formbasedocs
Go to appApp

Legal

Privacy Policy

What personal data formbase collects, why we collect it, how we use it, and the choices you have over your information.


Last updated: 7 October 2026

This Privacy Policy explains how formbase handles personal data for everyone who visits our website, uses the product, or submits a response to a form built on formbase. If you have any questions, contact us at support@formbase.so.

1. Introduction

formbase is a form builder. People use it to create surveys, applications, registrations, checkouts, and other interactive documents, and to collect responses from their audiences. Personal data flows through the Service in two distinct ways: data that formbase collects about its own users (the people who build forms), and data that respondents submit through forms built by those users.

This Privacy Policy describes both. We have tried to keep it short, plain, and honest. Where a section applies only to one group, we say so. Capitalized terms not defined here have the meanings set out in our Terms of Service. For data protection roles, references to “you” in this policy correspond to the “Customer” (and, under the GDPR, the “Controller”) in our Data Processing Agreement.

By using formbase, you acknowledge that we process personal data as described in this policy. If you do not agree, do not use the Service.

2. Who We Are

The Service is operated by Formbase AS, a Norwegian limited company with organisation number 937 921 217 and registered office in Oslo, Norway (“formbase”, “we”, “us”, “our”). For the personal data we collect about users of the Service — such as your account, billing, and product usage data — formbase is the data controller.

For the personal data that respondents submit through your forms, you (the formbase user who built the form) are the data controller, and formbase acts as your data processor. The terms of that processing relationship are described in the Data Processing Agreement, which applies automatically to customers subject to the GDPR or equivalent regimes. This Privacy Policy still tells respondents what formbase technically does with their data on your behalf, but it does not replace your own privacy notice.

For questions, complaints, or data subject requests, contact us at support@formbase.so.

3. Scope

This Privacy Policy covers personal data that formbase collects, uses, or shares when:

  • You visit formbase.so or any of its subdomains;
  • You sign up for, sign in to, or use the formbase application at app.formbase.so;
  • You submit a response to a form that is hosted on formbase or embedded on another website;
  • You contact us for support, sales, partnerships, or anything else;
  • You read or interact with our marketing emails, social channels, or events.

It does not cover third-party websites, services, or integrations that we link to or that you choose to connect, even if they are reached from inside formbase. Those services have their own privacy policies, and you should review them.

4. Personal Data We Collect

We try to collect only what we need. The categories below describe the personal data we may handle in different parts of the Service.

Account data

When you create a formbase account, we collect:

  • Your email address, used to sign in and receive system messages.
  • A display name and avatar if you set them, used to identify you to your collaborators.
  • Authentication data linked to sign-in methods you choose, such as magic-link login, Google sign-in, or anonymous guest sign-in for short-lived guest sessions.
  • Workspace settings you set up, including workspace name, timezone, and the list of members you have invited.

Your email address is a contractual requirement for using the Service — it is the only data required to register, and without it we cannot create your account. Display name, avatar, and workspace settings are optional.

Subscription and billing data

formbase subscriptions and AI credit purchases are sold through Polar (polar.sh), our payment provider and Merchant of Record. Polar collects and stores your payment details directly. formbase receives only the limited information needed to provision your plan and credits, including:

  • A Polar customer identifier linking your formbase account to your Polar customer record;
  • A Polar subscription identifier and the chosen billing interval (monthly or annual);
  • Subscription lifecycle timestamps such as the current period end, lapse, and grace-period markers used to apply your plan entitlements;
  • Order and credit-top-up identifiers used to provision AI credits.

formbase does not see or store payment card details, tax identifiers, or billing addresses — Polar holds those records directly, and you can access them through the Polar billing portal. Where you accept respondent payments through the Payment field, Stripe collects all card data directly; formbase receives only non-sensitive references such as the last four digits.

Form content you create

The forms you build on formbase — including questions, copy, media, conditional logic, and styling — are stored on our infrastructure so we can display them to respondents and let you edit them later. Form configuration is treated as Your Content under our Terms of Service.

