Privacy Policy
What Folio32 is
Folio32 ("we", "us") is a private, self-reported requirement tracker for dental students and residents, available at folio32.com. This policy describes what information the service handles and how.
Information you give us
- Account details — your name, email address, and password. Passwords are stored only as a modern cryptographic hash (argon2id); we cannot read them.
- Your clinical log — the procedures, CDT codes, targets, fees, notes, and the names of attendings and clinics that you enter. Patients are represented only by a private case code and initials that you choose.
- Feedback — anything you send through the in-app feedback button, including an optional screenshot.
Information we deliberately do not collect
Folio32 has no field for a patient's name, date of birth, address, or chart number, and the trade board publishes procedures — never patients. Do not enter protected health information (PHI) anywhere in Folio32, including in free-text notes. The service is designed so that no PHI ever enters the system.
Information collected automatically
- One session cookie, used only to keep you signed in. There are no advertising or third-party analytics cookies.
- Security logs — sign-ins and similar account events are recorded with your IP address to protect your account.
How we use your information
- To run the service: show your progress, compute what's available to trade, and back up your data.
- To email you when needed — password resets and replies to your feedback. No marketing lists.
- To keep the service safe: rate limiting, abuse prevention, and debugging.
We do not sell or rent your information, and we do not show ads.
When information is visible to others
- Trade board — if you post a case for trade, classmates on your school's board see the procedure, the CDT code, and your display name. Never a patient.
- Service providers — we host on Amazon Web Services (United States) and send transactional email through Resend. Each receives only what's necessary to provide its service.
- Legal requirements — we may disclose information if required by law.
Security
All traffic is encrypted in transit (HTTPS). Every record is isolated per user at the database level (row-level security), and backups are encrypted. No system is perfectly secure, but the most sensitive category of data — patient identity — is kept out of the system entirely by design.
Your choices
- Export — your full log can be exported from the app at any time.
- Correction — everything you log can be edited or deleted in the app.
- Account deletion — email us and we'll delete your account and its data.
Data retention
We keep your data while your account is active — the whole point of a career portfolio is that it persists. If you delete your account, your data is removed from the live database promptly and from rotating backups as they expire.
Children
Folio32 is for dental students and residents and is not directed to anyone under 16.
Contact
Questions or requests: hello@folio32.com.