Privacy Policy
Effective date: July 9, 2026 · Last updated: September 12, 2026
This policy supersedes the SteelFolio Privacy Policy dated May 31, 2026.
SteelFolio ("we," "our," or "us") is a web application operated by SteelFolio LLC, a Washington limited liability company, for knife collection management. This policy explains what we collect, why, who else touches it, and what you can ask us to do about it.
Our guiding principle is data minimization: we collect only what the Service needs to work, and nothing we collect is used for advertising, profiling, or sale.
1. Information We Collect
We collect the information you give us, together with a small amount the Service generates automatically as you use it. These are the categories of information we collect, and they are all listed below.
Account information: Your email address and a cryptographically hashed version of your password. Hashing is deliberately one-way — unlike encryption, it cannot be undone with a key, so we cannot recover your password and neither can anyone who obtained the stored value. We never store your password in plain text.
Profile information (optional): Your legal name and insurance policy number, used solely to populate your insurance appraisal PDF documents. These fields are entirely optional.
Collection data: Information about knives in your collection, including maker, model, blade specifications, purchase details, current value, condition notes, storage location, and audit history.
Uploaded files: Photos of your knives and receipt or documentation images and PDFs you upload for insurance documentation purposes. When you upload a photo, we automatically strip embedded metadata (EXIF), including any GPS location data, before storing it. We also generate a small thumbnail copy of each photo for display purposes.
Two-factor authentication data (optional): If you enable 2FA, we store a TOTP secret and hashed recovery codes associated with your account.
Email preferences: If you opt in to periodic collection reminder emails, we store your chosen frequency (monthly, quarterly, or annually) and the date a reminder was last sent.
Payment information: If you purchase a paid plan, payment is handled by Stripe (see Section 4). We do not collect or store your card number. We store only what we need to manage your subscription, such as your plan, billing status, and a Stripe customer reference.
2. Cookies and Analytics
We use only first-party, functional cookies. Specifically:
Session cookie: Set when you log in to keep you authenticated. It expires after 30 minutes of inactivity.
Security (CSRF) token: Used to protect forms against cross-site request forgery attacks.
We do not use advertising cookies, tracking cookies, or any third-party cookies. There are no advertising or tracking cookies to consent to, so we do not ask you to make that choice.
Analytics: We measure page usage with our own server-side counter, hosted entirely on our own infrastructure. For each page visit, we record the page visited, the time of the visit, and, when you are signed in, which account made the visit, so we can understand which features are being used. We do not record your IP address. We do not use Google Analytics or any third-party website analytics or tracking service, and this website usage data does not leave our infrastructure. Separately, if you opt in to our mailing list, our email provider records whether you opened or clicked those messages; that is described under Brevo in Section 4 and is the only engagement measurement handled outside our own systems.
Do Not Track and Global Privacy Control. SteelFolio does not track you across other websites or over time, and does not sell or share personal information for cross-context behavioral advertising. A Do Not Track or Global Privacy Control signal is therefore already consistent with how the Service works — there is nothing for it to switch off. If that ever changes, we will treat a Global Privacy Control signal as a valid request to opt out.
3. How We Use Your Information
We use the information you provide solely to operate and improve SteelFolio. Specifically:
- To authenticate your account and maintain your session
- To store and display your knife collection data
- To generate insurance appraisal PDFs and export files on your request
- To send transactional emails you initiate, such as password reset links
- To send periodic collection reminder emails, if and only if you opt in, at the frequency you choose (you can change or disable this at any time in Settings)
- To process subscription payments and send billing-related notices
- To send product updates, announcements, and collecting-related information through our mailing list, if and only if you separately opt in; you can unsubscribe at any time using the link in any such email
- To understand which features are being used, through our own server-side page-visit records, which are linked to your account while you are signed in as described in Section 2
We do not use your data for advertising, profiling, or any purpose beyond providing the SteelFolio service to you. We do not train AI models on your data.
4. Service Providers
We share data only with the service providers needed to run SteelFolio, and only the minimum each requires:
Hosting — Render.com: The Service and its database run on servers provided by Render, a cloud hosting provider based in the United States, on a persistent encrypted disk. Render's privacy practices are described at render.com/privacy.
