Folkorama

Privacy Policy

Last updated: 2026-08-14.

Who is responsible for your data

The data controller is Folkorama, trading as Folkorama ("we", "us"), reachable at matteo@folkorama.com. This notice covers folkorama.com and every *.folkorama.com workspace we host.

What we collect

Why we process it (and on what legal basis)

Who processes data for us

Hetzner / AWSservers hosting the control plane and workspaces
CloudflareDNS and backups storage (R2)
Stripepayment processing for paid plans
Mailtrapdelivering transactional email
Let's EncryptTLS certificates

Some of these are based outside the EU. Transfers are covered by an adequacy decision (EU-US Data Privacy Framework) or Standard Contractual Clauses; each provider's current terms apply. We have a data processing agreement in place with each of them.

Cookies and tracking

We set no tracking or analytics cookies and run no ads. The dashboard keeps your session as an authentication token in your browser's local storage - strictly necessary to operate the service, and never shared with anyone.

How long we keep it

Your rights

You can request access, rectification, erasure, portability, restriction or objection at any time by emailing matteo@folkorama.com. Portability is also self-service: a lore clone is a complete copy of a repository. If you believe we handled your data unlawfully, you can complain to your local data protection authority (for us: the authority of Italy ).

Security

Passwords and API keys are stored hashed, all traffic is TLS-encrypted, secrets are sealed at rest, and each workspace's data lives on its own isolated disk volume with a hard capacity cap. No method is perfect; if a breach risks your rights we will tell you and the authority as the law requires.

Changes

We may update this policy; the current version is always at folkorama.com/privacy.html. For material changes we will email the address on your account before they take effect.