Legal
Privacy Policy.
Last updated: 4 October 2026
Foliopeak is owned by Rackel Ltd (“Foliopeak”, “we”, “us”). This policy explains what information we collect when you use Foliopeak, why we collect it, who we share it with, and the rights you have over it.
The short version: we don't link to your bank. Every number in your Foliopeak account is one you typed in yourself. We don't sell your data, we don't run ads, and we don't track you across other sites.
Information we collect
Account information
When you create an account, we collect your name, your email address and, if you choose one, a password. Foliopeak receives your password briefly, to screen it against known breaches and to pass it to our authentication provider, Neon Auth. We never store it, log it or write it to a database. Neon Auth keeps only a salted one-way hash of it, never the password itself, and our application code never reads that hash. Before a password is set, a one-way hash of it is calculated and only the first five characters of that hash are sent to Have I Been Pwned, so a password already known from a breach cannot be used; the password itself is never sent to them, and nothing is stored from the check. If you sign in with Google instead, no password is involved and the OAuth exchange is handled by Neon Auth.
Signing in with Google, and Google Sheets. If you choose Continue with Google, Google tells us, through Neon Auth, your name, your email address and whether Google has confirmed it, the link to your Google profile picture, and an ID for your Google account. We use these only to create your Foliopeak account, sign you in and show your name. We never receive your Google password, and we can't see your Gmail, Drive, contacts or anything else in your Google account. If you connect Google Sheets to keep a live copy of your accounts, you give Foliopeak permission to create and update spreadsheets: it only ever writes to the one sheet it created for you, never reads your other spreadsheets, and keeps the connection's access tokens encrypted so the sync can run. We don't sell Google user data, use it for advertising, or share it with anyone except the providers named on this page who run Foliopeak for us. It is deleted when you disconnect Google Sheets or delete your account, and you can remove Foliopeak's access at any time at myaccount.google.com/permissions. Foliopeak's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can also sign in, or sign up, with a link we email you instead of a password. Neon Auth makes the link and we send it. If you sign up this way, we keep the name and email address you gave, and any referral code, until the link has made your account, and for no more than two days.
If you turn on two-factor authentication, we store the information needed to verify your one-time codes, plus a set of one-way-hashed backup codes. The plaintext backup codes are shown to you once, at setup, and never stored.
If you add Face ID, a fingerprint or a security key (a passkey) as your second step, we store its public key and ID, a counter your device sends with each use, how it connects (for example USB or built in), a name for it worked out from your browser and the kind of key (for example "iPhone" or "YubiKey"), and when it was added and last used. We never receive anything biometric: your face or fingerprint is checked by your device and does not leave it, and the device only tells us the check passed. Adding or using a passkey also stores a random one-time challenge, which stops working after five minutes. Passkeys are removed when you remove them, turn two-factor off or delete your account.
To warn you about sign-ins from somewhere new, we keep a short record of each device your account signs in from: the browser and system (for example "Chrome on Windows"), a rough location worked out from your connection (a town and country), and when it was first and last used, plus any name you give it. Each signed-in session is linked to its device, so Settings shows which session is which; that link is deleted when the session ends. We never keep your IP address for this. The record is used only for those emails and that list, and is deleted with your account.
Financial information you enter yourself
Foliopeak does not connect to your bank, broker, or pension provider, and never asks for your banking credentials. Every account, holding, transaction, balance, and goal in Foliopeak is information you've typed in directly. We store it so we can show it back to you - as your dashboard, your tax-year tracking, your net worth history, and your calculators.
If you use the business tools, we also store the figures you save there - your income for the year, expected turnover and expenses, whether you pay Scottish income tax, whether it's your first Self Assessment year, and your company's year end. If you import your business accounts, or type them in, we store the figures you confirm - turnover, expenses, profit, cash at bank, retained profit, a director's loan and Corporation Tax owed - with the period they cover and which accounting software they came from. The report file itself is read in your browser and never uploaded. When you log a payment against your tax reserve, we store what you were paid and what you set aside; and which company year-end checklist items you have ticked.
To build your net worth history, we save a snapshot of your total net worth (and a breakdown by account type) once a day when you visit, or on demand if you use the "Save snapshot now" button - both are stored the same way as everything else above.
If you use the Retirement overview, we also store the year you were born, the age you plan to retire, your State Pension forecast, what you pay into pensions, your expected retirement spending and any retirement income you add. They are used to show that page and to fill in the Monte Carlo when you open it from there.