File and backup storage — Cloudflare R2: Files you upload — photographs and receipt or documentation images — are stored in Cloudflare R2, an object storage service, as are the notarization records described below and the encrypted database backups described in Section 6. Uploads and backups are held in separate storage areas under separate credentials, so the credential used for backups cannot alter or delete the backup snapshots, which are held under object-lock rules for their retention period. Cloudflare's privacy practices are described at cloudflare.com/privacypolicy.
Transactional email — Resend: Emails such as password resets, account notices, and opt-in reminders are sent via Resend from hello@steelfolio.app. Resend processes your email address in order to deliver these messages. Resend's privacy practices are described at resend.com/legal/privacy-policy.
Payments — Stripe: Subscription payments are processed by Stripe. Your card details are entered directly with Stripe and never touch our servers. Stripe processes your payment information under its own privacy policy, described at stripe.com/privacy. Stripe also sends billing-related emails such as receipts.
Mailing list — Brevo: If you opt in to the SteelFolio mailing list, your email address and basic engagement data, such as opens and clicks, are processed by Brevo to deliver those messages. SteelFolio uses the mailing list only for its own updates and information about the Service, such as new features, changes to these policies, and knife-collecting, collection-management, and insurance topics. SteelFolio does not send third-party advertising, does not sell or rent your address, and Brevo does not use your information for its own marketing. You can unsubscribe from mailing-list emails at any time without affecting account, billing, or security messages.
Blockchain timestamping — OpenTimestamps calendar servers: When a Condition Audit is notarized, our servers send a single blinded cryptographic value to public OpenTimestamps calendar servers. They do not receive your Condition Audit, its digest, your name, your email address, or anything identifying your account. This is described in full under Blockchain Notarization below.
Public verification page: So that someone you give a report to can check a notarization without an account and without trusting us, we publish a verification page for each notarized record. The page is reached by a link containing the record's digest, and it shows the digest, that the record is a condition audit, the date it was recorded, and the Bitcoin block. It does not show your name, your collection, or the contents of the record, and it is excluded from search engine indexing. Anyone holding the link can open the page.
We do not sell, rent, trade, or share your personal information with any third party for marketing or commercial purposes. Your collection data is private to your account. We do not share your data with insurers, appraisers, or any other party. Other than the service providers listed above, and any sharing you enable in Settings or initiate yourself, including share links you generate, the only circumstances under which we would disclose your information are if required to do so by law or legal process, or as part of a merger or sale of the business (in which case this policy would continue to apply to previously collected data).
Community Data Contributions (Optional)
SteelFolio offers optional features that let you contribute certain information to community datasets shared with other users. One example is a sale price you observed in the marketplace, which appears to other users under your username or a display alias you choose. Another, which you turn on in Settings and which is off by default, lets you contribute information from your own collection records, such as purchase price, purchase date, purchase source, and item characteristics like maker, model, and materials.
These features work only after you opt in, and they work differently from one another. A sale price you log is shown to other users attributed to your username or a display alias you choose. Collection information you contribute is shown only in aggregate, and never together with your account identity, name, email address, photographs, or documents. You may withdraw your consent at any time in Settings. Withdrawal stops the use of your information in future aggregations; statistics already calculated from aggregated contributions do not identify you and may be kept and used by SteelFolio, including after you delete your account, to provide and improve the Service.
Blockchain Notarization
When you complete a Condition Audit on a paid plan, SteelFolio assembles a record of that audit and calculates its SHA-256 digest — a fingerprint usually written as 64 hexadecimal characters.
The digest is not what we submit for timestamping. Before submitting, we combine it with a fresh random value and hash the result again, producing a separate value. Only that second value goes to the timestamping service, and it is sent by SteelFolio’s servers — never by your browser or your device. The public OpenTimestamps calendar servers do not receive your Condition Audit, your name, your email address, or anything identifying your account.
The digest itself is not secret, and we want you to know where it appears. It is printed on reports you generate, and it is the address of a verification page on our site that anyone with the link can open. That page shows the digest, that the record is a condition audit, the date it was recorded, and the Bitcoin block. It does not show your name, your collection, or the contents of any record. The digest is an identifier for a record, not a window into it — no one can work out what a record says from its digest alone.
