# Privacy Policy

How formbase collects, uses, and protects personal data

## Privacy Policy

What personal data formbase collects, why we collect it, how we use it, and the choices you have over your information.

> ℹ️ **Last updated: 7 October 2026**
> <div>
>     <p>
>       This Privacy Policy explains how formbase handles personal data for everyone who visits our website, uses the product, or submits a
>       response to a form built on formbase. If you have any questions, contact us at{' '}
>       <a href="mailto:support@formbase.so">support@formbase.so</a>.
>     </p>
>   </div>

<h2 id="introduction">1. Introduction</h2>
formbase is a form builder. People use it to create surveys, applications, registrations, checkouts, and other interactive documents, and to
collect responses from their audiences. Personal data flows through the Service in two distinct ways: data that formbase collects about its
own users (the people who build forms), and data that respondents submit through forms built by those users.

This Privacy Policy describes both. We have tried to keep it short, plain, and honest. Where a section applies only to one group, we say so. Capitalized terms not defined here have the meanings set out in our [Terms of Service](/legal/terms-of-service). For data protection roles, references to "you" in this policy correspond to the "Customer" (and, under the GDPR, the "Controller") in our [Data Processing Agreement](/legal/dpa).

By using formbase, you acknowledge that we process personal data as described in this policy. If you do not agree, do not use the Service.

<h2 id="who-we-are">2. Who We Are</h2>
The Service is operated by **Formbase AS**, a Norwegian limited company with organisation number 937 921 217 and registered office in Oslo,
Norway ("formbase", "we", "us", "our"). For the personal data we collect about users of the Service — such as your account, billing, and
product usage data — formbase is the data controller.

For the personal data that respondents submit through your forms, **you** (the formbase user who built the form) are the data controller, and formbase acts as your data processor. The terms of that processing relationship are described in the [Data Processing Agreement](/legal/dpa), which applies automatically to customers subject to the GDPR or equivalent regimes. This Privacy Policy still tells respondents what formbase technically does with their data on your behalf, but it does not replace your own privacy notice.

For questions, complaints, or data subject requests, contact us at <a href="mailto:support@formbase.so">support@formbase.so</a>.

<h2 id="scope">3. Scope</h2>
This Privacy Policy covers personal data that formbase collects, uses, or shares when:

- You visit **formbase.so** or any of its subdomains;
- You sign up for, sign in to, or use **the formbase application** at app.formbase.so;
- You **submit a response** to a form that is hosted on formbase or embedded on another website;
- You **contact us** for support, sales, partnerships, or anything else;
- You read or interact with our **marketing emails, social channels, or events**.

It does not cover third-party websites, services, or integrations that we link to or that you choose to connect, even if they are reached from inside formbase. Those services have their own privacy policies, and you should review them.

<h2 id="data-we-collect">4. Personal Data We Collect</h2>
We try to collect only what we need. The categories below describe the personal data we may handle in different parts of the Service.

<h3 id="account-data">Account data</h3>
When you create a formbase account, we collect:

- Your **email address**, used to sign in and receive system messages.
- A **display name and avatar** if you set them, used to identify you to your collaborators.
- Authentication data linked to **sign-in methods** you choose, such as magic-link login, Google sign-in, or anonymous guest sign-in for short-lived guest sessions.
- **Workspace settings** you set up, including workspace name, timezone, and the list of members you have invited.

Your email address is a contractual requirement for using the Service — it is the only data required to register, and without it we cannot create your account. Display name, avatar, and workspace settings are optional.

<h3 id="billing-data">Subscription and billing data</h3>
formbase subscriptions and AI credit purchases are sold through **Polar** (polar.sh), our payment provider and Merchant of Record. Polar
collects and stores your payment details directly. formbase receives only the limited information needed to provision your plan and credits,
including:

- A Polar customer identifier linking your formbase account to your Polar customer record;
- A Polar subscription identifier and the chosen billing interval (monthly or annual);
- Subscription lifecycle timestamps such as the current period end, lapse, and grace-period markers used to apply your plan entitlements;
- Order and credit-top-up identifiers used to provision AI credits.

formbase does not see or store payment card details, tax identifiers, or billing addresses — Polar holds those records directly, and you can access them through the Polar billing portal. Where you accept respondent payments through the Payment field, Stripe collects all card data directly; formbase receives only non-sensitive references such as the last four digits.