Submission data from respondents

When someone submits a response to one of your forms, we store on your behalf:

  • The answers and uploads the respondent provides, exactly as they entered them;
  • A submission timestamp, the respondent’s browser language, the workspace timezone (captured at submit), and identifiers that link the submission to your form;
  • Drafts and partial submissions saved server-side while the respondent fills the form, plus timestamps used to power abandoned-response reminders (when you enable them);
  • Technical analytics signals captured for every published form, including approximate country (derived from the respondent’s timezone or the Cloudflare edge CF-IPCountry header), device type, browser, traffic source, and engagement duration;
  • A respondent-side visitor identifier used to deduplicate form view and engagement counts — see Cookies and Similar Storage for details;
  • Where you use the Payment field, a reference to the Stripe payment the respondent completed (the card data itself is handled by Stripe, not by formbase).

Respondent IP addresses are processed transiently for rate limiting, Cloudflare Turnstile bot protection, and abuse prevention, and are not persisted alongside submissions.

You decide what fields to include and which of these technical signals to capture. You are the data controller for submissions — see Section 2 for data protection roles.

Form submissions may include special categories of personal data under Article 9 GDPR — such as health information, political opinions, or biometric data — depending on the questions you ask. As the controller, you are responsible for establishing a valid legal basis under Article 9(2) GDPR before collecting such data and for making any required disclosures to respondents.

Product usage and device data

When you use the formbase application, we automatically collect:

  • Activity logs such as which pages you load, what features you use, and when, used to operate the product, debug issues, and understand which features matter.
  • Device and browser data such as user-agent, screen size, operating system, language, and approximate location derived from IP.
  • IP address, used to deliver the Service, detect abuse, rate-limit, and meet security obligations.
  • Diagnostic data such as error reports and performance traces when the application encounters a problem, used to diagnose and fix the issue.

Cookies and similar technologies

We use cookies and similar storage mechanisms to keep you signed in, remember your workspace and preferences, and secure the application. On our website, analytics cookies are set only if you accept them. See Cookies and Similar Storage for details and the choices you have.

AI feature data

When you use AI Features — such as AI-assisted form building, the AI skill picker, or AI chat for analysing submissions — we process:

  • The prompts you send to the AI;
  • The context the feature passes alongside the prompt, such as the structure of the form you are editing or submission data you explicitly share;
  • The outputs the AI returns;
  • Credit consumption metadata, so we can show your remaining balance and deduct usage correctly.

These inputs and outputs are sent to Amazon Bedrock to generate the response. We may add or change providers over time and will update this Privacy Policy and the subprocessor list in the Data Processing Agreement accordingly. See AI Features below for the contractual protections we have in place.

Support and communications data

When you email us, fill out a contact form, or chat with us, we keep the contents of the conversation, the contact details you provide, and any context needed to assist you. Recordings and transcripts of demo calls, if applicable, are stored only with your prior consent.

Where this data comes from

Most personal data comes directly from you. Some is received from Google (sign-in profile), Polar (billing metadata), Stripe (transaction references, not card data), or derived from your IP address (approximate country for analytics).

5. How We Use Personal Data

We use personal data for the following purposes, and only when one of the legal bases in Section 6 applies.

PurposeWhat this means in practice
Provide the ServiceRun formbase, show your forms to respondents, store submissions, send notifications, run integrations you enable, and apply your settings.
Manage your accountCreate your account, authenticate you, route you to the right workspace, manage roles and permissions, and apply plan entitlements.
Process paymentsProvision Pro features, top up AI credits, reconcile invoices issued by Polar, and handle billing support requests.
Operate AI FeaturesSend the prompts and context you submit to our LLM subprocessors, return their outputs to you, and meter your AI credit usage.
Secure the ServiceDetect and prevent abuse, fraud, spam, account takeover, and other attacks, and investigate incidents when they occur.
Support youRespond to your questions, debug issues you report, and keep a record of the conversation so we can follow up.
Improve the productUnderstand which features are used, how the product performs, and where it breaks, so we can make it better. We rely on aggregated and de-identified data wherever possible.
Communicate with youSend system emails (account, billing, security) and service announcements.
Comply with lawMeet our legal obligations, respond to lawful requests from authorities, exercise or defend legal claims, and enforce our Terms.

We do not sell personal data, and we do not share personal data with advertisers or data brokers for advertising purposes. For AI data-handling and no-training commitments, see Section 13.

