Privacy

Privacy Notice

This notice explains the personal data folli.io processes when you use the website, app, Trading 212 connection, and support channels.

Last updated: 5 June 2026 · Version 2026-06-05

Controller And Contact

folli.io is the controller for personal data processed through the service unless we tell you otherwise. Not incorporated yet; No registered address is currently published.

General support and deletion requests: support@folli.io. Privacy and security: security@folli.io.

Data We Collect

  • Account data: name, email, login method, email verification, workspace membership, settings, and communications.
  • Portfolio and financial-account data: account identifiers, currency, cash, positions, instruments, transactions, dividends, reports, orders, and related metadata made available by Trading 212.
  • API connection data: API keys, connection status, scopes, provider identifiers, sync history, request metadata, and rate-limit information.
  • Technical and usage data: IP address, device/browser details, pages viewed, actions taken, session data, diagnostics, logs, and approximate location.
  • Support data: messages, feedback, attachments, and records of our communications.

How We Use Data

  • Provide the service, create accounts, authenticate users, maintain workspaces, sync portfolios, and generate analytics.
  • Secure the service, prevent abuse, diagnose errors, monitor performance, and maintain audit logs.
  • Respond to support requests and service communications.
  • Improve the product using aggregate usage and diagnostics where lawful.
  • Comply with legal obligations and handle disputes.

Lawful Bases

We rely on contract where processing is needed to provide the service, legitimate interests for operating, securing, improving, and supporting the service, legal obligation where required by law, and consent where required for non-essential cookies or marketing.

API Credentials

Trading 212 API credentials are stored only where needed for account-sync features. They are encrypted at rest and are not displayed after submission. You can disconnect inside folli.io and should also revoke keys directly with Trading 212 when you no longer want access to continue.

Sharing And Providers

We do not sell personal data. We may share data with hosting, database, authentication, email, analytics, monitoring, logging, security, payment, broker/API, professional adviser, regulator, court, law-enforcement, tax, investor, or business-transfer providers where needed.

The site uses Vercel Web Analytics. Vercel describes this analytics product as identifying visitors without relying on cookies, using a request-derived hash that resets daily.

Retention

  • Account data: for the life of the account, then deletion or anonymisation within 30 days of deletion request where possible.
  • Portfolio/API data: while connected or account active, then within 30 days after disconnection or deletion where possible.
  • API credentials: until revoked, replaced, disconnected, or the account is deleted.
  • Support messages: 3 years.
  • Billing and tax records: 6 years if paid billing is introduced.
  • Security logs: 12 months unless needed for abuse, security, legal claims, or compliance.

Your Rights

Depending on where you live and the lawful basis, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your data, and to withdraw consent. Contact security@folli.io to exercise rights.

If you are in the UK, you can complain to the Information Commissioner's Office. We would appreciate the chance to address your concern first.

Automated Outputs

The service may generate automated calculations, alerts, rankings, summaries, and assistant responses. These are informational only and do not make legally or similarly significant decisions about you.