<h3 id="form-content">Form content you create</h3>
The forms you build on formbase — including questions, copy, media, conditional logic, and styling — are stored on our infrastructure so we
can display them to respondents and let you edit them later. Form configuration is treated as Your Content under our [Terms of
Service](/legal/terms-of-service).

<h3 id="submission-data">Submission data from respondents</h3>
When someone submits a response to one of your forms, we store on your behalf:

- The **answers and uploads** the respondent provides, exactly as they entered them;
- A **submission timestamp**, the respondent's browser language, the workspace timezone (captured at submit), and identifiers that link the submission to your form;
- **Drafts and partial submissions** saved server-side while the respondent fills the form, plus timestamps used to power abandoned-response reminders (when you enable them);
- **Technical analytics signals** captured for every published form, including approximate country (derived from the respondent's timezone or the Cloudflare edge `CF-IPCountry` header), device type, browser, traffic source, and engagement duration;
- A **respondent-side visitor identifier** used to deduplicate form view and engagement counts — see [Cookies and Similar Storage](#cookies) for details;
- Where you use the Payment field, a reference to the **Stripe payment** the respondent completed (the card data itself is handled by Stripe, not by formbase).

Respondent IP addresses are processed transiently for rate limiting, Cloudflare Turnstile bot protection, and abuse prevention, and are not persisted alongside submissions.

You decide what fields to include and which of these technical signals to capture. You are the data controller for submissions — see [Section 2](#who-we-are) for data protection roles.

Form submissions may include special categories of personal data under Article 9 GDPR — such as health information, political opinions, or biometric data — depending on the questions you ask. As the controller, you are responsible for establishing a valid legal basis under Article 9(2) GDPR before collecting such data and for making any required disclosures to respondents.

<h3 id="usage-data">Product usage and device data</h3>
When you use the formbase application, we automatically collect:

- **Activity logs** such as which pages you load, what features you use, and when, used to operate the product, debug issues, and understand which features matter.
- **Device and browser data** such as user-agent, screen size, operating system, language, and approximate location derived from IP.
- **IP address**, used to deliver the Service, detect abuse, rate-limit, and meet security obligations.
- **Diagnostic data** such as error reports and performance traces when the application encounters a problem, used to diagnose and fix the issue.

<h3 id="cookies-data">Cookies and similar technologies</h3>
We use cookies and similar storage mechanisms to keep you signed in, remember your workspace and preferences, and secure the application. On
our website, analytics cookies are set only if you accept them. See [Cookies and Similar Storage](#cookies) for details and the choices you
have.

<h3 id="ai-data">AI feature data</h3>
When you use AI Features — such as AI-assisted form building, the AI skill picker, or AI chat for analysing submissions — we process:

- The **prompts** you send to the AI;
- The **context** the feature passes alongside the prompt, such as the structure of the form you are editing or submission data you explicitly share;
- The **outputs** the AI returns;
- **Credit consumption metadata**, so we can show your remaining balance and deduct usage correctly.

These inputs and outputs are sent to Amazon Bedrock to generate the response. We may add or change providers over time and will update this Privacy Policy and the subprocessor list in the [Data Processing Agreement](/legal/dpa) accordingly. See [AI Features](#ai) below for the contractual protections we have in place.

<h3 id="support-data">Support and communications data</h3>
When you email us, fill out a contact form, or chat with us, we keep the contents of the conversation, the contact details you provide, and
any context needed to assist you. Recordings and transcripts of demo calls, if applicable, are stored only with your prior consent.

<h3 id="sources">Where this data comes from</h3>
Most personal data comes directly from you. Some is received from Google (sign-in profile), Polar (billing metadata), Stripe (transaction
references, not card data), or derived from your IP address (approximate country for analytics).

