Privacy Policy
Last updated: April 29, 2026
This Privacy Policy explains how Formaya ("we", "us", "our") collects, uses, stores, and protects your personal information when you use our platform at formaya.app and related services (the "Service"). We are committed to protecting your privacy and handling your data transparently.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Name and email address
- Password (stored as a bcrypt hash, never in plain text)
- Workspace name and membership details
1.2 Form Response Data
When respondents fill out forms created on Formaya, we collect the data they submit. This data is encrypted at rest using AES-256-GCM encryption before being stored in our database. Form creators are responsible for ensuring they have a lawful basis to collect the data their forms request.
1.3 Usage Data
We automatically collect:
- IP addresses (for rate limiting and security)
- Browser user-agent strings (for session management)
- Form analytics data (completion rates, response times, drop-off points)
- API usage logs (for API key authentication)
1.4 File Uploads
When respondents upload files through forms, we store the files on our servers organized by form. File metadata (name, type, size) is recorded in our database.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Authenticate users and manage sessions
- Process form responses and deliver them to form creators
- Generate analytics and insights for form creators
- Send transactional emails: password resets, email verifications, workspace invitations, billing receipts and notifications, payment failure and recovery notices, subscription change notices, monthly usage threshold alerts (50%, 80%, 100% of plan limit), and other service-critical communications
- Enforce rate limits and prevent abuse
- Deliver webhook notifications to configured endpoints
- Process payments through our payment provider (Stripe)
Transactional emails are sent regardless of marketing preferences because they relate to the operation of your account and the Service.
3. Data Encryption and Security
We implement multiple security measures to protect your data:
- Response encryption: All form response data is encrypted with AES-256-GCM before database storage
- Password security: Passwords are hashed with bcrypt (12 rounds)
- Two-factor authentication: Optional TOTP-based 2FA with backup codes
- Session management: JWT tokens with configurable expiration and refresh token rotation
- API key security: API keys are SHA-256 hashed; only the prefix is stored in readable form
- Webhook signing: Webhook payloads are signed with HMAC-SHA256
- Transport security: All communications are encrypted via TLS/HTTPS
4. Data Sharing
We do not sell your personal information. We may share data with:
- Form creators: Response data is accessible to the workspace that created the form
- Webhook recipients: When configured, response data is sent to third-party webhook endpoints specified by form creators
- Payment processor: Stripe processes payment information on our behalf
- Law enforcement: When required by law, court order, or to protect our rights and safety
5. Data Retention
- Account data: Retained for the duration of your account, plus a reasonable period after deletion
- Form responses: Retained until deleted by the form creator or account termination
- Uploaded files and workspace assets: Retained for the duration of your account. When your storage usage exceeds your plan's limit, new uploads are blocked but existing files remain accessible. Files are deleted only when you delete them yourself or when your account is terminated
- Partial responses: Auto-saved drafts expire after 48 hours
- Session tokens: Refresh tokens are valid for 30 days
- Email verification codes: Expire after 10 minutes
- Password reset tokens: Expire after 1 hour
- Webhook delivery logs: Retained for 30 days
- Audit logs: Records of subscription changes, webhook state changes, storage purges, and other administrative events are retained for security and compliance purposes
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Export your data in a portable format
- Object to or restrict certain processing activities
- Withdraw consent at any time
To exercise any of these rights, contact us at [email protected].
7. Cookies and Local Storage
We use browser local storage to maintain your authentication session and cache workspace data for performance. We do not use third-party tracking cookies. For more details, see our Cookie Policy.
8. International Data Transfers
Your data may be processed on servers located in different jurisdictions. Where we transfer data outside your jurisdiction, we ensure appropriate safeguards are in place, including standard contractual clauses or other approved transfer mechanisms.
9. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us immediately. Form creators are responsible for ensuring their forms do not collect data from minors without appropriate consent.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy and changing the "Last updated" date. We encourage you to review this policy periodically.
11. Contact
For privacy-related inquiries, contact our privacy team at [email protected].