OpenTimestamps combines values from many submissions into a single aggregate and anchors that aggregate to the Bitcoin blockchain. Your submission does not appear on the blockchain as an entry of its own; what is recorded there is an aggregate that your value can later be proven to form part of.
This anchoring is permanent, public, and worldwide. It cannot be undone, deleted, or recalled by SteelFolio or by anyone else, including after you delete your account. We are telling you plainly because it is irreversible in a way that nothing else we do with your data is.
The purpose is to let you show that a condition record existed, in exactly that form, no later than a particular point in time — without anyone having to take SteelFolio’s word for it. Demonstrating that requires the record and its proof file, which stay in your account. SteelFolio does not publish either, and only you can choose to share them.
Please understand what sharing a proof file does. The random value we used to blind your digest is stored inside the proof file, because verification is impossible without it. That value is what keeps the blockchain entry unconnected to your record for everyone else. When you give someone your proof file, you give them the ability to connect the two — which is exactly what lets an adjuster or a buyer verify your record, and is the point of the feature. It also means the recipient can test whether a particular set of details matches the record. Share your proof file with people you intend to be able to verify your record, and treat it as you would the record itself.
When you delete your account, we delete the record, its proof file, and the stored data they were calculated from, together with the internal entry linking that notarization to your account. Copies may remain in encrypted backups until those backups age out on the schedule described in Section 6. After that, nothing remains on our side that connects the blockchain entry to you — not the blinding value, not the record, and not the link to your account. That is why the anchor can remain permanently without remaining personal information in our hands. No one can remove it. The one thing we cannot delete for you is a copy of a proof file you exported or gave to someone else, because that copy is no longer ours to reach; if you have shared proof files and want them out of circulation, you will need to ask the people holding them.
5. Your Rights
You have the right to access, correct, export, or delete your data at any time.
Access and export: You can export your full collection data and files at any time, on any plan and at no charge, using the backup feature in the application. Data portability is a standing commitment — we will never hold your data hostage.
Correction: You can edit any information in your account or collection at any time.
Deletion: You can delete your account directly from the Settings page. Deletion takes effect immediately on our live systems — it removes your user account, all collection data, uploaded photos, receipts, condition audits, notarization records and proof files, feedback submissions, and market comp entries, including the stored files behind them. You may also request deletion by contacting us at the address below. Three things outlast that: encrypted database backups, which are immutable by design and age out on the schedule in Section 6 rather than being edited; data you contributed to community datasets in aggregated form, which is not tied to your account, as described under Community Data Contributions; and any blockchain notarization anchor, which no one can remove, as described under Blockchain Notarization.
We recommend exporting a backup of your collection data before deleting your account, as this action cannot be undone.
SteelFolio serves users in the United States. Depending on your state, you may have additional rights under state privacy law, described below. To exercise any right, use the in-app tools or contact us at hello@steelfolio.app.
Your State Privacy Rights
A growing number of states give their residents privacy rights, and the details vary by state. Rather than track a list, SteelFolio extends the core rights to every user, wherever you live.
You may ask SteelFolio to confirm whether it holds personal information about you and give you access to it, correct information that is wrong, delete your information, and provide a portable copy of the information you gave us. You may also opt out of the sale of personal information, targeted advertising, and profiling. SteelFolio does not sell personal information, does not use it for targeted advertising, and does not profile you, so there is nothing to opt out of, but the right is stated here for completeness.
SteelFolio does not use or disclose sensitive personal information, such as account credentials, for advertising or profiling. It collects that information only to run the Service.
To make a request, use the in-app tools or email hello@steelfolio.app. SteelFolio verifies your request through your account login or by confirming information already on file. You may use an authorized agent, and SteelFolio may ask the agent to show written permission. SteelFolio responds within 45 days and may extend once when reasonably needed, with notice to you.
SteelFolio will not deny service, charge a different price, or provide a lesser experience because you exercised a privacy right. If SteelFolio denies a request, you may appeal by replying to the decision or emailing hello@steelfolio.app. If your state provides for it and the appeal does not satisfy you, you may contact your state attorney general.
6. Data Retention and Backups
We retain your data for as long as your account is active. When you delete your account, your personal information, collection data, and uploaded files are removed from our live systems immediately, subject to the three exceptions described in Section 5.
