed above, which are the purposes needed to give you the service you asked for.
Marketing is separate and opt-in. Signing in with Google is not consent to be emailed. Our records carry a distinct marketing-consent flag, defaulted to off, which is only set when someone takes an explicit affirmative action to opt in, together with the time and source of that action. Every marketing email carries an unsubscribe link, and we keep our own suppression list so an opt-out survives a change of email provider.
You may withdraw consent for any purpose at any time by writing to hello@folivue.com. We will tell you what withdrawing it means before we act — for most purposes here, withdrawal means we can no longer provide the account, because the data is the service.
Who else gets it
We do not sell personal data. We share it only with the following, and only as needed:
- Google LLC— identity. Sign-in happens on Google’s systems; Google tells us who you are and knows that you signed in to Folivue. Google’s handling of your Google account is governed by Google’s own privacy policy, not this one. Google also serves the profile pictures described above.
- Our hosting provider, Vercel Inc.— runs the application and therefore processes requests, including IP addresses, in its own infrastructure and logs.
- Our database provider, Supabase— stores everything in the “What we collect” section above.
- Our email provider, Resend— receives the email addresses of people who joined the mailing list, in order to send the emails they asked for.
- Anyone we are legally required to disclose to— a court order, a regulator, or a lawful request from a public agency.
- A buyer or successor, if the business or its assets are ever transferred. We would tell you before your data moved.
The market-data provider is deliberately not on that list. Requests for quotes, charts and news are made by our servers, not by your browser, and we send the provider only the symbols being looked up — never your identity, your account, or the fact that a particular symbol belongs to a particular person’s list. The one exception is the news thumbnails described above: those images stay on the news source’s servers and your browser fetches them itself, so it sees your IP address and the page you were on, and nothing else about you.
Data leaving Singapore
Our providers operate globally, so your personal data is stored and processed outside Singapore — currently in the United States for both the database (Supabase, in AWS’s us-east-1 region) and the application (Vercel), with Google processing sign-ins in its own global infrastructure.
Section 26 of the PDPA and the Personal Data Protection Regulations allow us to transfer personal data overseas only if we have taken appropriate steps to ensure the recipient is bound by legally enforceable obligations to protect it to a standard comparable to the PDPA. In practice that means the transfer must be covered by contract terms binding each provider to that standard, or by another basis the Regulations permit. We state this as an obligation we are subject to, not as a formality: it has to be satisfied for each provider named above.
How long we keep it
The PDPA requires us to stop keeping personal data once it no longer serves the purpose it was collected for and there is no legal reason to retain it. Today:
- Your account, lists and transactions are kept for as long as your account exists.
- Sessions carry their own expiry and stop being valid at it.
- Anything you delete in the app is deleted for real.Deleting a list removes its rows from the database along with its symbols and transactions; the “undo” that appears afterwards is held in your browser for that moment only, and nothing keeps a second server-side copy. Deleting a transaction removes that row.
- Unsubscribe records are kept deliberately. If you opt out of email we keep enough of a record to make sure you stay opted out.
- After account closure, nothing is kept on purpose.There is no self-service closure today, so closing an account is something we do by hand — and closing it and deleting its data are the same act. When we process your request, the account and everything under it are deleted then and there. Copies can persist for a limited period in our providers’ routine backups until those expire on the providers’ own schedules.
Access, correction and deletion
Under the PDPA you may ask us:
- for access— what personal data of yours we hold, and how it has been used or disclosed in the past year;
- for correction— to fix anything inaccurate or incomplete, and to pass the correction on to anyone we sent it to;
- to withdraw consent, as described above.
Write to hello@folivue.com. We will respond as soon as we reasonably can and, where the PDPA sets a deadline, within it. We may need to confirm your identity first, and there are narrow cases where the law allows or requires us to refuse — if we do, we will say why.
Much of your data you can change yourself, immediately: rename or delete a list, remove a symbol, edit or delete any transaction. There is currently no self-service “delete my account” button— to close an account and have its data removed, email hello@folivue.com and we will do it.
Security
The site is served over HTTPS. The session cookie is httpOnly, so page scripts cannot read it. We hold no passwords at all, because sign-in is Google’s, so there is no password of ours to leak. Data is stored with the providers named above and is subject to their security controls as well as our own.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please tell us at hello@folivue.com before disclosing it publicly.
Children
Folivue is not intended for children. You must be at least 18 years old to create an account — see the Terms. If we learn that we hold the personal data of someone below that age without appropriate consent, we will delete it.
Changes
If we change this policy we will post the new version here and update the date at the top. If the change materially affects how we handle data you have already given us, we will tell you before it takes effect.
Complaints
Raise anything with hello@folivue.com first — we would rather hear it. If you are not satisfied with how we have handled a complaint, you may refer it to the Personal Data Protection Commission of Singapore.