If you use the household feature, we also store what you choose to share for a combined view - your ownership share of joint accounts, and (if you invite a partner) their email address, sent by us so they can join. A Partner member's invite also carries an invite code to the site, labelled with the inviter's name and linked to the partner's account once they join. Everyone in a household sees the others' accounts, debts, budget and tax-year allowance figures, and any family map entries they choose to share, read-only, until they leave it. If you choose to share an employer share grant with them, they see its company and vested value, not its units, prices, notes or vesting schedule. That sharing stops when anyone joins or leaves the household.
If you use the family map (part of Household, on the Partner plan), we store what you add to it: where accounts, pensions, policies, property and documents are held or kept, reference numbers, notes, and the names and contact details of people you list, such as a solicitor. It is for where things are, not how to get into them, and it turns away entries that look like a password, PIN, recovery code or card number. A household partner sees only the entries you choose to share with them. Someone you share your portfolio with sees your whole map, including executor notes on your accounts, only if you include it in that share.
Learning Hub progress
If you use the Learning Hub, we save which articles you've finished and whether you got full marks, and, for the daily review question, which questions you've answered and when each is next due. It's stored with your account so your progress follows you between devices, and it isn't used for anything else.
Information you send us directly
If you use the contact form, we receive whatever name, email address, and message you provide, so we can reply to you. If you use Contact support inside the app, we receive your message, your email address, the page you were on and any screenshot you attach.
Contact support also has a box, unticked unless you tick it, saying we may quote your message on the Foliopeak website. If you tick it, we store that and the first name and town you give, and we may then show your words, or part of them, on the website with that name and town and nothing else about you. Email us and we take a quote down; the message itself goes after 12 months, like any other.
Technical information
We process your IP address for security purposes - specifically, to rate-limit sign-up and sign-in attempts and reduce automated abuse. We don't use it for tracking or profiling.
How we use your information
We use the information above to:
- Provide and run your Foliopeak account - your dashboard, calculators, tax-year tracking, and goals
- Authenticate you and keep your account secure, including two-factor authentication and rate-limiting
- Send account-related emails - email verification, password reset, sign-in links, and (if you invite one) a household partner invite
- Respond to you when you contact us
- Process payments and manage your subscription, if you're on a paid plan (Solo or Partner)
- Meet our own legal and accounting obligations
We do not use your information for advertising, and we do not sell it to anyone.
If you connect an AI assistant (Cairn)
Cairn lets you connect an AI app you already use - Claude, or anything else that speaks MCP - to your Foliopeak data, so you can ask about your own numbers in plain English. It is off unless you turn it on. Cairn is read-only by default. You can choose to create a key with write access, which can only propose changes - new balances, new accounts, bills, journal entries, allowance payments, trades, goals, family map entries or fixes for your notifications. It cannot move money, delete data or change account settings, and nothing changes until you approve it inside Foliopeak.
A key with write access works through Cairn and through Foliopeak's API, and both can only propose a change. It waits in Foliopeak, showing exactly what would change, until you approve or decline it while signed in, and lapses after 7 days. Approval is refused where any relevant underlying value has changed since it was proposed. Revoke a key in Settings and it stops working immediately.
How the write side is held back, control by control:
- A write key can only propose. Every write tool - balances, new accounts, bills, journal entries, allowance payments, trades, goals, family map entries, fixes for notifications - creates a proposal. Several at once arrive as one batch. The key applies nothing itself.
- You approve inside Foliopeak. A proposal is applied only by your tap while signed in, and it is checked again at that moment: approval is refused where any relevant underlying value has changed since it was proposed - a balance or allowance figure that has moved, a holding that no longer exists, a notification already dealt with - and the rest is validated as if you had entered it by hand. A batch is approved or declined whole, and refused whole if any item in it no longer fits.
- Proposals lapse, and there is a cap. A proposal expires after 7 days, and at most 20 can wait at once. Past that the tools answer with a message to approve or decline some first, so a runaway or hijacked assistant fills one card, not your account.
- Write access is a deliberate choice. Only a key you create in Settings, choosing write access, can propose. Connecting an assistant with one click issues a read-only key, and no assistant can raise its own permission.
- Rate limited. A key may propose at most 30 changes an hour.
