Foliant

Legal

English translation of the binding German version at foliant.dev/legal/. In case of conflict the German text prevails.

Legal notice

Information pursuant to § 5 Austrian E-Commerce Act (ECG), § 63 Trade Act (GewO) and disclosure pursuant to § 25 Media Act (MedienG).

Service provider and media owner
karrer.solutions
Martin Karrer
Zillfeldweg 2
6361 Hopfgarten im Brixental
Austria

Email: hello@foliant.dev
Web: karrer.solutions

Company details
Legal form: sole proprietorship (Einzelunternehmen)
Business purpose: software development, operation of software-as-a-service applications, IT consulting
Trade: services in automatic data processing and information technology
Trade authority: Bezirkshauptmannschaft Kitzbühel
Chamber membership: Wirtschaftskammer Tirol, professional group for management consulting, accounting and information technology
Applicable regulations: Austrian Trade Act (GewO), available at www.ris.bka.gv.at

Purpose of this site
Foliant is a product of karrer.solutions. This website describes the service and provides the API and the customer account.

Consumer dispute resolution
The European Commission provides a platform for online dispute resolution: ec.europa.eu/consumers/odr. We are neither willing nor obliged to take part in dispute resolution proceedings before a consumer arbitration board.

Liability for content and links
We are responsible for our own content under general law. For third-party information we transmit or store we are not obliged to monitor it (§§ 13 to 18 ECG). Users are responsible for documents they create through the API. We accept no liability for the content of linked third-party websites; their operators are responsible. We remove infringing content or links promptly once we become aware of them.

Privacy Policy

The controller is the provider named in the legal notice. This policy describes which data Foliant processes and why. In short: we store your email address, usage counters and the templates and files you upload. We do not store rendered documents or the source you send to the render API.

1. Hosting and server logs

Foliant runs on Amazon Web Services (AWS), operated by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. All stored data (account, usage counters, assets, templates) lives in the Frankfurt region (eu-central-1). The default endpoint api.foliant.dev processes requests in Frankfurt as well. If you explicitly choose the endpoint us.api.foliant.dev, your request is processed in the US East (N. Virginia) region; there too, content is held in memory only for the duration of the request. The website is delivered through the global CloudFront network. Where data reaches the US, this is based on the EU-US Data Privacy Framework, to which AWS is certified, and on standard contractual clauses. When you access the website or the API, AWS processes technical access data (IP address, time, requested address, user agent) in server logs that are deleted after 7 to 30 days. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in operating and securing the service.

2. Demo without an account

For the demo feature we store a salted hash of your IP address together with a daily counter to limit use to three renders per day. The hash is deleted automatically after two days. Legal basis: Art. 6(1)(f) GDPR (abuse prevention).

3. Account and sign-in

To sign in you provide your email address. We send a sign-in link by email; an account is created only when the link is opened. We store: email address, time of account creation, hashes of your API keys (never the key itself), monthly usage counters (pages, renders), credit balance and subscription state, and a hashed IP counter to limit account creation. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). The session is held in a cookie fl_session (HttpOnly, 30 days), which is required for the service and needs no consent.

Sign-in links and account notices are sent through Amazon Simple Email Service (Amazon Web Services EMEA SARL, Frankfurt region). Email to hello@foliant.dev is forwarded through Cloudflare Email Routing (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA) to our mailbox at Google Workspace (Google Cloud EMEA Limited, Dublin, Ireland). Domain name resolution is provided by Cloudflare. Legal basis: Art. 6(1)(b) GDPR for account notices, Art. 6(1)(f) GDPR for operating the infrastructure.

4. Render API

Source text, attached files and the generated document are processed in memory only for the duration of the request and then discarded. We log page count, duration, format and result status, not content. If you process personal data of third parties in your documents, you are the controller and we act as processor; a data processing agreement under Art. 28 GDPR is available on request.

For files you reference by URL, our server fetches the given address. The target server sees our IP address and a user agent, not your data.

5. Assets and templates

Files and templates you store in your account are kept encrypted in Amazon S3 until you delete them or the account. Legal basis: Art. 6(1)(b) GDPR.

6. Payments

Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Stripe receives your email address, billing address, VAT ID where given, and payment details; card data never reaches our servers. We store your Stripe customer id, credit movements and subscription state. Legal basis: Art. 6(1)(b) GDPR and statutory retention duties under commercial and tax law (Art. 6(1)(c) GDPR, 10 years). Stripe's privacy notice: stripe.com/privacy.

