Skip to content
Folanza
Open the app

Privacy Policy

Last updated: September 4, 2026

This policy applies exclusively to folanza.app — the informational and landing page for Folanza. The app itself runs at app.folanza.app and has its own privacy policy because different processing takes place there (local data storage in the browser, optional third-party APIs for price data).

This page is static HTML. We set no tracking cookies, no analytics, no pixel. We do not collect or store any personal data about you — apart from the technically unavoidable server logs of our host (see below).

1. Data controller

Controller within the meaning of the General Data Protection Regulation (GDPR):

Robert Dathe
Robert-Matzke-Str. 44
01127 Dresden, Germany
Email: admin@folanza.app

2. Hosting and edge worker (Cloudflare)

This website is hosted on Cloudflare Pages, a service of Cloudflare, Inc. When you visit, technical server-log data (IP address, timestamp, requested URL, user agent, referrer) is automatically processed by Cloudflare. This data is required for delivery, protection against attacks (e.g. DDoS protection) and error analysis.

On the same infrastructure we additionally operate a Cloudflare Worker (service name folanza-api, domain app.folanza.app/api/*) that receives and forwards API calls from the Folanza app. The worker performs a short edge check on each request (rate-limit check based on the requesting IP, geographic assignment via Cloudflare's own cf-ipcountry signal for spam prevention). This processing is technically necessary to protect the interfaces from misuse.

  • Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
  • Purposes: delivery of the website (Pages), processing of API requests (Worker), DDoS/bot protection, error analysis
  • Legal basis: legitimate interest, Art. 6 (1) (f) GDPR (technical provision, IT security)
  • Data processing: agreement pursuant to Art. 28 GDPR (Cloudflare Data Processing Addendum)
  • Third-country transfer (USA): EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR); additionally Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR
  • Storage period for worker logs: max. 7 days (Cloudflare's standard for Workers Analytics); automatic deletion afterwards
  • Privacy: cloudflare.com/en-gb/privacypolicy

3. Fonts (self-hosted)

The fonts Sora (headings) and Roboto Flex (body) are delivered directly from this domain — not via Google Fonts or any other CDN. When loading the page, therefore, no additional IP address is transmitted to third parties.

  • Storage location: folanza.app/assets/fonts/
  • Format: WOFF2, Latin + Latin-Extended subset
  • License: SIL Open Font License 1.1 (OFL)
  • Note: Fonts are loaded with font-display: swap. If the font is not available, the browser falls back to system fonts.

4. Cookies and local storage

This website sets no cookies of its own and embeds no external analytics or tracking service. The in-house audience measurement (section 6) stores nothing on your device and reads nothing from it. There is therefore no consent banner — no consent-requiring cookies are set.

A single entry is stored locally in your browser: if you use the light/dark design switch, your browser remembers that choice in localStorage under the key folanza:landing-theme (value light or dark). The entry carries no personal reference, is never transmitted to us, and disappears as soon as you clear your browser data. It is written only when you click, and it is strictly necessary to provide the function you asked for — legal basis § 25 (2) No. 2 TDDDG. sessionStorage is not used.

Cloudflare sets the cookie __cf_bm for bot detection and security checks (lifetime ~30 minutes). It is strictly technically necessary to protect the website from automated attacks — legal basis § 25 (2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) in conjunction with Art. 6 (1) (f) GDPR. Consent is therefore not required.

5. Beta signup (discontinued)

Until September 4, 2026 you could sign up for beta access on this website: your email address and optionally your first name were sent to our Cloudflare Worker, which used the transactional email service Resend to send a notification to admin@folanza.app.

  • The legal basis was Art. 6(1)(b) GDPR (pre-contractual measures at your request)
  • Processor: Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA
  • Third-country transfer (USA): safeguarded by standard contractual clauses under Art. 46(2)(c) GDPR
  • Resend privacy policy: resend.com/legal/privacy-policy

This processing has ended. The app opens without an access code, the signup form no longer exists, and no data is collected through it any more. The email addresses and first names received have been deleted on our side. How long Resend keeps delivery data in its own logs is governed by their privacy policy.