- On the record. Every request a key makes is in the Cairn request log, and every approval and decline is in your account's audit log.
- Revoked in one click. Revoking a key in Settings stops it immediately.
We do not see your conversation. Your assistant translates what you typed into a specific request - “summarise my portfolio”, say - and that request is all that reaches us. We never receive the wording of your question or anything else you discussed.
We keep a log of those requests - which one, when, and whether it succeeded, including any balance it updated - and show it back to you on the Cairn page. It exists so you can see what left your account and when, which is the thing worth being able to check after connecting a third party to your finances. Entries are deleted automatically after 12 months, and revoking the API key stops any further access immediately.
The data your assistant receives goes to whichever AI provider you chose, under their terms and their privacy policy, not ours. That is the trade Cairn makes, and it is why it is opt-in and why we describe it plainly rather than calling it seamless.
Our legal bases for using your information
UK data protection law requires us to have a specific reason for each thing we do with your information, and to tell you what it is. Ours are:
- Running your account - Performance of a contract. You asked us to provide Foliopeak; storing the accounts, holdings and goals you enter is how we do that.
- People you list on the family map - Our legitimate interests in you being able to record who to contact. We store the names and contact details you add, show them to you and anyone you share the map with, and delete them with your map or your account.
- Taking payment for a paid plan - Performance of a contract, for the subscription itself. Keeping the resulting records is a legal obligation - UK tax law requires us to retain them.
- Account security email - Performance of a contract, and our legitimate interests. Password resets, verification, sign-in links and sign-in codes are not optional extras; an account you cannot recover is not a usable account.
- Keeping the service working and preventing abuse - Our legitimate interests. Rate limiting, the bot check on sign-up, and blocking fraudulent payments protect every other user, and none of it requires knowing anything about you beyond what we already hold.
- Optional emails - Consent. Monthly Assessment reminders and the newsletter are off unless you turn them on. Turn any of them off in Settings, or with the unsubscribe link in the email, and that consent is withdrawn straight away. If you tell us why you unsubscribed, we keep your answer, any note you add and the month for 13 months, not linked to your account or email address.
- The Cairn request log - Performance of a contract, and our legitimate interests in you being able to audit what an assistant you connected has read. Only kept if you use Cairn at all, and deleted after 12 months.
- Your trusted contact - Performance of a contract, at your request: you choose who we write to if you die, what they get, and whether they can see your account read-only for a year. We use their name and email address for that alone, and delete them when you remove the contact or your account.
Where we rely on legitimate interests, we have considered whether our reason is outweighed by your rights, and we think it is not - but you can object, and we will look at it properly rather than pointing at this paragraph.
Who we share information with
We use a small number of service providers to run Foliopeak. Each only receives what it needs to do its specific job:
- Neon - our database and authentication provider. Hosts your account details and everything you enter into Foliopeak.
- Amazon Web Services - keeps the nightly backups of the database, and copies of any documents you attach to accounts, in London, in an account kept apart from the rest of Foliopeak. The site can add a backup but cannot change or delete one. New backups are encrypted before they reach AWS, with a key AWS does not hold. Documents are only ever copied encrypted.
- Cloudflare - hosts the application itself and handles web traffic.
- Resend - sends emails on our behalf. This includes account security emails (password resets, email verification, sign-in links and codes), contact-form messages, household and portfolio-share invites, payment receipts and failed-payment notices for paid plans, and any notifications you have turned on. Security emails contain a one-time link or code tied to your account. No email we send contains your figures - balances, holdings, amounts, rates or allowances - or the names of your accounts, goals, debts, providers or companies, or where you are: an email says that something has happened or needs a look, and links to the page in Foliopeak where the detail is, behind your sign-in.
- Stripe - processes Solo and Partner subscription payments. We never see or store your card details; Stripe's own checkout page handles that directly.
- Attio - our customer list (CRM). Holds a copy of your name, email address, whether you came from the early-access list or signed up directly, your plan and the date you joined, so we can keep track of who is waiting and who is using Foliopeak. Never your accounts, balances or anything you enter into Foliopeak.
- Google - if you choose to sign in with Google, or connect Google Sheets to export your data, the relevant exchange happens directly with Google under your control.
Foliopeak's calculators and news pages also call market-data and currency providers (for share prices, exchange rates, and headlines), public news feeds and, for a property value estimate, HM Land Registry. These only ever receive a ticker symbol, a currency code, a postcode, or a request for general headlines - never your name, your balances, or anything that identifies you.
