Trust & security

The register

Who else touches your data.

Every third party Folio sends data to, what it is for, and its own privacy policy — the whole list, on a page you don’t need an account to read.

10 subprocessors · last reviewed September 7, 2026

Supabase (Postgres + object storage)

Always in use

The database and file storage behind every account — documents, sources, uploads and the audit log.

supabase.com privacy policy Location per the applicable data processing agreement

Vercel

Always in use

Application hosting and request logs. Every page and API request is served through Vercel.

vercel.com privacy policy Location per the applicable data processing agreement

Lemon Squeezy

Feature-dependent

Merchant of record for paid plans: checkout, card processing, invoices and tax. Card details never reach Folio.

lemonsqueezy.com privacy policy Location per the applicable data processing agreement

LiveKit

Feature-dependent

Audio and video transport for live class and office-hours sessions, while the session is running.

livekit.io privacy policy Location per the applicable data processing agreement

Cloudflare R2

Feature-dependent

Storage for session recordings, deleted after 90 days.

Deepgram

Feature-dependent

Speech-to-text for session recordings, so a class has a searchable transcript. Audio is sent for the request and not kept.

deepgram.com privacy policy Location per the applicable data processing agreement

Resend

Feature-dependent

Delivery of transactional email — sign-in links, invitations, grade and alert notifications.

resend.com privacy policy Location per the applicable data processing agreement

Upstash Redis

Feature-dependent

Rate limiting and short-lived caches. Holds request counters, not content.

upstash.com privacy policy Location per the applicable data processing agreement

PostHog

Feature-dependent

Opt-in product analytics — which features get used. No document content, and nothing at all until you consent.

posthog.com privacy policy Location per the applicable data processing agreement

Anthropic, OpenAI

Feature-dependent

AI features — claim checks, summaries, drafting help. Content is sent for the request and is not used to train models.

anthropic.com privacy policy Location per the applicable data processing agreement

How this list is maintained

It is generated from the same register the application itself runs on, not written by hand alongside it. A vendor appears here when Folio is configured to use it and disappears when it isn’t — which is why a service can be marked feature-dependent: it only ever sees data if you use the feature it powers, such as class recordings or transcription.

Where a vendor’s processing region is pinned by our configuration we say so. Everywhere else the honest answer is the applicable data processing agreement, so that is what it says — we don’t name a region because a vendor happens to offer one. Each row links to the vendor’s own policy, which is always the authority on what it does with what it receives.

Your rights over this data — export, deletion, and what we will never do with your writing — are in the privacy policy. Institutions can pull the same register, plus live retention and audit facts, from their own compliance page, and a DPA is available on request.

What this list is not

Nobody on this page gets your work to keep.

These are the services that make Folio run — hosting, storage, payments, email. None of them are data buyers, advertising networks, or model trainers: we do not sell your data, and your writing is not used to train anyone’s model. Analytics is off until you turn it on, and it never carries document content.

Need this in a procurement pack?

Ask us for the DPA and the processing register — we’ll send both, and answer whatever your data-protection office needs to sign off.

Contact us