As a commercially reasonable measure to protect against data loss, we maintain automated daily backups of the Service's database in Cloudflare R2, an encrypted, off-platform cloud storage service separate from our primary hosting provider (Render). Backups are retained on a rolling schedule of up to 30 daily snapshots and up to 12 monthly snapshots, after which they are automatically deleted. To guard against tampering or improper deletion — including by us — backups are protected by object-lock rules that make each snapshot immutable for its retention period. This means that when you delete your account, your information is removed from our live systems immediately, but may continue to exist in encrypted, immutable backup copies for up to approximately 12 months before being automatically purged. Uploaded files (photos, receipts, and certificates of authenticity) are stored in a separate private, encrypted storage bucket and are served to you only through short-lived authenticated links. Backups are used solely for disaster recovery and are never used to restore data you have chosen to delete. We have tested our restore process end to end. These measures reduce the risk of data loss, but we do not guarantee against all possible loss, and backups are not a substitute for your own copy of your data — you can export your complete collection and files at any time, at no charge, on every plan, using the built-in export feature (see Section 5).
7. Security
We take reasonable measures to protect your information, including password hashing, HTTPS encryption in transit, session timeouts, CSRF protection, rate limiting, optional two-factor authentication, and stripping of location metadata from uploaded photos. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.
8. Children's Privacy
SteelFolio is intended for adults. The Terms of Service require every user to be at least 18 years old, the Service is not directed to children, and we do not target children in our design or marketing. We do not knowingly permit anyone under 18 to hold an account. If we learn that a user is under 18, we will close the account and delete the information collected from it. Separately, and as required by law, SteelFolio does not knowingly collect personal information from any child under 13; if we learn that we have, we will delete that information promptly and close any related account. A parent or guardian who believes a child under 13 has given SteelFolio personal information may contact hello@steelfolio.app to have it removed.
9. Changes to This Policy
We may update this Privacy Policy from time to time.
Where a change materially reduces the protections described here, expands what we collect, or introduces a new purpose for using your information, we will notify you by email or in-app notice at least 30 days before it takes effect.
Where a change corrects an inaccuracy, clarifies existing wording, or describes something the Service already does, it takes effect when we publish it, and we record it in the change log below. We would rather correct a description promptly than leave an inaccurate one in place while a notice period runs.
Continued use of the Service after a change takes effect constitutes acceptance of the updated policy. If you do not agree, stop using the Service and, if you wish, delete your account.
10. Contact Us
If you have questions about this Privacy Policy, wish to exercise any of the rights described in Section 5, or want to report a concern, contact us at hello@steelfolio.app.
Change Log
A record of changes to this policy since July 9, 2026, and what each one did.
- September 12, 2026 — Narrowed Section 9 so that corrections and clarifications take effect on publication while changes that reduce protections, expand collection, or add a purpose keep the 30-day notice. Added this change log. Removed the statement that using the Service constitutes agreement to this policy, which the Terms of Service already capture. Replaced the term "de-identified" with a plain description of what is actually shown, and separated the attributed sale log from the aggregated collection contribution. Replaced the enumerated list of states with a general commitment covering every user. Added the OpenTimestamps calendar servers and the public verification page to the service provider list. Corrected the description of page-visit records in Section 3, the backup-credential sentence in Section 4, the deletion sentence in Section 6, and the sharing sentence in Section 4 to cover generated share links. Restated the children's privacy section as separate commitments for under 13 and under 18.
- August 18, 2026 — Revised the Blockchain Notarization section in full: added an explanation of what sharing a proof file allows a recipient to do, narrowed the statement about where the digest is sent, disclosed that the digest appears on reports and in the address of the public verification page, removed unqualified claims about what third parties can and cannot do, replaced the characterization of the backup window with a cross-reference to Section 6, and explained why the permanent anchor does not survive as personal information after deletion.
- August 12, 2026 — Corrected statements about how the Service actually behaves: the account deletion description in Section 5, the storage location of uploaded files and backups in Section 4, the password storage description in Section 1, the analytics description in Section 2, and the disclosure carve-out in Section 4.
- August 9, 2026 — Added the Blockchain Notarization section, describing the timestamping of Condition Audits and the permanence of the resulting record.