Template placeholder. Replace this page with a policy reviewed for your product, providers and jurisdiction before launch.
Privacy Policy
Effective date: October 1, 2026
This Privacy Policy explains what information Folio (公卷, the "Service") at publics.nexushubs.com ("we", "us") collects, how we use it, who we share it with, and the choices you have. It should be read together with our Terms of Service.
1. Information we collect
Information you give us
- Account details: email address, optional display name and password. Passwords are stored only as a salted hash.
- Conversations: the prompts you send, the answers generated for you, conversation titles, and any feedback you give on answers.
- Uploads: files you attach (PDF, DOCX, XLSX, CSV, TXT, MD) and the text and tables we extract from them.
- Messages to us: anything you send when you contact us.
Information collected automatically
- Session and device data: for signed-in sessions, the IP address, browser user agent, and sign-in and last-seen times, so you can review and revoke your sessions.
- Usage counters: daily counts of prompts, uploads and model tokens, keyed by your account, a random guest identifier, or your IP network, to enforce quotas and prevent abuse.
- Server logs: request paths, status codes, timing and, at our web server, IP addresses, used for security and troubleshooting.
2. Cookies and local storage
We use only cookies needed to run the Service. We do not use advertising or third-party analytics cookies.
| Name | Purpose | Duration |
|---|---|---|
app_anon | Random guest identifier that keeps your temporary chats and guest quota together | 1 year |
app_session | Keeps you signed in | 30 days, or until you sign out |
app.theme, app.lang | Browser local storage for your appearance and language preferences | Until you clear them |
3. How we use information
- To provide the Service: answer your questions, search your uploads, build charts, and save and show your conversation history.
- To manage accounts: sign-in, email verification, password reset, and linking earlier guest chats to your account after you verify your email.
- To keep the Service secure and fair: rate limits, quotas, abuse prevention and investigating misuse.
- To maintain and improve the Service, including reviewing answer quality and feedback.
- To send service emails, such as verification and password reset messages. We do not send marketing email.
We do not sell your personal information, and we do not use it for advertising.
4. Service providers
To answer your questions we send relevant content to the following kinds of providers, which process it on our behalf:
- AI model providers (an OpenAI-compatible model API): your prompts, earlier turns of the conversation, and excerpts from data, documents and uploads used to answer.
- Embedding and reranking providers (an OpenAI-compatible embeddings API and, if enabled, a rerank API): search queries derived from your questions and text from files you upload, to find relevant passages.
- Web search provider (Tavily), when web search is enabled: search queries and page addresses derived from your questions.
- Email delivery: your email address and the message content for service emails.
- Hosting: the infrastructure that runs our servers, database and backups.
These providers may be located outside your country. Their handling of data is governed by their own terms and privacy policies.
5. Other disclosures
- Shared links: if you create a share link, anyone with the link can view that conversation until you revoke it.
- Administrators: a small number of our administrators can see account details, usage statistics and conversation contents for support, safety and quality purposes. Every administrator action and conversation view is recorded in an audit log.
- Legal reasons: we may disclose information if required by law, or to protect the rights, safety and security of users, the public or the Service.
- Business transfers: if the Service is transferred to another organization, information may be transferred with it under this Policy.
6. Retention
- Guest conversations and their uploads are deleted automatically, generally within 24 hours, unless you sign in and save them.
- Saved conversations and their uploads are kept until you delete them or your account is deleted.
- Sessions expire after 30 days; email verification and reset links expire after a short time and can be used once.
- Backups of the database and uploaded files are kept for up to 14 days, so deleted data may remain in backups for that period.
- Audit logs and usage counters are kept as long as needed for security, accounting and abuse prevention.
7. Security
We use HTTPS, hashed passwords and tokens, HTTP-only cookies, rate limiting and access controls to protect your information. No system is perfectly secure, so please avoid uploading highly sensitive information.
8. Your choices and rights
- Use the Service as a guest without giving us your email address.
- Rename or delete conversations, revoke share links, and view or revoke your active sessions.
- Download an export of your account data from the account settings.
- Ask us to access, correct or delete your personal information, or to delete your account, by contacting us below.
Depending on where you live, you may have further rights, such as to object to or restrict processing, to withdraw consent, or to complain to a data protection authority. We will respond to requests within the time required by applicable law.
9. Children
The Service is not intended for children under 16, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. We will post the new version on this page and update the effective date; for material changes we will take reasonable steps to notify account holders, for example by email.
11. Contact
Privacy questions or requests: publics@nexushubs.com.