This section remains for the information of people who signed up earlier. Questions are welcome at admin@folanza.app.

6. Audience measurement without personal data

To see at all whether this site is being visited, page views are counted in-house — on the same infrastructure that serves the site. No Google Analytics, no Plausible, no Matomo, no Sentry, no Facebook pixel and no advertising tag is used.

On each visit a small script (/assets/hit.js) reports to the site's own endpoint folanza.app/api/hit. All that results from it are daily counters for:

  • the page visited, from a fixed list of the pages that exist
  • the hostname of the referring site, e.g. google.com — never the full address including search terms
  • the country Cloudflare derives from the IP address
  • the coarse device type, mobil or desktop
  • clicks on the buttons to the app and to Google Play

What matters is how it is counted: these details go into separate tables, never in combination. No row "someone from country X read page Z on day Y" is created — only "page Z: 40 views" and "country X: 12 views". The link between them exists nowhere and cannot be reconstructed afterwards either.

Not stored are: your IP address (it is checked only transiently for abuse prevention and never written down), no visitor identifier — not even a hash of the kind other privacy-friendly services build for "returning visitors" —, no time of day (the date only), no user agent and no full referring address. Recognising you across visits or across websites is therefore technically impossible. For the same reason this count reports views, not "visitors".

Nothing is stored on or read from your device for this — no cookie, no localStorage, no fingerprinting. § 25 TDDDG therefore does not apply and no consent is required. The legal basis is the legitimate interest in audience statistics without personal data, Art. 6 (1) (f) GDPR.

If your browser sends "Do Not Track" or a Global Privacy Control signal, no counting takes place at all. Counters are deleted after 400 days. In addition, countries and referral sources that accounted for fewer than five views on a given day are merged into a collective value — precisely the rare values would otherwise be the most revealing.

Storage is in a Cloudflare D1 database on the same infrastructure that serves this website (see section 2). No additional recipient is involved.

7. External links

This website contains links to external sources, in particular to the Folanza app at app.folanza.app. When you click an external link you leave this site — we have no influence on the data processing of the target site.

Purchases (Folanza Pro): This site does not process payments itself. Purchase of the optional Pro membership happens inside the app via our payment provider Lemon Squeezy (Lemon Squeezy, LLC, USA — part of Stripe) as Merchant of Record — separate from your portfolio data. Details in the app's privacy policy.

8. Your rights

Under the GDPR you have the following rights:

  • Access to the personal data processed about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure of your data (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection to processing (Art. 21)
  • Complaint to a data-protection supervisory authority (Art. 77) — competent authority in Saxony: Sächsische Datenschutz- und Transparenzbeauftragte, Devrientstraße 1, 01067 Dresden, Germany, saechsdsb.de

You can send requests by email to admin@folanza.app.

No automated decision-making (Art. 22 GDPR): No automated decision-making, including profiling, takes place on this website.

9. Data security

This website is delivered exclusively over HTTPS (Strict-Transport-Security with a two-year validity). We use a restrictive Content Security Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff and further security headers to make attacks such as XSS or clickjacking more difficult.

10. Changes to this policy

We reserve the right to adapt this privacy policy if the scope of functionality or the third-party services used change. The current version is always available at folanza.app/datenschutz.

Governing law: German law. In case of discrepancy between this translation and the German original, the German version prevails. Original versions: Impressum (DE) · Datenschutz (DE) · Nutzungsbedingungen (DE)

© 2026 Folanza
Home Imprint Terms If the app ends Go to app
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français 🇪🇸 Español 🇮🇹 Italiano 🇳🇱 Nederlands 🇵🇱 Polski 🇵🇹 Português 🇹🇷 Türkçe