Skip to main content

Privacy Policy

Last updated: February 24, 2026

Overview

Formalingo is an AI-powered form and document platform. This policy explains what information we collect, why we collect it, and how we handle it. We aim to be direct and honest — we won't claim practices we don't follow.

Information We Collect

Creator Accounts

When you create an account you provide an email address and password. We store your email in plain text and your password as a bcrypt hash — we never store your password in readable form.

Form Responses

When a respondent submits a form, we store the answers they provide. Respondents do not need an account — they are identified by a unique, randomly generated token tied to their submission link.

Visit Tracking

When someone visits a form link, we record:

  • IP address (stored in full; displayed in the dashboard in masked form, e.g. 84.109.x.x)
  • User-agent string (browser and OS details, parsed via ua-parser-js)
  • Approximate geographic location derived from the IP address via the ip-api.com service
  • Timestamp of the visit

This data is made available to the form creator in their analytics dashboard. It is not sold or shared with third parties beyond what is described in this policy.

How We Use Your Information

  • To operate the service — authenticate creators, display form responses, send form links
  • To provide analytics to form creators (visit counts, device breakdown, geographic data)
  • To improve the security and reliability of the platform

We do not use your data to train AI models or for advertising.

Data Retention

Form responses and visit data are retained as long as the form exists. When a form is permanently deleted, its associated response and visit data is deleted too.

Account data is retained until you request account deletion.

Cookies

We use a single session cookie (form_session_*) for form respondents. It is HttpOnly, lasts 24 hours, and is required for the form-filling experience. We do not use advertising cookies, analytics cookies, or any cross-site tracking.

See our Cookie Policy for full details.

Third-Party Services

  • Supabase — We use Supabase for database storage, file storage, and authentication. Data is stored on Supabase infrastructure. Their privacy policy applies to data processing on their end.
  • ip-api.com — Visitor IP addresses are sent to ip-api.com to derive an approximate geographic location. Their terms and privacy policy govern that request.

We do not integrate Google Analytics, advertising networks, or other third-party tracking services.

Your Rights

You can request access to, correction of, or deletion of your personal data at any time. To do so, please contact us. We will respond within a reasonable timeframe.

We don't have a formal legal compliance team. We are a small team and will handle requests in good faith.

Changes to This Policy

We may update this policy as the product evolves. When we do, we will update the "Last updated" date at the top. Continued use of the service after changes constitutes acceptance.

Contact

Questions about this policy? Get in touch.