feedfold

Privacy Policy

Updated 24 September 2026

What we keep

We use this data to run your reader, sign you in, fetch updates, handle requested AI features, answer questions and prevent abuse. Feed addresses can contain private tokens; adding one sends it and its content to Feedfold.

Who receives it

Feedfold has no advertising system, session replay or product analytics SDK. Administrators can access server data to operate the service. Public source content is shared between accounts following the same source; reading state and settings belong to each account.

Browser storage

A session cookie keeps you signed in for up to 30 days; sign-out or inactivity can end the session sooner. Local storage remembers preferences. IndexedDB holds your browser identifier and the key that unlocks your encrypted AI credentials on the server. Signing out removes that browser’s saved AI credentials and unlocking key.

The service worker caches app files, not authenticated API responses. Clear Feedfold’s site data to remove browser preferences, keys and caches. You will need to enter AI keys again. Cloudflare and content hosts may use their own cookies.

Google and YouTube

Feedfold uses YouTube API Services for channel subscriptions and embedded playback. Loading a player sends data to YouTube even before Play. See the Google Privacy Policy.

Connecting YouTube grants youtube.readonly (“View your YouTube account”) permission. Feedfold uses it to read your subscribed channels and import them as feeds. It does not change your YouTube subscriptions or publish anything.

Feedfold stores an encrypted refresh token on the backend, with its encryption key kept separately from the database, to sync daily while your browser is closed. Short-lived access tokens are used in memory and are not saved to the database. A complete, successful sync always removes corresponding feeds when it confirms an unsubscription. Failed or incomplete syncs do not trigger those removals.

Google account data is used only for subscription syncing, not advertising, sale, AI training or sharing with AI providers.

Disconnecting stops syncing and immediately revokes the Google token. Feedfold deletes the stored tokens and data imported through that connection as soon as possible, within seven calendar days. The same deletion deadline applies when you delete your account or request deletion at [email protected].

You can also revoke access in Google’s account permissions. Feedfold periodically checks authorization and deletes the stored tokens and associated YouTube data as soon as possible, within 30 calendar days of that revocation.

Stored YouTube subscription data is refreshed or deleted within 30 calendar days, including when syncing is paused. YouTube connection tokens and synced subscriptions are excluded from database backups, so restoring a backup does not restore that connection or its synced feeds. They take precedence over the general retention rules below. Deleting data in Feedfold does not delete anything on YouTube.

Retention and deletion

Reader data stays until you remove it or delete your account. Inactivity pauses refreshes after seven days; it does not delete data.

Removing a feed deletes your subscription and reading state. Deleting your account removes its credentials, reader data, AI results and related invitation records from the active database. Unused sources and articles are removed; content another account uses remains.

Expired or revoked unused invitations are removed within 30 days during normal operation. Redeemed records remain while the accounts involved exist.

Backups are configured for a seven-day limit, with at most two copies on the server. Account deletion does not edit existing backups. For data other than YouTube connection data, outages can delay local cleanup and restoring a backup can bring deleted data back. Email [email protected] if that happens.

Application logs keep request routes, status, timing and security events, without request bodies, credentials, raw IPs or full URLs. They rotate by size, keeping up to two 5 MB files, with no fixed time limit. Hosting providers have separate log retention rules.

Your controls

Remove feeds or export subscriptions in Manage feeds. OPML exports subscriptions, not all account data. In Settings you can manage sign-in methods, remove AI keys or delete your account.

Email [email protected] for privacy questions, complaints, access, correction or deletion requests. Depending on applicable law, you may also have rights to portability, restriction, objection, withdrawal of consent or a complaint to a data protection authority.

Security

Feedfold uses HTTPS, password hashing, account access checks and rate limits. Saved AI keys and off-server backups are encrypted. Account data is not end-to-end encrypted, and AI requests pass through the server. No system is completely secure.

Changes to this policy will appear here with an updated date.