Privacy Policy
Last updated: 9 October 2026
What Folix AI is
Folix AI (“Folix”, this web app) is a personal AI assistant. Its owner and the people they invite sign in with a Folix account. Folix helps them chat with an AI assistant, read and act on their own email and calendar, and remembers notes they choose to save. “Folix for Chrome” is Folix's browser extension: a side panel in Chrome to chat with Folix about the page you are on.
What we collect and why
- Account: your email address and name from sign-in, to know who you are. We never see or store your password; sign-in is handled by Amazon Cognito.
- Chats: the messages you send to Folix and Folix's replies, so you can see your chat history and Folix can continue a conversation.
- Notes and memory: things you ask Folix to remember.
- Connected services: only those you connect yourself (for example Google or a YouTube channel), as described below.
- Security records: an audit log of actions taken for you (what, when), to keep the service safe.
Folix for Chrome (the browser extension)
- Page content, only when you send a message. The extension reads nothing in the background. When you send a message while the “📄 This page” chip is on (it is on by default; ✕ turns it off), press “Use this page”, or ask about the page, it reads the current tab's title, address (URL), the text you selected and the page's readable text, plus a list of its buttons and form fields (their labels, never what is typed in them). This is sent to Folix to answer that one message. The page text is not stored: only your message and Folix's reply are kept in your chat history.
- Never read: password fields, one-time codes, PINs or card fields; obvious secrets (keys, tokens, card numbers) are removed from page text before it leaves your browser and again on our server. Private (incognito) windows are never read unless you turn that on in the extension's settings and in Chrome.
- Browser tasks. If you ask Folix to do something in your browser (search a site, open a page, fill a form), it works in your current tab one step at a time and shows every step in the side panel; the Stop button ends the task at once, and a task ends after at most 30 steps. While the task runs, the tab is read again after each step (and, only during the task, the titles and addresses of the tabs in that window, and a screenshot of the visible tab when the text is not enough) and sent to Folix to choose the next step; none of it is stored. Folix never types into password, code or card fields and never presses pay, checkout or order buttons (it hands those steps back to you); anything involving money, and sending, submitting, posting or deleting, asks you first unless you asked for exactly that. Instructions written in web pages are never followed. Banking, payment and sign-in sites, Chrome's own pages and the Chrome Web Store are never read or touched. Chrome asks you before Folix may work on a new site.
- Sign-in token. The extension keeps one revocable Folix sign-in token in Chrome's extension storage on your computer. It expires after 30 days. Signing out in the extension, or “Sign out all” on the connect page, deletes it on our server.
- Settings (such as which sites you allowed automatic steps on) stay in your browser.
- No browsing history, analytics, advertising or tracking. The extension does not run on pages by itself.
Google user data
With your explicit consent through Google sign-in, Folix AI accesses Gmail (to read messages and, only after you approve each one, send email) and Google Calendar (to read events and, only after approval, create them). Google access tokens are stored encrypted.
Folix AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to provide Folix AI's features to you. It is not sold, not used for advertising, and not shared with anyone except as described below.
YouTube API Services
Folix AI uses YouTube API Services to let you connect your own YouTube channel, upload the videos you approve to it and see your channel's details and numbers. By using Folix's YouTube features you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
- What we access. Only after you press “Connect YouTube channel” on the Social page and agree on Google's consent screen, Folix asks Google for three permissions: upload videos (youtube.upload), see your YouTube account (youtube.readonly) and view YouTube Analytics reports (yt-analytics.readonly). With them Folix reads your channel's ID, name, handle, profile picture and public statistics (subscriber, video and view counts), and uploads the videos you approve (with the title, description, tags, thumbnail and schedule you approved).
- How we use it. To show you which channel is connected and how it is doing, to upload and schedule the posts you approved, and to show you whether each upload went up. Nothing is posted without your approval. YouTube data is not used for advertising, not sold and not used to train AI models.
- How we store it. Google's permission (OAuth refresh token) is kept on our server only, encrypted in our Safe Key Box, and is used only for server-side calls to YouTube; it is never shown in a page or sent to an AI model. Channel details and statistics are stored encrypted with it. They are refreshed from YouTube at least every 7 days, and if they cannot be refreshed for 30 days they are deleted. For each upload we keep the video's ID and link so you can see your post history, until you disconnect.
- Sharing. We do not share YouTube data with any third party. It is sent only to YouTube (Google) itself to perform the uploads you asked for.
- Information on your device. Folix AI stores, accesses and collects information on your device: the web app keeps your sign-in session in your browser's session storage and a few preferences (such as language and theme) in local storage. Sign-in (Amazon Cognito) and Google's consent screen may set their own cookies. Pages load fonts from Google Fonts, which receives your IP address and browser details. Folix uses no advertising or analytics cookies, and serves no third-party ads or third-party content in its YouTube features.
- Revoking access. You can remove Folix's access at any time on the Social page with “Disconnect”, or in Google's security settings at security.google.com/settings/security/permissions.
- Deletion. “Disconnect” revokes Folix's access at Google and immediately deletes the stored token, the channel's details and statistics, and the video IDs and links of its uploads. If you revoke access at Google instead, Folix notices on its next check of the channel (at least every 7 days) and deletes the same data 7 days later — always within 30 days. The videos you made in Folix and the titles you wrote stay in your Folix account; the videos on YouTube stay on your channel. Our tamper-evident security log keeps a minimal record that a channel was connected, used or disconnected (dates and IDs), which cannot be edited. To ask for deletion of any YouTube data, email support@folix.ai; we delete it within 7 days.
- Contact. Questions or complaints about privacy: support@folix.ai.
AI processing
To answer, summarise or draft, the relevant text (your message and, when you asked, the page content) is sent to AI model providers (such as OpenAI, Anthropic and Google) solely to produce that result. We do not use your data to train AI models, and Google user data is never used to train AI models.
We do not sell your data
We do not sell, rent or trade personal data, do not use it for advertising or credit decisions, and do not share it with third parties except the service providers above that are needed to run Folix, or when the law requires it.
Storage, security and retention
Data is stored on servers operated for Folix, encrypted in transit (HTTPS). Sensitive actions require your approval and are recorded in a tamper-evident audit log.
- Page content read by the extension: not stored (used for one answer; a short-lived copy may sit in memory for a few minutes).
- Chat history, notes and memory: until you delete them or ask us to delete your account.
- Extension sign-in token: 30 days at most, or until you sign out.
- YouTube channel data: refreshed at least every 7 days, deleted after 30 days without refresh, and deleted at once on disconnect (see YouTube API Services).
- Audit log: kept while your account exists, for security.
Your choices and deletion
You can sign the extension out at any time, remove it from Chrome, disconnect a YouTube channel on the Social page, and disconnect Google at security.google.com/settings/security/permissions. To get a copy of your data, to have your data or account deleted, or for any question about this policy, email support@folix.ai (or maxafmarketer@gmail.com). We answer within 30 days.
Changes
If this policy changes, the new version is posted here with a new date. Also see our Terms of Use.