<h2 id="how-we-use">5. How We Use Personal Data</h2>
We use personal data for the following purposes, and only when one of the legal bases in [Section 6](#legal-bases) applies.

We do **not** sell personal data, and we do not share personal data with advertisers or data brokers for advertising purposes. For AI data-handling and no-training commitments, see [Section 13](#ai).

<h2 id="legal-bases">6. Legal Bases for Processing</h2>
If you are in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with a similar regime, we process
personal data only when one of the following legal bases under the GDPR applies:

- **Contract** (Article 6(1)(b)) — providing the Service, managing your account, processing payments, operating AI Features, and providing support.
- **Legitimate interests** (Article 6(1)(f)) — where our interest does not override your rights. Specifically:
  - _Securing the Service_ — our interest in keeping formbase and its users safe from abuse, fraud, and attacks.
  - _Improving the product_ — our interest in understanding how formbase is used so we can make it better, relying on aggregated and de-identified data wherever possible.
  - _Service communications_ — our interest in telling you about changes to features you already use.
  - _Counting website visits_ — our interest in knowing how many people visit our website and which pages they view, measured without cookies as described in [Cookies and Similar Storage](#cookies).
- **Consent** (Article 6(1)(a)) — analytics cookies and session recordings on our website, and optional product data sharing. You can withdraw consent at any time, for example through Cookie settings in the website footer.
- **Legal obligation** (Article 6(1)(c)) — tax, accounting, sanctions, and other legal obligations.
- **Vital interests** (Article 6(1)(d)) — only in rare cases to protect someone's life or physical safety.

Where we rely on legitimate interests, you have the right to object, and we will reconsider on the basis of your specific situation.

<h2 id="sharing">7. How We Share Personal Data</h2>
We share personal data only when one of the following applies.

<h3 id="subprocessors">With subprocessors that help us run formbase</h3>
We rely on a small set of trusted third-party providers to deliver the Service. They process personal data only as needed to provide their
part of the Service, under contracts that require appropriate confidentiality and security measures. The core subprocessors include:

- **Convex** — application database and backend.
- **Cloudflare R2** — object storage for file uploads and signatures.
- **Cloudflare** — CDN, DNS, edge security, custom hostnames, and Turnstile bot protection.
- **Polar** — subscription billing and AI credit purchases (Merchant of Record; independent controller for buyer billing data).
- **Stripe** — respondent payment processing via Stripe Connect (independent controller for payment data).
- **Amazon Web Services (AWS)** — Amazon Bedrock for AI Features; Amazon SES for transactional and system emails, including abandoned-response reminders on Pro workspaces.
- **Axiom** — operational logs and monitoring.
- **PostHog** — analytics for our website and account sign-ups.
- **Unsplash** — image search API; selected images are stored in Cloudflare R2 and served from there.

The authoritative, up-to-date list of subprocessors, along with the categories of data each one processes and the regions in which they operate, is maintained in our [Data Processing Agreement](/legal/dpa).

<h3 id="integrations-share">With integrations you connect</h3>
When you connect a third-party service to formbase — such as a webhook endpoint, automation platform, spreadsheet, messaging tool, or CRM —
you authorise us to send the relevant data to that service on your behalf. We share only what is needed for the integration to work, and the
third party becomes responsible for the data once it receives it under its own terms and privacy policy.

<h3 id="collaborators-share">With your collaborators</h3>
If you invite people to your workspace, they will see your name, email, role, and the forms and submissions they have permission to access.
Workspace owners can change member access and request ownership reassignment through support; the available workspace roles are described in
[Section 5 of the Terms of Service](/legal/terms-of-service#workspaces).

<h3 id="legal-share">For legal and safety reasons</h3>
We may disclose personal data when we believe in good faith that disclosure is necessary to (a) comply with applicable law or a binding
order from a competent authority, (b) enforce our [Terms of Service](/legal/terms-of-service), (c) detect, prevent, or address fraud,
security, or technical issues, or (d) protect the rights, property, or safety of formbase, our users, respondents, or the public.