7. Cookies and tracking

We set one technically necessary cookie (fl_session). There are no analytics, advertising or third-party cookies. Fonts and all other resources are served from our own servers; no third-party content is embedded.

8. Connected AI assistants (MCP)

If you connect Foliant to an AI assistant (for example Claude, ChatGPT, Grok or Le Chat) through our MCP server, that assistant obtains an API key for your account after you sign in and approve the connection. The key is labelled with the assistant's name and can be revoked in the dashboard at any time. The assistant sends document sources and template or asset requests to the same API described above; we receive only what the assistant sends for the requested action and do not receive your conversation history. The assistant provider's own privacy policy applies to what they store.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and the right to lodge a complaint with a supervisory authority, in Austria the Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at. To delete your account, email hello@foliant.dev from the registered address; payment records are retained for tax purposes.

Terms of Service

1. Subject

Foliant is an application programming interface (API) that converts Typst source into PDF, PNG or SVG files. The provider is karrer.solutions, Martin Karrer, Hopfgarten im Brixental, Austria (see legal notice). The service is aimed at businesses within the meaning of § 1 Austrian Commercial Code (UGB). Consumers within the meaning of the Austrian Consumer Protection Act (KSchG) may use the free tier; section 8 applies to credit purchases by consumers.

2. Contract and pricing

Creating an account concludes a free contract for the free tier (currently 300 pages per calendar month). Beyond that we offer two kinds of paid use:

Credit (pay as you go). You may buy credit at any time in the amount shown; the contract is concluded when the payment completes. Credit does not expire and is consumed per rendered page at the price shown (currently 0.4 cent).

Monthly plans (Starter, Studio, Scale). Plans are available to businesses only. The contract is concluded when the payment completes, runs for one month and renews automatically for one further month at a time unless cancelled to the end of the current period. Cancellation is possible at any time in the customer portal or by email and takes effect at the end of the period. A plan includes a monthly page allowance; unused pages expire at the end of the period. Pages beyond the allowance (overage) are billed at the per-page price shown for the plan with the next invoice; existing credit is consumed before overage. An upgrade takes effect immediately and is prorated; a downgrade takes effect at the end of the period. If the monthly fee cannot be collected, the service remains usable for 7 days; after that existing credit is used, otherwise rendering is suspended until payment is received. If payment remains outstanding, the plan ends and the account reverts to credit use.

Failed renders are never charged. All prices are net of VAT, which is shown at checkout and on the invoice.

3. Use

You may not use the service to create unlawful content, to circumvent usage limits through multiple accounts or changing IP addresses, or to overload the infrastructure. API keys must be kept secret; you are liable for use with your keys until you revoke them in the dashboard.

4. Availability and changes

We aim for high availability but do not guarantee it on the free tier. We may change limits, prices and features with 30 days' notice by email; credit already purchased remains usable at the old price, and plan price changes apply from the first renewal after the notice period. We do not offer a service level agreement to credit customers either; we resolve incidents as quickly as reasonably possible once known. The current operational status is shown at api.foliant.dev/health.

5. Liability

We are liable without limitation for intent and gross negligence, for personal injury and under the Product Liability Act. Towards businesses, liability for slight negligence is excluded; compensation for consequential damage, lost profit and data loss is excluded to the extent permitted by law. Towards businesses, total liability is limited to the fees paid in the preceding twelve months. You are responsible for the accuracy of generated documents and the lawfulness of processed content.

6. Term and termination

You may have your account deleted at any time; a running plan then ends at the end of the period and monthly fees already paid are not refunded pro rata. Unused credit is refunded in full to the original payment method on request when the account is deleted. We may terminate the contract with 30 days' notice, in which case we refund unused credit on our own initiative. In case of violations of section 3 we may suspend the account without notice.

7. Final provisions

Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods and its conflict-of-law rules. For businesses, the competent court in Kitzbühel has exclusive jurisdiction; for consumers the statutory venues apply. Version: September 2026.

8. Right of withdrawal for consumers

Consumers may withdraw from a credit purchase within 14 days of the contract without giving reasons (§ 11 Austrian Distance Selling Act, FAGG). An email to hello@foliant.dev from the registered address is sufficient. We refund the amount paid within 14 days to the original payment method, less the value of pages already consumed before withdrawal at the price shown, since by purchasing you expressly request that we begin performance immediately.