If you are in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with a similar regime, we process personal data only when one of the following legal bases under the GDPR applies:

  • Contract (Article 6(1)(b)) — providing the Service, managing your account, processing payments, operating AI Features, and providing support.
  • Legitimate interests (Article 6(1)(f)) — where our interest does not override your rights. Specifically:
    • Securing the Service — our interest in keeping formbase and its users safe from abuse, fraud, and attacks.
    • Improving the product — our interest in understanding how formbase is used so we can make it better, relying on aggregated and de-identified data wherever possible.
    • Service communications — our interest in telling you about changes to features you already use.
    • Counting website visits — our interest in knowing how many people visit our website and which pages they view, measured without cookies as described in Cookies and Similar Storage.
  • Consent (Article 6(1)(a)) — analytics cookies and session recordings on our website, and optional product data sharing. You can withdraw consent at any time, for example through Cookie settings in the website footer.
  • Legal obligation (Article 6(1)(c)) — tax, accounting, sanctions, and other legal obligations.
  • Vital interests (Article 6(1)(d)) — only in rare cases to protect someone’s life or physical safety.

Where we rely on legitimate interests, you have the right to object, and we will reconsider on the basis of your specific situation.

7. How We Share Personal Data

We share personal data only when one of the following applies.

With subprocessors that help us run formbase

We rely on a small set of trusted third-party providers to deliver the Service. They process personal data only as needed to provide their part of the Service, under contracts that require appropriate confidentiality and security measures. The core subprocessors include:

  • Convex — application database and backend.
  • Cloudflare R2 — object storage for file uploads and signatures.
  • Cloudflare — CDN, DNS, edge security, custom hostnames, and Turnstile bot protection.
  • Polar — subscription billing and AI credit purchases (Merchant of Record; independent controller for buyer billing data).
  • Stripe — respondent payment processing via Stripe Connect (independent controller for payment data).
  • Amazon Web Services (AWS) — Amazon Bedrock for AI Features; Amazon SES for transactional and system emails, including abandoned-response reminders on Pro workspaces.
  • Axiom — operational logs and monitoring.
  • PostHog — analytics for our website and account sign-ups.
  • Unsplash — image search API; selected images are stored in Cloudflare R2 and served from there.

The authoritative, up-to-date list of subprocessors, along with the categories of data each one processes and the regions in which they operate, is maintained in our Data Processing Agreement.

With integrations you connect

When you connect a third-party service to formbase — such as a webhook endpoint, automation platform, spreadsheet, messaging tool, or CRM — you authorise us to send the relevant data to that service on your behalf. We share only what is needed for the integration to work, and the third party becomes responsible for the data once it receives it under its own terms and privacy policy.

With your collaborators

If you invite people to your workspace, they will see your name, email, role, and the forms and submissions they have permission to access. Workspace owners can change member access and request ownership reassignment through support; the available workspace roles are described in Section 5 of the Terms of Service.

We may disclose personal data when we believe in good faith that disclosure is necessary to (a) comply with applicable law or a binding order from a competent authority, (b) enforce our Terms of Service, (c) detect, prevent, or address fraud, security, or technical issues, or (d) protect the rights, property, or safety of formbase, our users, respondents, or the public.

In a business transfer

If formbase is involved in a merger, acquisition, reorganisation, sale of assets, or insolvency, personal data may be transferred to the relevant counterparties as part of that transaction. Any such transfer will be subject to applicable data protection law.

8. International Data Transfers

formbase is based in Norway, and we aim to minimise transfers outside the European Economic Area. Some of our subprocessors are located in, or transfer data to, jurisdictions outside the EEA, including the United States and the United Kingdom.

When personal data leaves the EEA, we rely on Standard Contractual Clauses (SCCs) adopted under Decision (EU) 2021/914, the UK International Data Transfer Addendum, the Swiss FDPIC addendum, adequacy decisions, or the EU–US Data Privacy Framework (DPF), as applicable. We also apply encryption in transit and at rest, restricted access, and contractual data minimisation. The applicable transfer mechanism for each subprocessor is detailed in our Data Processing Agreement.

9. Data Retention

We keep personal data only as long as we need it for the purposes described in this policy and as required by law.

  • Account data is kept while your account is active. When you ask us to delete your account, account records are removed from active systems shortly after the request is processed and remain in backups only until the corresponding backup window expires.

  • Form configuration and submissions are kept while your workspace exists and you have not deleted them. Cancelling a Pro subscription moves you to the free tier; only closing your account triggers deletion. You can also configure a per-form submission retention period; submissions are automatically removed by a scheduled cleanup job when that period elapses.