Property value estimates. If you ask for an estimate of a property's value - on a property account or with the property value calculator - the postcode you enter is sent to HM Land Registry's public Price Paid Data service, to find past sales at that postcode. The local council area of the matching sale is then sent to its UK House Price Index, to see how prices there have moved since. The house number or name you type is matched against those results on our own server and is never sent. Nothing that identifies you goes with either request, and we don't keep the postcode. HM Land Registry is a public open-data service, not one of our processors: it answers the lookup and receives nothing else from us.
If you choose to have a property follow house prices, its postcode is sent to HM Land Registry once, to find its local council area. We keep that area with the property, not the postcode, and once a week ask the UK House Price Index for the area's latest figure; the area's name is all that request carries. Stop following and the area is removed.
Each of these acts as our processor: they handle your information on our instructions and for no purpose of their own, under a written data processing agreement. We remain responsible for it either way, which is the point of naming them here rather than leaving it vague. You can read each agreement: Neon, Amazon Web Services, Cloudflare, Stripe, Resend and Attio.
Stripe is also a controller in its own right for parts of what it does - fraud prevention and meeting its own financial-services obligations - which it explains in its own privacy policy. That is not us passing your data on for Stripe's benefit; it is a payments company having duties of its own that we cannot instruct it out of.
We don't share your information with anyone else, and we don't sell it. If that ever changes for a specific new feature, we'll update this policy first. The exceptions are ones you make yourself: a household partner, someone you share your portfolio with, and a trusted contact you name - who gets only what you chose, and only when it is released, as set out under How long we keep your information.
Where your information is held
Your database is in the UK. Everything you enter into Foliopeak - your accounts, holdings, transactions, goals, journal entries and family map - is stored in a Neon database hosted in London (AWS eu-west-2), and backed up every night to Amazon Web Services, also in London, in an account kept apart from the rest of Foliopeak.
Some of the services around it do operate internationally, and we would rather say so than imply otherwise:
- Cloudflare - Serves the site from whichever data centre is nearest to you, so request data (such as your IP address) may be processed outside the UK. Also holds any document you attach to an account, your profile picture if you add one, and any screenshot you attach to a support message, in private storage in Western Europe. Covered by the UK Addendum to the EU Standard Contractual Clauses in its data processing agreement.
- Stripe - US-based. Certified under the UK Extension to the EU-US Data Privacy Framework, which is a transfer mechanism the UK government recognises.
- Resend - US-based. Also certified under the UK Extension to the EU-US Data Privacy Framework.
- Attio - Hosted on Google Cloud. Transfers of your details are covered by the UK Addendum to the EU Standard Contractual Clauses in its data processing agreement.
- Google - Only involved if you choose to sign in with Google or connect Google Sheets, and only for that exchange.
In plain terms: the sensitive part - the numbers themselves - stays in the UK. What crosses a border is the infrastructure around it, and each provider that does so is under a recognised safeguard rather than a handshake.
The early-access list
While Foliopeak is invite-only, the page you reach without an invite code offers to tell you when it opens. If you use it we store the email address you give us and whether you asked for the monthly newsletter as well, and when you confirmed it - no name, no tracking, and nothing else.
We use it to email you once when Foliopeak opens, and, only if you ticked that box and then pressed the confirm link we email you, the monthly newsletter on how Foliopeak is being built. If an email to the address bounces for good or is reported as spam, Resend tells us, we note that against the address, and no more optional emails go to it. Our legal basis is your consent, which you can withdraw at any time: every one of those emails has an unsubscribe link, and one click is enough. The address is held in our database in London, copied to Attio - the customer list named above - so we can keep track of who is waiting, and sent through Resend, the email provider named above. It is never sold, and never passed to anyone beyond those two.
If you have an account and turn the newsletter on in Settings, that choice is stored in the same list. It is removed, or switched off, when you delete your account.
We keep it until Foliopeak opens or until you ask us to delete it, whichever comes first. Email hello@foliopeak.com to see what we hold, correct it, or have it deleted.
How long we keep your information
We keep your account and the information you've entered for as long as your account is active, so Foliopeak can keep working the way it's meant to. You can delete your account and data yourself at any time, from Settings - or email hello@foliopeak.com and we'll do it for you.
