Privacy Policy
Last Updated: August 6, 2026
100% Data Ownership & Self-Hosted Architecture
FolioForge is engineered for complete data autonomy. When you host FolioForge, your canonical resume graph, job tailoring records, exported documents, and user sessions are stored exclusively in your dedicated PostgreSQL instance. We do not sell, track, or monetise your personal career history.
1. Information We Collect
When authenticating via Google OAuth 2.0, FolioForge requests access solely to your basic Google profile information:
- Primary email address (`email`)
- Display name (`name`)
- Google account identifier (`google_id`)
- Profile picture URL (`avatar_url`)
2. How We Use Authentication Data
Google OAuth data is used strictly for identity verification and account provisioning within your local PostgreSQL `users` table. We do not request access to Google Drive, Gmail, or any unrelated Google service scopes.
3. Session Security & Cookies
Sessions are maintained using stateful session tokens backed by PostgreSQL. Tokens are transmitted to your client browser inside secure HTTP-only cookies (`HttpOnly`, `SameSite=Lax`, `Secure`).
4. Account Deletion & Right to Erase
You maintain total control over your records. Triggering account deletion purges your user profile, Google authentication metadata, canonical resume graphs, tailored bullet variations, and hosted portfolio subdomains permanently.