  • Draft submissions that a respondent starts but does not submit are kept for a limited period and then purged, unless you have configured a different retention.

  • Trashed forms that you have moved to trash are permanently purged after a short grace period.

  • Anonymous (guest) sessions created when you try formbase without an account are purged automatically within a short period.

  • Billing records are kept for the period required by applicable accounting and tax law. Polar, as Merchant of Record, retains its own billing records under its own retention policy.

  • Support communications sent to or from the formbase support inbox are kept as long as needed to resolve your request and handle any related legal claims.

  • Product usage and device data — activity logs, device metadata, and diagnostics are retained in identifiable form for a limited period and then deleted or aggregated so that individual users can no longer be identified.

  • Operational and security logs generated by the Service are kept for the period needed to operate, debug, and secure the Service. Where a specific incident requires a longer period, we restrict access and delete the logs as soon as the obligation expires.

  • Backups are created on a regular schedule with a short retention window. File uploads stored in Cloudflare R2 are not covered by object versioning; deletions of file uploads are unrecoverable immediately. Personal data deleted from production becomes unrecoverable once the corresponding backup window expires.

  • AI prompts and outputs sent to Amazon Bedrock are not stored by AWS after the request is processed and are not used to train any models, as described in the AWS Service Terms.

If law requires us to keep a record for longer — for example to meet a tax, anti-money-laundering, or court-order obligation — we restrict access to that record and delete it as soon as the obligation expires.

10. Security

We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. These measures include:

  • Encryption of personal data in transit using TLS 1.2 or higher, and at rest using industry-standard algorithms;
  • Access controls based on least privilege, with internal access to production systems restricted on a need-to-know basis;
  • Logging and monitoring of administrative actions in production systems;
  • Network segmentation and isolation of production from development environments;
  • Vulnerability management, including timely application of security updates and a responsible disclosure channel at support@formbase.so;
  • Access controls limiting production access to authorised personnel.

No system is perfectly secure. If you become aware of a vulnerability or a possible compromise, report it to support@formbase.so.

11. Your Rights

Depending on where you live, you may have the following rights over the personal data we hold about you. Many of these are guaranteed under the GDPR, the UK GDPR, and equivalent laws in other jurisdictions.

  • Right of access — ask for a copy of the personal data we hold about you and information about how it is processed.
  • Right to rectification — ask us to correct inaccurate or incomplete data.
  • Right to erasure — ask us to delete personal data when there is no overriding reason to keep it. You can also close your account and delete most of your data yourself from the product.
  • Right to restriction — ask us to pause processing in certain situations, for example while we check a correction or objection.
  • Right to data portability — receive your personal data in a structured, commonly used, machine-readable format, or have it sent to another controller. The export feature in the application covers most of this for forms and submissions, with CSV and Excel (XLSX) output.
  • Right to object — object to processing based on legitimate interests, including profiling, and to direct marketing at any time.
  • Right to withdraw consent — where we rely on your consent, you can withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
  • Right not to be subject to a decision based solely on automated processing (Article 22 GDPR) — we do not make decisions about you that produce legal or similarly significant effects through solely automated processing, including profiling.

To exercise any of these rights, email support@formbase.so or use the self-service options in the application where available. We will respond within one month, or tell you why we need more time. We may ask for information to verify your identity before acting on a request, especially for access or deletion.

If you are unhappy with how we have handled your data, you can lodge a complaint with a supervisory authority — for users in Norway, the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no). You can also complain to the authority in the EEA country where you live or work.

Rights of respondents

If you are a respondent who submitted a form built on formbase, your data subject rights run primarily against the formbase user who built that form — they are the data controller. We can help you reach them, and we will support them in responding to your request. Where we hold the underlying data as a processor on their behalf, we will act on their documented instructions. To contact us, write to support@formbase.so and tell us which form you submitted (the URL is usually enough).

12. Cookies and Similar Storage

We use a small number of cookies, localStorage, and sessionStorage entries to make formbase work and to deduplicate analytics on your forms. We try to keep the list short.