<h3 id="business-share">In a business transfer</h3>
If formbase is involved in a merger, acquisition, reorganisation, sale of assets, or insolvency, personal data may be transferred to the
relevant counterparties as part of that transaction. Any such transfer will be subject to applicable data protection law.

<h2 id="transfers">8. International Data Transfers</h2>
formbase is based in Norway, and we aim to minimise transfers outside the European Economic Area. Some of our subprocessors are located in,
or transfer data to, jurisdictions outside the EEA, including the United States and the United Kingdom.

When personal data leaves the EEA, we rely on Standard Contractual Clauses (SCCs) adopted under Decision (EU) 2021/914, the UK International Data Transfer Addendum, the Swiss FDPIC addendum, adequacy decisions, or the EU–US Data Privacy Framework (DPF), as applicable. We also apply encryption in transit and at rest, restricted access, and contractual data minimisation. The applicable transfer mechanism for each subprocessor is detailed in our [Data Processing Agreement](/legal/dpa#international-transfers).

<h2 id="retention">9. Data Retention</h2>
We keep personal data only as long as we need it for the purposes described in this policy and as required by law.

- **Account data** is kept while your account is active. When you ask us to delete your account, account records are removed from active systems shortly after the request is processed and remain in backups only until the corresponding backup window expires.
- **Form configuration and submissions** are kept while your workspace exists and you have not deleted them. Cancelling a Pro subscription moves you to the free tier; only **closing your account** triggers deletion. You can also configure a per-form submission retention period; submissions are automatically removed by a scheduled cleanup job when that period elapses.
- **Draft submissions** that a respondent starts but does not submit are kept for a limited period and then purged, unless you have configured a different retention.
- **Trashed forms** that you have moved to trash are permanently purged after a short grace period.
- **Anonymous (guest) sessions** created when you try formbase without an account are purged automatically within a short period.
- **Billing records** are kept for the period required by applicable accounting and tax law. Polar, as Merchant of Record, retains its own billing records under its own retention policy.
- **Support communications** sent to or from the formbase support inbox are kept as long as needed to resolve your request and handle any related legal claims.
- **Product usage and device data** — activity logs, device metadata, and diagnostics are retained in identifiable form for a limited period and then deleted or aggregated so that individual users can no longer be identified.
- **Operational and security logs** generated by the Service are kept for the period needed to operate, debug, and secure the Service. Where a specific incident requires a longer period, we restrict access and delete the logs as soon as the obligation expires.
- **Backups** are created on a regular schedule with a short retention window. File uploads stored in Cloudflare R2 are not covered by object versioning; deletions of file uploads are unrecoverable immediately. Personal data deleted from production becomes unrecoverable once the corresponding backup window expires.

- **AI prompts and outputs** sent to Amazon Bedrock are not stored by AWS after the request is processed and are not used to train any models, as described in the [AWS Service Terms](https://aws.amazon.com/service-terms/).

If law requires us to keep a record for longer — for example to meet a tax, anti-money-laundering, or court-order obligation — we restrict access to that record and delete it as soon as the obligation expires.

<h2 id="security">10. Security</h2>
We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss,
alteration, unauthorised disclosure, and unauthorised access. These measures include:

- Encryption of personal data **in transit** using TLS 1.2 or higher, and **at rest** using industry-standard algorithms;
- **Access controls** based on least privilege, with internal access to production systems restricted on a need-to-know basis;
- **Logging and monitoring** of administrative actions in production systems;
- **Network segmentation** and isolation of production from development environments;
- **Vulnerability management**, including timely application of security updates and a responsible disclosure channel at <a href="mailto:support@formbase.so">support@formbase.so</a>;
- **Access controls** limiting production access to authorised personnel.

No system is perfectly secure. If you become aware of a vulnerability or a possible compromise, report it to <a href="mailto:support@formbase.so">support@formbase.so</a>.

<h2 id="rights">11. Your Rights</h2>
Depending on where you live, you may have the following rights over the personal data we hold about you. Many of these are guaranteed under
the GDPR, the UK GDPR, and equivalent laws in other jurisdictions.

