Privacy Policy

Last updated: February 21, 2026

Welcome to Formfex! This Privacy Policy explains how Ultronite LLC collects, uses, discloses, and safeguards your information when you use the Formfex web application and related services.

By using Formfex, you agree to the terms of this Privacy Policy. If you do not agree with these terms, please do not use our application.

Key Terms

  • "We," "our," or "us" refers to Ultronite LLC
  • "You" or "your" refers to the user of Formfex
  • "Personal Data" refers to any information that identifies or can be used to identify a person
  • "Form Content" refers to your forms, form schemas, form responses, templates, AI-generated content, and analytics reports

1. What Data We Collect

Account & Profile Information

  • Name and email address
  • Authentication credentials (hashed and encrypted)
  • Google ID (for Google Sign-In users)
  • Account preferences and settings

Form Data

  • Form titles and form schemas (fields, sections, settings, validation rules)
  • Form publishing status and visibility settings
  • Share URLs and embed configurations
  • Form expiry dates
  • Creation and modification timestamps

Form Response Data

  • Responses submitted by form respondents (all field values as structured data)
  • Respondent email addresses (only when OTP verification is enabled for private forms)
  • Submission timestamps

AI-Generated Content (Optional Feature)

When you use our AI-powered features:

  • Text prompts you provide for form generation
  • Uploaded PDF documents used for AI-based form generation (RAG)
  • AI chat history for conversational form refinement
  • AI-generated form schemas and translations
  • Smart Analytics reports (AI-generated analysis of form responses)
  • Analytics Chat conversations (stored locally in your browser only, not on our servers)
  • Token usage and credit consumption data

Form Access Control Data

  • Whitelisted email addresses for private forms
  • OTP session data (hashed OTP codes, email, verification attempts) — temporary, deleted after verification

Subscription & Billing Data

  • Subscription plan type (Free, Starter, Pro, Max)
  • Subscription status and billing period
  • AI credit balance and usage counters
  • Stripe customer and subscription identifiers (we do not store credit card numbers or payment details)

Template Data

  • User-created form templates (title, description, category, schema)

Security & Authentication Logs

  • Authentication events (login attempts, token refreshes, account deletions)
  • Event metadata for security monitoring (no passwords or tokens are logged)

2. How We Use Your Data

Core App Functionality

  • Create, edit, and manage your forms with drag-and-drop builder
  • Generate forms from natural language prompts using AI
  • Generate forms from uploaded PDF documents using AI
  • Translate forms into different languages using AI
  • Publish and share forms via links or embed codes
  • Collect and store form responses from respondents
  • Provide form analytics dashboards (response counts, growth charts, per-question breakdowns)
  • Generate AI-powered Smart Analytics reports
  • Provide conversational AI for querying form response data
  • Manage form templates (system and personal)
  • Process OTP verification for private form access

App Improvement

  • Analyze application performance and fix bugs
  • Understand feature usage patterns
  • Develop new features based on usage trends

Communication

  • Send transactional emails (account verification OTP, password reset links, form access OTP codes)
  • Provide customer support

3. Data Storage & Security

Where Your Data Lives

  • Form Content & Responses: Stored in cloud-hosted PostgreSQL database with encryption
  • Authentication: Token-based authentication with securely hashed passwords and refresh tokens
  • AI Processing: Processed by third-party AI service providers when you use AI features
  • Smart Analytics Reports: Generated PDF reports and analysis data stored in secure cloud storage
  • Browser Storage: Authentication tokens stored in secure httpOnly cookies

Security Measures

  • Industry-standard hashing for passwords and authentication tokens
  • Short-lived access tokens and secure refresh token rotation
  • SSL/TLS encryption for all network communications
  • Rate limiting and request throttling
  • Automated bot protection on registration and form submission endpoints
  • Security headers to prevent common web attacks
  • Graceful account deletion with email obfuscation and data retained briefly before permanent removal
  • Time-limited, signed URLs for secure report access

Your Data Rights

  • You can export your form response data (CSV/Excel) at any time
  • You can delete individual forms, responses, or your entire account
  • Account deletion removes your data from our systems

3A. Cookies & Local Storage

What We Use

  • httpOnly Cookies: We use httpOnly cookies to store authentication tokens (access token and refresh token). These cookies are not accessible to client-side JavaScript and are used solely for session management.

What We Do Not Use

  • No third-party tracking cookies
  • No analytics cookies
  • No advertising cookies

4. Third-Party Services

We work with trusted third-party service providers to deliver and operate Formfex. These providers are contractually obligated to protect your data and only use it for the purposes we specify.

Cloud Infrastructure & Hosting — Google Cloud Platform

We use Google Cloud Platform (Cloud Run, Cloud Storage, Cloud Tasks) to host our application, store data, and process background tasks. Your form content, responses, and generated reports are stored securely on these platforms.

AI Processing — Google Gemini

When you use AI-powered features (form generation, translation, Smart Analytics, Analytics Chat), your prompts, form data, and uploaded documents are sent to Google Gemini (via Google AI) for processing. Your data is processed in real-time and is not used to train AI models. For more information, refer to Google's AI data usage policy.