  • Strictly necessary — keep you signed in, remember the workspace you last used, secure the application against cross-site request forgery, and store essential preferences. These cannot be disabled without breaking the product.
  • Functional — remember UI preferences such as theme, sidebar state, and language. You can clear them from your browser.
  • Analytics on our website (formbase.so and formbase.no) — PostHog, our analytics provider, counts every visit without storing anything on your device. Its servers combine your IP address and browser user agent with a random value that changes every day and is then deleted, so a visit can’t be linked to your visits on other days. Only if you accept in the cookie banner does PostHog also set a cookie (ph_*_posthog) and localStorage entries that identify your browser, and record your visits as session replays. Your choice is stored in localStorage (fb_analytics_consent) so we don’t ask on every page. You can change it at any time through Cookie settings in the website footer; withdrawing deletes what PostHog stored.
  • Analytics on hosted form pages — a random visitor identifier (fb_visitor_id) in localStorage, plus short-lived sessionStorage flags (fb_viewed, fb_engaged), used to deduplicate view and engagement counts. This storage is not needed for the form to function and does not enable advertising, cross-site tracking, or profiling. formbase places this storage as a data processor on your instructions as controller. If your respondents are in jurisdictions where prior consent is required for non-essential storage (such as the EEA under the ePrivacy Directive or Norway under Ekomloven § 3-15), you are responsible for obtaining that consent before the form page loads.

We do not use cookies or similar storage to track respondents across other websites for advertising, and we do not place advertising cookies on hosted form pages. You can clear cookies, localStorage, and sessionStorage through your browser settings. Blocking strictly necessary cookies or storage may prevent parts of the Service from working.

If you build forms on formbase, your hosted forms will set fb_visitor_id in localStorage on respondent devices as described above. You should disclose this in your own privacy notice to respondents.

13. AI Features

Prompts and context you submit through formbase AI Features are sent to Amazon Bedrock. Context includes, where applicable, the structure of the form you are editing and submission samples you explicitly share for analysis or summarisation. We configure it so that, under the AWS Service Terms, inputs and outputs are not used to train any models and are not stored by AWS after the request is processed. Processing is in line with the security and data protection commitments in this Privacy Policy and the Data Processing Agreement.

AI outputs are generated probabilistically and may be inaccurate, incomplete, or out of date. You are responsible for reviewing every AI-generated output before you rely on it, publish it, or send it to respondents.

You should not submit personal data, secrets, or other sensitive information through AI Features unless you have a lawful basis to share that information with our subprocessors and have considered the risks. We do not control how providers respond to lawful government requests directed at them.

14. Children

formbase is not designed for children. You must be at least sixteen (16) years old to create a formbase account, as described in our Terms of Service.

formbase users may build forms intended for younger audiences. If you collect personal data from children through formbase, you are responsible for obtaining any required parental or guardian consent and for handling that data in accordance with applicable law, including COPPA where relevant. Section 6 of the Terms of Service lists sensitive data classes the Service is not designed for, and Section 7 sets out prohibited uses, including content that exploits or endangers minors.

We do not knowingly collect personal data from children under sixteen (16) (or under thirteen (13) where COPPA sets a lower threshold). If you believe we have inadvertently collected personal data from a child below the applicable age threshold without the required consent, contact us at support@formbase.so and we will delete it without undue delay.

15. Communications

We send two kinds of email:

  • System emails about your account, security, billing, and the forms you build. These are part of the Service and cannot be opted out of while your account is active.
  • Service announcements about changes to the product, policies, or features you rely on. We keep these to the minimum needed to keep you informed.

16. Notice for California Residents

If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete it, the right to correct inaccuracies, and the right to opt out of the “sale” or “sharing” of personal information.

formbase does not sell personal information and does not share personal information for cross-context behavioural advertising. Because no sale or sharing occurs, no “Do Not Sell or Share My Personal Information” link is required or provided.

The categories of personal information we collect, purposes, and retention periods are described in Section 4, Section 5, and Section 9. We do not build behavioural profiles for advertising and do not use sensitive personal information for inferences or profiling.

To exercise your rights — including the right to know, delete, correct, opt out, or limit sensitive personal information — write to support@formbase.so. We will not discriminate against you for exercising any of these rights.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our subprocessors, applicable law, or business practices. The “Last updated” date at the top of this policy shows when it was most recently revised.

If you continue to use the Service after a change takes effect, you accept the updated Privacy Policy. If you do not agree to a change, you can close your account before it takes effect.

18. Contact Us

For privacy questions, data subject requests, or anything else related to this policy, contact us at:

formbase has not appointed a Data Protection Officer. Our privacy team monitors the support@formbase.so inbox and will route your request appropriately.