Self-Hosted & Private

Privacy Policy

Last Updated: August 6, 2026

100% Data Ownership & Self-Hosted Architecture

FolioForge is engineered for complete data autonomy. When you host FolioForge, your canonical resume graph, job tailoring records, exported documents, and user sessions are stored exclusively in your dedicated PostgreSQL instance. We do not sell, track, or monetise your personal career history.

1. Information We Collect

When authenticating via Google OAuth 2.0, FolioForge requests access solely to your basic Google profile information:

  • Primary email address (`email`)
  • Display name (`name`)
  • Google account identifier (`google_id`)
  • Profile picture URL (`avatar_url`)

2. How We Use Authentication Data

Google OAuth data is used strictly for identity verification and account provisioning within your local PostgreSQL `users` table. We do not request access to Google Drive, Gmail, or any unrelated Google service scopes.

3. Session Security & Cookies

Sessions are maintained using stateful session tokens backed by PostgreSQL. Tokens are transmitted to your client browser inside secure HTTP-only cookies (`HttpOnly`, `SameSite=Lax`, `Secure`).

4. Account Deletion & Right to Erase

You maintain total control over your records. Triggering account deletion purges your user profile, Google authentication metadata, canonical resume graphs, tailored bullet variations, and hosted portfolio subdomains permanently.