Foli

XXM Studio LLC

Privacy Policy

Last updated September 9, 2026

Foli is provided by XXM Studio LLC. This policy explains how information is handled when you use Foli.

Information we process

  • Account data: email address, display name, salted password hash, and login sessions.
  • Language preference: browser local storage and a functional language cookie lasting up to one year, used to render the selected language from the first page view.
  • Browser preview state: source inputs, presentation settings, and displayed results live only in the current page's memory, not localStorage or sessionStorage; reloading or leaving does not automatically restore them. Server-side Notes samples still follow the retention period below. Foli Notes preview credentials use HttpOnly cookies valid for up to 24 hours. Explicitly generating a preview for the same source may reuse an eligible unexpired preview without extending its original deadline; the cookie contains no source URL, body, or settings. Legacy browser recovery records are removed on entry to the homepage or My sites.
  • Share data: submitted iCloud Shared Album links, a one-way hash and a temporary encrypted copy of an Apple Notes collaboration link during pairing, selected product, language, and public name.
  • Notes blog content: shared folder and note identifiers, titles, bodies, creation and modification times, and attachment metadata.
  • Site analytics: a one-way hash of a random anonymous visitor ID, a two-letter country or region code, and UTC visit time.
  • Photo reactions: site and photo identifiers, a one-way hash of a network identifier, reaction time, and—when signed in—the account ID.
  • Security data: hashed network identifiers used for rate limiting and essential operational logs.

Photos and metadata

Foli reads photos and videos on demand from Apple's public Shared Album service. Media files are not permanently copied into the Foli database.

To validate preview downloads and metadata requests, Photos temporarily stores the source URL and a random media-access capability for 30 minutes; maintenance jobs remove expired records. This mechanism does not persist album responses, captions, EXIF, or media files. Download proxying and metadata analysis may temporarily use memory while processing a request.

Photo details use a limited set of camera, lens, and exposure metadata. Foli does not read, return, or display GPS coordinates.

Apple Notes blogs

To create a Notes blog, you add notes@foli.cc as a participant in a shared folder. Foli Bridge reads only folders that this Apple Account has been permitted to access.

Foli stores sanitized note bodies and attachment metadata in Cloudflare D1. The Bridge converts inline images to JPEG or PNG, removes EXIF/GPS metadata, and uploads them to private Cloudflare R2 storage. PDFs and other attachments remain metadata-only.

Images follow the note's access rules: private previews and drafts do not expose public image addresses. Unpublishing stops public access; unavailable source access or preview expiry prevents access. Images are cleaned up with deleted sites and expired content; failed cleanup is retried.

New Notes previews initially read at most two eligible notes as a private sample. Saving or requesting publication starts full synchronization; partial samples are not exposed as complete sites. The synchronization wake channel stores only a change marker, not note bodies or Apple credentials.

During pairing, the complete Apple Notes collaboration URL is temporarily stored in the database using AES-256-GCM encryption for an authenticated Foli Bridge to read, with a 24-hour validity period. The encrypted copy is deleted after pairing; expired copies are removed during subsequent cleanup. Only a one-way hash is kept for long-term matching.

Site analytics

Foli provides anonymous analytics for published, persistent Photos and Notes sites: visits, unique visitors, visit date, UTC hour, and coarse country or region distribution. Repeat visits from the same visitor within the same 30-minute reporting bucket count once.

Notes analytics start after the first sync. Directory and article visits are combined at site level; article paths and per-article rankings are not stored. Only the site owner can view the report.

The browser stores a first-party HttpOnly random visitor ID for up to one year; D1 stores only its one-way hash. Site analytics do not store raw IP addresses, cities, precise locations, or full User-Agent strings.

Photo reactions and public identity

A network address can applaud each photo on a site once. Foli does not store the raw IP address; it stores a site-isolated one-way hash.

When a signed-in user applauds, their current display name appears publicly in the photo's reaction summary. Signed-out visitors are included only in the anonymous count. Deleting an account removes the display-name association and leaves that reaction as an anonymous count. Reactions remain until the related site is deleted.

RSS

Every published persistent Photos site has a public RSS feed. Anyone with the site address can subscribe and receive the album title, description, photos, videos, captions, and capture or publication times. The feed becomes unavailable when the site is unpublished or deleted. Notes blogs do not currently provide RSS.

Public sharing

Apple's Public Website and published Foli Photos and Notes sites are accessible to anyone with their address. Previews and drafts are not automatically public. Do not publish sensitive content or content you cannot lawfully share.

Saving to an account or creating a public site requires sign-in. Previously issued anonymous shares keep their original 24-hour deadline; a holder of the management credential can sign in to retain the address. Saved sites have no automatic expiry, but unpublishing, deletion, or an unavailable source affects access.

When loss of source access is detected, Foli suspends the site's public access. Detection depends on periodic checks rather than an instant Apple notification. Temporary network failures alone are not treated as revocation.

After persistent Notes source unavailability is confirmed by rechecks, synchronized content enters a private 24-hour recovery period. If access is not restored, maintenance jobs remove the content after the deadline while preserving site settings and the address. You can delete the entire site immediately instead. Public access requires source revalidation and your confirmation to resume.

Suspension cannot retract copies already saved by browsers, Apple, feed readers, or other people. Pending copies on an offline Bridge are cleared after reconnection. Failed online cleanup is retried and never reopens public access.

Providers and retention

Foli uses Cloudflare Workers, D1, and private R2 storage for computing, databases, security, and Notes images. Apple iCloud provides source content, and Resend handles account verification, password reset, and email-change messages.

Account data remains until account deletion; sessions last up to 30 days; unsaved private previews last up to 24 hours; previously issued anonymous shares retain their original deadline; visit records last 180 days; and the visitor cookie lasts up to one year. Expired previews cannot be accessed, and their stored data is subsequently removed by maintenance jobs.

After a saved site is deleted, its address is reserved for 30 days to prevent immediate takeover. Reservation records contain no note bodies or account identity. Minimal records preventing old synchronization from restoring deleted content also contain no bodies. Online deletion does not mean existing backups are erased instantly.

Your choices

  • Change your password or delete your account in account settings.
  • Unpublish or delete a site to stop new analytics collection. Deleting a site or account also deletes its visit records.
  • Deleting your account removes your display name from applause left on other sites, while retaining the anonymous count.
  • Disable Apple's Public Website to prevent Foli from continuing to read the album.
  • Revoke notes@foli.cc in Apple Notes and delete the Notes site in Foli to remove its synchronized content.
  • Send access, correction, or deletion requests to support@foli.cc.
© 2026 XXM Studio LLC
FAQPrivacyTermsContactApple Support