The register
Who else touches your data.
Every third party Folio sends data to, what it is for, and its own privacy policy — the whole list, on a page you don’t need an account to read.
10 subprocessors · last reviewed September 7, 2026
Supabase (Postgres + object storage)
Always in useThe database and file storage behind every account — documents, sources, uploads and the audit log.
Vercel
Always in useApplication hosting and request logs. Every page and API request is served through Vercel.
Lemon Squeezy
Feature-dependentMerchant of record for paid plans: checkout, card processing, invoices and tax. Card details never reach Folio.
LiveKit
Feature-dependentAudio and video transport for live class and office-hours sessions, while the session is running.
Cloudflare R2
Feature-dependentStorage for session recordings, deleted after 90 days.
Deepgram
Feature-dependentSpeech-to-text for session recordings, so a class has a searchable transcript. Audio is sent for the request and not kept.
Resend
Feature-dependentDelivery of transactional email — sign-in links, invitations, grade and alert notifications.
Upstash Redis
Feature-dependentRate limiting and short-lived caches. Holds request counters, not content.
PostHog
Feature-dependentOpt-in product analytics — which features get used. No document content, and nothing at all until you consent.
Anthropic, OpenAI
Feature-dependentAI features — claim checks, summaries, drafting help. Content is sent for the request and is not used to train models.
How this list is maintained
It is generated from the same register the application itself runs on, not written by hand alongside it. A vendor appears here when Folio is configured to use it and disappears when it isn’t — which is why a service can be marked feature-dependent: it only ever sees data if you use the feature it powers, such as class recordings or transcription.
Where a vendor’s processing region is pinned by our configuration we say so. Everywhere else the honest answer is the applicable data processing agreement, so that is what it says — we don’t name a region because a vendor happens to offer one. Each row links to the vendor’s own policy, which is always the authority on what it does with what it receives.
Your rights over this data — export, deletion, and what we will never do with your writing — are in the privacy policy. Institutions can pull the same register, plus live retention and audit facts, from their own compliance page, and a DPA is available on request.
What this list is not
Nobody on this page gets your work to keep.
These are the services that make Folio run — hosting, storage, payments, email. None of them are data buyers, advertising networks, or model trainers: we do not sell your data, and your writing is not used to train anyone’s model. Analytics is off until you turn it on, and it never carries document content.
Need this in a procurement pack?
Ask us for the DPA and the processing register — we’ll send both, and answer whatever your data-protection office needs to sign off.
Contact us