AI features are optional. Core form building and response collection work without AI.

Payment Processing — Stripe

Subscription billing and payment processing are handled by Stripe, a PCI-compliant payment processor. We share only the minimum information needed to manage your subscription (user identifier, plan type, billing period).

All payment card details are handled exclusively by Stripe. We never store credit card numbers or payment method details in our systems.

Email Delivery — Resend

We use Resend to send transactional emails such as account verification codes, password reset links, and form access codes. Only your email address and name are shared with this provider.

We only send transactional emails necessary for account security and functionality. We do not send marketing emails.

Authentication & Bot Protection — Google Sign-In & Google reCAPTCHA

We offer Google Sign-In for your convenience. When you use social sign-in, we receive basic profile information (name, email) from Google.

We also use Google reCAPTCHA on registration and form submission pages to prevent abuse and spam.

Database Services — Neon (PostgreSQL)

All application data (user accounts, forms, responses, and subscription information) is stored in a managed, encrypted PostgreSQL database hosted by Neon.

5. Data Sharing

We do not sell your personal data. We do not use any third-party analytics or advertising trackers.

We may share data with:

  • Service providers for app functionality (as described in Section 4)
  • Law enforcement if required by valid legal process
  • Business transfer in case of merger or acquisition

We do not currently respond to Do Not Track (DNT) browser signals as there is no industry standard for compliance. However, we do not track users across third-party websites.

6. Your Privacy Rights

Access & Control

  • View and export your form responses (CSV/Excel)
  • Edit or delete any form, response, or template
  • Delete your entire account and all associated data
  • Correct any inaccurate profile information

Communication Preferences

Transactional emails (account verification, password reset, form access OTP) are required for app functionality and cannot be opted out of while your account is active.

Data Deletion

To delete your account:

  1. Go to your Profile settings
  2. Select "Delete Account"
  3. Confirm deletion

Upon deletion:

  • Your email is obfuscated and account is soft-deleted
  • Your Stripe subscription is cancelled
  • Your Smart Analytics reports are deleted from cloud storage
  • Your data is permanently removed within 30 days

7. Data Retention

Active Accounts

  • Form content and responses: Retained as long as your account is active
  • Authentication data: Until account deletion
  • AI job records: Retained for credit accounting and history

After Account Deletion

  • Account and form data: Permanently deleted within 30 days
  • Authentication logs: May be retained for security audit purposes
  • Legal obligations: Data may be retained as required by law

7A. Data Breach Notification

In the event of a data breach that compromises your personal data, we will:

  • Notify affected users via email within 72 hours of discovering the breach
  • Notify applicable law enforcement and regulatory authorities as required by law
  • Provide a description of the nature of the breach, the categories and approximate number of data records affected, and the measures taken or proposed to address the breach

8. Children's Privacy

Formfex is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover such data has been collected, we will delete it immediately.

Users aged 13–17 should have parental consent before using the application.

9. International Data Transfers

Your data may be processed in the following regions where our service providers operate:

  • United States: Primary application hosting and data processing
  • European Union (europe-west1): Select infrastructure services via Google Cloud Platform

For transfers of personal data from the European Economic Area (EEA) or United Kingdom to countries outside those regions, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Our infrastructure providers, including Google Cloud Platform, maintain industry-recognized compliance certifications (SOC 2, ISO 27001) to ensure appropriate data protection safeguards.

10. California Residents (CCPA)

You have the right to:

  • Know what personal information we collect
  • Delete your personal information
  • Opt-out of the sale of personal information (we don't sell data)
  • Non-discrimination for exercising privacy rights

11. EU/UK Residents (GDPR)

You have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing of your data
  • Data portability
  • Object to data processing
  • Withdraw consent at any time

Legal Basis for Processing

  • Consent: For optional features like AI form generation, Smart Analytics, and Analytics Chat
  • Contract: For core form building, response collection, and account management
  • Legitimate interests: For application improvement and security

To exercise your rights or file a complaint, contact us or your local data protection authority.

12. Changes to This Policy

We may update this Privacy Policy to reflect new features or legal requirements. We'll notify you of significant changes via email or in-app notification.

13. Contact Us

For privacy questions or to exercise your rights:

Ultronite LLC
30 N Gould St Ste R, Sheridan, WY 82801
Email: support@formfex.com

For technical support: support@formfex.com

FormfexFormfex

Yapay zeka ile daha akıllı formlar oluşturun.

Ürün

HakkındaÖzelliklerŞablonlarKarşılaştırFiyatlandırmaYardımDokümanlar

Form Türleri

İletişim FormuAnketGeri Bildirim FormuKayıt FormuBaşvuru Formuİş Başvuru FormuSipariş FormuQuiz

Sektörler

SağlıkEğitimE-ticaretİK ve İşe AlımPazarlamaEtkinliklerGayrimenkulRestoranlar

Yasal

Gizlilik PolitikasıKullanım Şartlarıİletişim
© 2026 Ultronite LLC. Tüm hakları saklıdır.