Deleting your account removes your login and everything attached to it - accounts, holdings, transactions, goals, journal entries, family map, snapshots, household membership, Learning Hub progress and API keys. Three things survive, and it is only fair to say so: we keep your email address and the reason you gave, as a short record that the deletion happened and why, for 12 months, after which it is deleted automatically; our audit log keeps its record of security events on the account, such as API keys being created, by an internal ID rather than your name or email, for 24 months; and your data remains inside existing backups until those age out, which is about three months. Ask us and the exit record goes sooner. If you were paying, the plan is cancelled when you ask to delete and ended in Stripe when the account goes; Stripe keeps its own record of the payments you made, which it and we are required to keep for tax and accounting.
Messages you send us - through the contact form or Contact support, with any screenshot - are kept for 12 months so we can follow up, then deleted automatically. Deleting your account deletes your Contact support messages and screenshots straight away; the contact form isn't linked to an account, so a message sent there goes at 12 months, or sooner if you ask.
Sign-ups never confirmed. If someone starts an account but never confirms their email address, never signs in and adds nothing, we delete it automatically after 14 days.
Your trusted contact. If you name a trusted contact in Settings, we keep their name and email address, the note you leave for them (encrypted), and the choices you make. Nothing is sent to them while you're alive. It is released in one of two ways: when someone sends us a death certificate and we have checked it, after 14 days' notice to your email address, during which signing in stops it; or, if you choose, after the period without a sign-in you set (6 or 12 months), with warnings to your email address first. We then send them your note. If you chose to let them see where your money is held, they see it read-only, through their own account, for 12 months - it is not put in the email - and then your account is deleted. If you turned on read-only access, they can also see your Foliopeak, read-only, through their own account, and download your export, for 12 months - never with your login - and then your account is deleted, sooner if they ask. If they get only your note, your account is deleted 12 months after it is sent. If it was sent because you hadn't signed in, we write to your email address 30 days before your account is deleted. Removing your trusted contact, or deleting your account, deletes all of this.
When you delete something - an account, a holding, a trade, a debt, a goal, a bill, a planned spend, a journal entry or a share grant - or change a debt's balance, we keep a copy of what it was in your activity history, so you can undo it. Undo works for 30 days, and the history is deleted automatically after 90. Documents attached to a deleted account are kept for those 30 days so an undo can bring them back, then deleted. Text that is encrypted stays encrypted in the history. It is included in your data export, cleared by Clear all my data, and deleted with your account.
Backups are written daily to Amazon Web Services in London, in their own account, so that a failure is recoverable rather than final. Each is kept for about three months, then deleted automatically.
Your rights
Under UK data protection law, you have the right to:
- Ask what personal information we hold about you, and get a copy of it
- Ask us to correct information that's wrong or incomplete
- Ask us to delete your information
- Ask us to restrict or object to certain uses of your information
- Receive your information in a portable format
To exercise any of these, email hello@foliopeak.com. We'll respond within one month.
Making a complaint
If you're unhappy with how we've handled your personal information, you can complain to us by emailing hello@foliopeak.com. Putting "Data protection complaint" in the subject line helps it reach the right place quickly. We'll acknowledge your complaint within 30 days, look into it, and tell you what we found and what we're doing about it without undue delay.
If you're not happy with our response, you can complain to the UK's data protection regulator, the Information Commissioner's Office (ICO).
Children
Foliopeak isn't intended for anyone under 18. We don't knowingly collect information from children. If we become aware that we have, we'll delete it.
Security
We use industry-standard measures to protect your information, including encryption in transit (HTTPS) and access controls on our systems. The free text you write, such as journal entries, notes and family map details, is also encrypted with a key kept outside the database before it is stored, as are your two-factor secret and any Google Sheets connection tokens; your numbers are not, because totals and charts need them. Your account and everything you enter into Foliopeak is stored in a UK data centre and backed up nightly to another, also in the UK. Some processing does happen outside the UK - Cloudflare serves the site from the data centre nearest you, and Stripe is US-based - which is set out in full under International transfers above, along with the legal mechanism covering each. No method of storage or transmission is completely secure, but we work to keep your information as safe as reasonably possible and to improve on that over time.
Changes to this policy
We may update this policy as Foliopeak changes. If we make a material change, we'll update the date at the top of this page. We'd encourage checking back occasionally.
Contact us
Questions about this policy or your information? Email hello@foliopeak.com or use the contact page.

