Foliome ("we", "us", "the service") is a personal portfolio tracker available as a Telegram Mini App and a standalone web app. This policy explains what we collect, why, where it lives, and the rights you have over it.
What we collect
- Account identifiers. When you sign in via Google or email/password, we receive your email address and (for Google) your account ID. When you use Foliome through Telegram, we receive your Telegram user ID and the public profile fields Telegram exposes (first name, username, language code).
- Portfolio data. The assets you add, the purchase records you log, your watchlist, and the alert thresholds you set.
- Derived data. Daily portfolio snapshots and price history we compute for your charts.
- Operational logs. Standard request logs (timestamp, route, status code) generated by our hosting provider for debugging and abuse prevention. These expire on a short cycle.
We do not collect financial account credentials. Foliome does not connect to banks or brokerages — you enter assets manually.
How we use it
- To run the product — show your portfolio, charts, alerts.
- To deliver the price-alert messages you configure (via the Telegram bot).
- To enforce plan limits and prevent abuse.
- To debug errors and improve performance.
We do not sell your data. We do not use your portfolio for ad targeting. We do not share it with third parties for marketing.
Where it's stored
Your data is stored in Supabase (PostgreSQL with row-level security). Row-level security means that at the database layer, each row is tagged with your user ID and queries are restricted to your own data — even an authenticated user can't read another user's portfolio.
The app and its backend are hosted on Vercel. Background jobs (price refresh, daily snapshots, alert delivery) run on a dedicated VPS.
Third-party services
Foliome uses these services to deliver the product. Each one receives only what's necessary for its function.
- Supabase — database, authentication, row-level security.
- Vercel — application hosting and serverless functions.
- Telegram — Mini App surface and bot delivery.
- Google — OAuth sign-in (only if you choose Google).
- Stripe — payment processing for Pro subscriptions on the web app. Stripe receives your email and payment method directly; Foliome never sees your card details. Only used if you upgrade to Pro on web.
- Telegram Stars — payment for Pro subscriptions inside the Telegram Mini App. Telegram handles the transaction; Foliome receives a confirmation tied to your Telegram user ID. Only used if you upgrade to Pro inside Telegram.
- Price providers — CoinGecko (crypto), Yahoo Finance (stocks, ETFs, metals), Frankfurter (FX), GoldAPI (metals fallback). These receive ticker symbols only — never your account or portfolio data.
Cookies and sessions
The web app stores a session token in your browser so you stay signed in. We do not use third-party analytics cookies, advertising cookies, or tracking pixels.
Your rights
- Access and export. You can see all your data inside the app. CSV export is part of the Pro plan.
- Delete. Settings → Delete account removes your auth identity (locking all logins immediately) and cascades through every related row: assets, purchases, alerts, snapshots, watchlist.
- Correct. Edit any asset or purchase record from inside the app.
Depending on where you live, you may have additional rights under laws like the GDPR or CCPA. Contact us to exercise them.
Telegram-specific notes
When you use Foliome inside Telegram, Telegram itself transmits the information needed to identify you securely (initData payload, verified by HMAC on our server). That payload is not stored — only the user ID and the public profile fields are kept.
Price alerts are delivered as bot messages. By setting up an alert you authorize the bot to message you when the threshold is hit.
Children
Foliome is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
If we make material changes, we will update the "Last updated" date at the top of this page and, when appropriate, surface the change inside the app.
Contact
Questions about this policy? Reach us at hello@foliome.me .