Privacy Policy
Last updated: February 24, 2026
Overview
Formalingo is an AI-powered form and document platform. This policy explains what information we collect, why we collect it, and how we handle it. We aim to be direct and honest — we won't claim practices we don't follow.
Information We Collect
Creator Accounts
When you create an account you provide an email address and password. We store your email in plain text and your password as a bcrypt hash — we never store your password in readable form.
Form Responses
When a respondent submits a form, we store the answers they provide. Respondents do not need an account — they are identified by a unique, randomly generated token tied to their submission link.
Visit Tracking
When someone visits a form link, we record:
- IP address (stored in full; displayed in the dashboard in masked form, e.g.
84.109.x.x) - User-agent string (browser and OS details, parsed via ua-parser-js)
- Approximate geographic location derived from the IP address via the ip-api.com service
- Timestamp of the visit
This data is made available to the form creator in their analytics dashboard. It is not sold or shared with third parties beyond what is described in this policy.
How We Use Your Information
- To operate the service — authenticate creators, display form responses, send form links
- To provide analytics to form creators (visit counts, device breakdown, geographic data)
- To improve the security and reliability of the platform
We do not use your data to train AI models or for advertising.
Data Retention
Form responses and visit data are retained as long as the form exists. When a form is permanently deleted, its associated response and visit data is deleted too.
Account data is retained until you request account deletion.
Cookies
We use a single session cookie (form_session_*) for form respondents. It is HttpOnly, lasts 24 hours, and is required for the form-filling experience. We do not use advertising cookies, analytics cookies, or any cross-site tracking.
See our Cookie Policy for full details.
Third-Party Services
- Supabase — We use Supabase for database storage, file storage, and authentication. Data is stored on Supabase infrastructure. Their privacy policy applies to data processing on their end.
- ip-api.com — Visitor IP addresses are sent to ip-api.com to derive an approximate geographic location. Their terms and privacy policy govern that request.
We do not integrate Google Analytics, advertising networks, or other third-party tracking services.
Your Rights
You can request access to, correction of, or deletion of your personal data at any time. To do so, please contact us. We will respond within a reasonable timeframe.
We don't have a formal legal compliance team. We are a small team and will handle requests in good faith.
Changes to This Policy
We may update this policy as the product evolves. When we do, we will update the "Last updated" date at the top. Continued use of the service after changes constitutes acceptance.
Contact
Questions about this policy? Get in touch.