- **Right of access** — ask for a copy of the personal data we hold about you and information about how it is processed.
- **Right to rectification** — ask us to correct inaccurate or incomplete data.
- **Right to erasure** — ask us to delete personal data when there is no overriding reason to keep it. You can also close your account and delete most of your data yourself from the product.
- **Right to restriction** — ask us to pause processing in certain situations, for example while we check a correction or objection.
- **Right to data portability** — receive your personal data in a structured, commonly used, machine-readable format, or have it sent to another controller. The export feature in the application covers most of this for forms and submissions, with CSV and Excel (XLSX) output.
- **Right to object** — object to processing based on legitimate interests, including profiling, and to direct marketing at any time.
- **Right to withdraw consent** — where we rely on your consent, you can withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
- **Right not to be subject to a decision based solely on automated processing** (Article 22 GDPR) — we do not make decisions about you that produce legal or similarly significant effects through solely automated processing, including profiling.

To exercise any of these rights, email <a href="mailto:support@formbase.so">support@formbase.so</a> or use the self-service options in the application where available. We will respond within one month, or tell you why we need more time. We may ask for information to verify your identity before acting on a request, especially for access or deletion.

If you are unhappy with how we have handled your data, you can lodge a complaint with a supervisory authority — for users in Norway, the **Norwegian Data Protection Authority** (Datatilsynet, <a href="https://datatilsynet.no">datatilsynet.no</a>). You can also complain to the authority in the EEA country where you live or work.

<h3 id="respondent-rights">Rights of respondents</h3>
If you are a respondent who submitted a form built on formbase, your data subject rights run primarily against the formbase user who built
that form — they are the data controller. We can help you reach them, and we will support them in responding to your request. Where we hold
the underlying data as a processor on their behalf, we will act on their documented instructions. To contact us, write to
<a href="mailto:support@formbase.so">support@formbase.so</a> and tell us which form you submitted (the URL is usually enough).

<h2 id="cookies">12. Cookies and Similar Storage</h2>
We use a small number of cookies, `localStorage`, and `sessionStorage` entries to make formbase work and to deduplicate analytics on your
forms. We try to keep the list short.

- **Strictly necessary** — keep you signed in, remember the workspace you last used, secure the application against cross-site request forgery, and store essential preferences. These cannot be disabled without breaking the product.
- **Functional** — remember UI preferences such as theme, sidebar state, and language. You can clear them from your browser.
- **Analytics on our website (formbase.so and formbase.no)** — PostHog, our analytics provider, counts every visit without storing anything on your device. Its servers combine your IP address and browser user agent with a random value that changes every day and is then deleted, so a visit can't be linked to your visits on other days. Only if you accept in the cookie banner does PostHog also set a cookie (`ph_*_posthog`) and `localStorage` entries that identify your browser, and record your visits as session replays. Your choice is stored in `localStorage` (`fb_analytics_consent`) so we don't ask on every page. You can change it at any time through **Cookie settings** in the website footer; withdrawing deletes what PostHog stored.
- **Analytics on hosted form pages** — a random visitor identifier (`fb_visitor_id`) in `localStorage`, plus short-lived `sessionStorage` flags (`fb_viewed`, `fb_engaged`), used to deduplicate view and engagement counts. This storage is not needed for the form to function and does not enable advertising, cross-site tracking, or profiling. formbase places this storage as a data processor on your instructions as controller. If your respondents are in jurisdictions where prior consent is required for non-essential storage (such as the EEA under the ePrivacy Directive or Norway under Ekomloven § 3-15), you are responsible for obtaining that consent before the form page loads.

We do not use cookies or similar storage to track respondents across other websites for advertising, and we do not place advertising cookies on hosted form pages. You can clear cookies, `localStorage`, and `sessionStorage` through your browser settings. Blocking strictly necessary cookies or storage may prevent parts of the Service from working.

If you build forms on formbase, your hosted forms will set `fb_visitor_id` in `localStorage` on respondent devices as described above. You should disclose this in your own privacy notice to respondents.

