Last updated: 2026-08-14.
Who is responsible for your data
The data controller is Folkorama, trading as Folkorama
("we", "us"), reachable at matteo@folkorama.com.
This notice covers folkorama.com and every *.folkorama.com workspace we host.
What we collect
- Account data - your email address and a hash of your password. API keys you create are stored only as hashes.
- Workspace content - the repositories, code and binary assets you push to your workspaces. We host it; we don't read it.
- Usage & metering data - per-workspace disk, memory, CPU and traffic readings, used to enforce plan limits and show you usage.
- Technical logs - IP addresses, timestamps and user-agent strings in our proxy and server logs, kept for security and debugging.
- Billing data - if you buy a paid plan, payment details are entered into and stored by Stripe; we only see the last four digits and your billing status.
Why we process it (and on what legal basis)
- Running the service - accounts, workspaces, metering, support. Basis: performance of the contract (Art. 6(1)(b) GDPR).
- Security and abuse prevention - logs, rate limiting, incident response. Basis: legitimate interest (Art. 6(1)(f)).
- Invoicing and tax records. Basis: legal obligation (Art. 6(1)(c)).
- Service emails - sign-up verification, password resets, billing and security notices. Basis: contract / legitimate interest. We do not send marketing email.
Who processes data for us
| Hetzner / AWS | servers hosting the control plane and workspaces |
| Cloudflare | DNS and backups storage (R2) |
| Stripe | payment processing for paid plans |
| Mailtrap | delivering transactional email |
| Let's Encrypt | TLS certificates |
Some of these are based outside the EU. Transfers are covered by an adequacy decision (EU-US Data Privacy Framework) or Standard Contractual Clauses; each provider's current terms apply. We have a data processing agreement in place with each of them.
Cookies and tracking
We set no tracking or analytics cookies and run no ads. The dashboard keeps your session as an authentication token in your browser's local storage - strictly necessary to operate the service, and never shared with anyone.
How long we keep it
- Account and workspace data: until you delete them. Deleting a workspace destroys its disk volume.
- Encrypted backups of the control plane roll off after about a week, so deleted data disappears from backups within that window.
- Usage metering samples: 30 days.
- Security logs: a few weeks at most, then rotated away.
- Invoice and tax records: as long as the law requires.
Your rights
You can request access, rectification, erasure, portability, restriction or
objection at any time by emailing
matteo@folkorama.com. Portability is also
self-service: a lore clone is a complete copy of a repository. If you believe
we handled your data unlawfully, you can complain to your local data protection
authority (for us: the authority of Italy ).
Security
Passwords and API keys are stored hashed, all traffic is TLS-encrypted, secrets are sealed at rest, and each workspace's data lives on its own isolated disk volume with a hard capacity cap. No method is perfect; if a breach risks your rights we will tell you and the authority as the law requires.
Changes
We may update this policy; the current version is always at folkorama.com/privacy.html. For material changes we will email the address on your account before they take effect.