Updated
Privacy policy
FolderSkin has no account and nothing that tracks you. Most of what you do with it never leaves your computer. This page says what does, and where it goes.
What never leaves your computer
- Your folders, what's in them, and the icons FolderSkin writes into them.
- Every picture you add, every skin you make, and your favourites, tags and settings.
- Your API keys. They're stored encrypted, in FolderSkin's own folder, and each one goes only to its own provider, with the requests you make. Where the key lives has the details.
FolderSkin has no analytics, and it doesn't send crash reports. If it crashes, a line about it goes in a log file on your computer, and stays there.
What the app sends, and to whom
FolderSkin goes online for the things below, and nothing else. The servers it reaches see your network address, as every server does.
- When you add a pack from Community, FolderSkin sends the pack's id to its community service, so the gallery on this site can show how often each pack is added. Only the app's version goes with it: no account, no device id, nothing about your library or your folders. The service counts an add once a day for each network and pack. For that, it keeps a hash of your network, never the address itself, under a key that changes every day, and deletes the hash when the day is over (how the counts work).
- Community, and the first launch, read the packs and their pictures from packs.folderskin.app, FolderSkin's own copy of them on Cloudflare, or from GitHub when that doesn't answer.
- A few seconds after it opens, FolderSkin reads the version file of its newest release on GitHub. If there's a new version, nothing is downloaded until you choose to update, and the update's signature is checked before it's installed.
- When you press Generate with your own key, your prompt, the size you picked and any picture to work from go straight from your computer to the provider you chose, with your key. No FolderSkin server sits in between. What the provider does with them is up to its own terms and privacy policy.
- Setting up the Local Model downloads the model from Hugging Face and the program that runs it from GitHub. On a Mac, that program is mflux: FolderSkin downloads uv from GitHub, and uv installs Python and mflux, with mflux's packages from the Python Package Index. From then on, painting happens on your computer and sends nothing anywhere.
- Sharing a pack sends it to the community service, but only when you share one. The next three sections are about that.
Sharing a pack
Sharing is up to you, and a person reviews every pack before anyone else can see it. FolderSkin's community service, at community.folderskin.app, runs on Cloudflare and keeps:
- Your computer's public key, and the name your packs are credited to. The first time you share, FolderSkin opens a page in your browser that checks you're a person, with Cloudflare Turnstile, which sends Cloudflare what it needs for that, your network address included. The private half of the key never leaves your computer, and nobody asks for an email address or a password.
- The pack: its name and tags, the skins' names and tags, its licence, where you said the pictures came from, your credits and the version of the pack sharing terms you agreed to. Then the pictures, and small contact sheets of them for the review.
- Your network, as hashes. The limits on sharing are counted per network, as a hash made with a key that changes every day, and the counts are deleted after eight days. Each pack keeps the hash from the day it was sent. A wait or ban that has to last longer than a day needs a hash that doesn't change: that one is deleted once it stops counting, and a pack keeps it until 30 days after it's decided.
Before a person looks, the pack's words are checked against a list, and its contact sheets are shown to an AI model on Cloudflare Workers AI. Neither can approve a pack or turn it down. All they can do is flag one for a closer look.
Pictures waiting for review stay in private storage. If you never finish sending a pack, what arrived is deleted within two days. A pack that's turned down or withdrawn has its pictures deleted at once. An approved pack's pictures are published, and its contact sheets are deleted 30 days after the approval. When a pack is turned down for what its pictures show, a fingerprint of each picture is kept, so the same file can't be sent again. The service keeps its record of every pack you send, which is what Your submissions in the app shows.
What becomes public
Once a pack is approved, its pictures, its name and tags, the skins' names and tags, its licence and the name it's credited to are public. They show in Community in the app and in the gallery on this site, and they're in the public packs repository on GitHub and on packs.folderskin.app. Where you said the pictures came from, your credits, your key and anything about your network stay with the service.
Taking a pack back
Your submissions, in the app, lists every pack you've sent, and Withdraw takes one back. A pack that's still waiting leaves the queue, and its pictures are deleted. An approved pack comes out of the service at once, and if it's in the packs repository already, the maintainer is told to take it out there, which can take a few days. The repository keeps its history, though, and copies people already have stay theirs under the pack's licence. Treat anything published as permanent, as rules 5 and 17 of the pack sharing terms say.
Reports
If a published pack breaks the pack sharing terms, report it on the packs repository on GitHub, where reports are public, or by email to hello@folderskin.app. Report anything involving a child to the authorities as well.
A report sent to the community service needs no account. The service keeps what the report is about and why, any details and contact you give, and a daily hash of your network, and deletes it all after 180 days. Notices to the maintainer about a report never include the contact details. A report of child sexual abuse material, or of intimate pictures shared without consent, reaches the maintainer at once.
This website
This site has no analytics, no ads and no cookies. Your browser keeps a few things for it, and they never leave your browser: the appearance and language you chose, whether the docs' sidebar is collapsed, and, for the length of a visit, things like the latest version number.
Cloudflare hosts the site, and sees each request as any host does. The pages fetch some of what they show from elsewhere: the latest release, the star count and the gallery's packs from GitHub, and the install counts from the community service. Downloads come straight from GitHub.
Email to hello@folderskin.app goes to FolderSkin's maintainer. Your address and what you write are used to answer you and to act on it, and nothing else. There's no mailing list.
Children
FolderSkin is for everyone. It asks nobody's age, and sharing a pack takes only a name to credit it to. The pack sharing terms keep anything sexual out of every pack, and anything that sexualises a child is reported to the authorities. If a child has shared a pack and you'd like it taken back, Withdraw in Your submissions does it, or write to hello@folderskin.app.
Changes to this page
If this page changes, so does the date at the top. FolderSkin's code is public, so anyone can check what the app sends.
Contact
For anything about your privacy, or about what the community service keeps, write to hello@folderskin.app. Report a security problem privately, through GitHub's advisory form.