<h2 id="ai">13. AI Features</h2>
Prompts and context you submit through formbase AI Features are sent to Amazon Bedrock. Context includes, where applicable, the structure of
the form you are editing and submission samples you explicitly share for analysis or summarisation. We configure it so that, under the AWS
Service Terms, inputs and outputs are not used to train any models and are not stored by AWS after the request is processed. Processing is
in line with the security and data protection commitments in this Privacy Policy and the [Data Processing Agreement](/legal/dpa).

AI outputs are generated probabilistically and may be inaccurate, incomplete, or out of date. You are responsible for reviewing every AI-generated output before you rely on it, publish it, or send it to respondents.

You should not submit personal data, secrets, or other sensitive information through AI Features unless you have a lawful basis to share that information with our subprocessors and have considered the risks. We do not control how providers respond to lawful government requests directed at them.

<h2 id="children">14. Children</h2>
formbase is not designed for children. You must be at least sixteen (16) years old to create a formbase account, as described in our [Terms
of Service](/legal/terms-of-service).

formbase users may build forms intended for younger audiences. If you collect personal data from children through formbase, you are responsible for obtaining any required parental or guardian consent and for handling that data in accordance with applicable law, including COPPA where relevant. [Section 6 of the Terms of Service](/legal/terms-of-service#acceptable-use) lists sensitive data classes the Service is not designed for, and [Section 7](/legal/terms-of-service#prohibited-uses) sets out prohibited uses, including content that exploits or endangers minors.

We do not knowingly collect personal data from children under sixteen (16) (or under thirteen (13) where COPPA sets a lower threshold). If you believe we have inadvertently collected personal data from a child below the applicable age threshold without the required consent, contact us at <a href="mailto:support@formbase.so">support@formbase.so</a> and we will delete it without undue delay.

<h2 id="marketing">15. Communications</h2>
We send two kinds of email:

- **System emails** about your account, security, billing, and the forms you build. These are part of the Service and cannot be opted out of while your account is active.
- **Service announcements** about changes to the product, policies, or features you rely on. We keep these to the minimum needed to keep you informed.

<h2 id="california">16. Notice for California Residents</h2>
If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the
California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete it, the right to
correct inaccuracies, and the right to opt out of the "sale" or "sharing" of personal information.

formbase does not sell personal information and does not share personal information for cross-context behavioural advertising. Because no sale or sharing occurs, no "Do Not Sell or Share My Personal Information" link is required or provided.

The categories of personal information we collect, purposes, and retention periods are described in [Section 4](#data-we-collect), [Section 5](#how-we-use), and [Section 9](#retention). We do not build behavioural profiles for advertising and do not use sensitive personal information for inferences or profiling.

To exercise your rights — including the right to know, delete, correct, opt out, or limit sensitive personal information — write to <a href="mailto:support@formbase.so">support@formbase.so</a>. We will not discriminate against you for exercising any of these rights.

<h2 id="changes">17. Changes to This Privacy Policy</h2>
We may update this Privacy Policy from time to time to reflect changes to the Service, our subprocessors, applicable law, or business
practices. The "Last updated" date at the top of this policy shows when it was most recently revised.

If you continue to use the Service after a change takes effect, you accept the updated Privacy Policy. If you do not agree to a change, you can close your account before it takes effect.

<h2 id="contact">18. Contact Us</h2>
For privacy questions, data subject requests, or anything else related to this policy, contact us at:

- **Privacy questions, data subject requests, and security reports** — <a href="mailto:support@formbase.so">support@formbase.so</a>

formbase has not appointed a Data Protection Officer. Our privacy team monitors the <a href="mailto:support@formbase.so">support@formbase.so</a> inbox and will route your request appropriately.

<h2 id="related">Related documents</h2>

<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Terms of Service](/legal/terms-of-service) — The rules that govern your use of formbase.
  - [Data Processing Agreement](/legal/dpa) — Terms for processing personal data on your behalf.
  - [Legal overview](/legal/overview) — Index of formbase legal documents.
</div>
