Skip to main content

Privacy Policy

Last updated: February 1, 2026

Your privacy matters to us. This policy explains what data we collect, how we use it, and your rights regarding your personal information.

256-bit Encryption

GDPR Compliant

CCPA Compliant

1Information We Collect

Information You Provide

  • Account Information: Email address, name, and optional profile photo when you sign up
  • Design Prompts: Text descriptions you submit for design generation
  • Design Files: STL, 3MF, and other files you create or upload
  • Payment Information: Billing details processed securely by Stripe (we don't store card numbers)
  • Communications: Messages you send to our support team

Information Collected Automatically

  • Usage Data: Features used, designs created, time spent in app
  • Device Information: Browser type, operating system, screen resolution
  • Log Data: IP address, access times, pages viewed
  • Cookies: Session tokens and preferences (see Cookies section)

What we DON'T collect: We don't collect location data, contacts, biometric data, or any information beyond what's needed to provide our service.

2How We Use Your Information

To Provide the Service

  • • Process your design requests
  • • Store and organize your designs
  • • Handle payments and subscriptions
  • • Provide customer support

To Improve the Service

  • • Analyze usage patterns
  • • Train and improve AI models
  • • Fix bugs and performance issues
  • • Develop new features

To Communicate

  • • Send account notifications
  • • Respond to support requests
  • • Share product updates (opt-in)
  • • Send security alerts

To Protect

  • • Prevent fraud and abuse
  • • Enforce our Terms of Service
  • • Comply with legal obligations
  • • Protect user safety

3Information Sharing

We do not sell your personal information. We share data only in these circumstances:

  • Service Providers: Trusted third parties who help us operate (see below)
  • Legal Requirements: When required by law, court order, or government request
  • Safety: To protect the rights, safety, or property of Formd or others
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you explicitly agree to sharing

4Data Storage and Security

Your data is stored securely using industry-standard encryption (AES-256 at rest, TLS 1.3 in transit). We use trusted third-party services:

Clerk

Authentication & user management

Supabase

Database storage

Stripe

Payment processing

Cloudflare R2

File storage & CDN

Vercel

Application hosting

Anthropic/OpenAI

AI model providers

All service providers are contractually bound to protect your data and comply with applicable privacy laws.

5Your Rights

You have the right to:

Access

Request a copy of your personal data

Correction

Update inaccurate or incomplete data

Deletion

Request deletion of your data

Portability

Export your designs and data

How to exercise your rights:

  • In-app: Dashboard → Settings → Privacy
  • Email: privacy@formd.dev
  • We respond to requests within 30 days

6Data Retention

We retain your data only as long as necessary:

  • Account data: As long as your account is active
  • Design files: 90 days for free users, indefinitely for Pro subscribers
  • Payment records: 7 years (legal/tax requirements)
  • Usage logs: 90 days
  • Support communications: 2 years

After account deletion, data is purged within 30 days, except where legal retention is required.

7Cookies

We use cookies and similar technologies for:

TypePurposeDuration
EssentialAuthentication, securitySession
PreferencesSettings, theme1 year
AnalyticsUsage statistics (anonymized)90 days

We do not use advertising or tracking cookies. You can disable cookies in your browser, but some features may not work properly.

8International Data Transfers

Your data may be processed in the United States and other countries where our service providers operate. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the EU
  • Data Processing Agreements with all service providers
  • Compliance with EU-US Data Privacy Framework where applicable

9Children's Privacy

The Service is not intended for users under 13 years of age (or 16 in the EU). We do not knowingly collect information from children. If we discover we have collected data from a child, we will delete it promptly.

Parents who believe their child has provided information to us should contactprivacy@formd.dev.

10Changes to This Policy

We may update this Privacy Policy from time to time. For significant changes:

  • We'll notify you via email at least 30 days in advance
  • We'll display a prominent notice in the app
  • The "Last updated" date at the top will be revised

Continued use after changes take effect constitutes acceptance.

11Contact Us

For privacy-related questions, data requests, or concerns:

privacy@formd.dev

We typically respond within 1-2 business days.

Data Protection Officer:
Formd Privacy Team
privacy@formd.dev