Privacy Policy
Last updated: April 29, 2026
Overview
Form Link helps you turn paper forms into structured data. You photograph a blank form to create a template, photograph filled forms to capture the handwritten values, and the results are pushed to the destination you choose (Google Sheets, or web apps via our browser extension).
This policy explains what we collect, where it goes, and the choices you have. If you have questions, email us at [email protected].
Quick summary
- We collect the minimum data needed to run the product.
- We use third-party services for things we don't build ourselves: Supabase (accounts and database), Cloudflare (backend infrastructure), Stripe (payments), Google (optional OCR and Sheets export), and Sentry (error reports).
- Captured form values on your iPhone are encrypted locally, protected by Face ID and the iOS Secure Enclave.
- OCR runs on our servers by default, so captures leave your iPhone. On-device OCR is used automatically if your credits run out.
- You can delete your account from Settings → Delete Account at any time. No email required.
What we collect
Account information
- Email address — required to create an account and sign in. Stored via Supabase Auth.
- Organization name — the name you give your workspace.
- Member roles — who in your organization is an owner, admin, or member.
- Display name — an optional name shown for your account within your organization.
We never ask for your phone number or physical address. Two pieces of data can contain a person's name, and we want to be plain about both: the optional display name above, and the device name your iPhone reports when you pair it — iOS commonly sets this to something like "Marko's iPhone", which we store as described under Device registration below.
Usage data
To enforce plan limits and calculate billing, we log metadata about AI calls you make through Form Link:
- Which provider and model were used (e.g., Google Gemini)
- Token counts and estimated cost
- HTTP response status and timestamp
- The organization and user the call belongs to
We do not log the content of your prompts or the AI's responses.
Device registration
When you pair your iPhone with your browser extension, we store:
- A device identifier (UUID)
- Device type (iOS or Chrome extension)
- Device name (e.g., "Marko's iPhone")
- Last-seen timestamp
This lets you see and manage your connected devices from the dashboard.
Captured form data
- Templates and field mappings — where you've told us each field lives on a paper form — are stored in your browser and synced to your Supabase workspace so you can use them across devices.
- Scanned form values — the actual text extracted from filled forms on iPhone — are stored only on your iPhone, in an encrypted archive protected by Face ID and the iOS Secure Enclave (AES-256-GCM). They are not uploaded to our servers.
- When you choose to export to a destination (Google Sheets or a web form), extracted values are sent to that destination on your command. We do not retain a copy.
Billing data
If you subscribe to a paid plan:
- Stripe is our payment processor. Card details are entered directly into Stripe's interface and never touch our servers.
- We store a Stripe customer ID, subscription ID, status, and price tier in our database so we know what plan you're on.
- Billing address and payment method are held by Stripe under their terms and privacy policy.
Website analytics
We use Google Analytics on form-link.ai to see which pages people visit and which links they click, so we know what's useful. It is configured with all consent signals denied, which means no analytics cookies are set and you are not tracked across other websites. Google receives the page you viewed, the link you clicked, your approximate location derived from your IP address, and basic browser and device information. Analytics does not run on captured form data, and it is disabled outside our production website.
Error reports
We use Sentry to monitor application errors. When something crashes or fails, Sentry may capture the error message, stack trace, your user ID, the page or URL where it happened, and browser or device metadata. We do not intentionally send form content or captured values to Sentry.
OCR processing: cloud and on-device
Form Link has two OCR modes on iPhone. Which one runs is decided by the app, not chosen by you — there is currently no mode control in the app:
Cloud OCR (default)
This is the default mode, and in normal use it is the only one. Each capture you take is transmitted over TLS to our Cloudflare Worker backend, which forwards it to third-party model providers for text recognition and field classification: Google Cloud Vision, Google Gemini and Anthropic. Images are sent only when you take a capture — nothing is uploaded in the background. Neither we nor these providers retain the image after processing; each processes the request and discards the image under their API terms.
On-device OCR
Text recognition runs entirely on your iPhone using Apple's Vision framework, and image data never leaves your device. It consumes no AI credits, and accuracy is considerably lower than cloud OCR.
This mode is not something you can select. Form Link switches to it automatically, and only when your organization's credit balance reaches zero. It is not used for capturing a blank form to build a template — that step requires cloud OCR, and will report an error rather than fall back. If you want captures processed on your device by choice rather than by credit exhaustion, that option does not exist today; email [email protected] if it matters to you.
Permissions we ask for
iOS app
- Camera — required to photograph paper forms.
- Local Network — required to connect your iPhone to the Chrome extension on your computer over your local Wi-Fi.
- Face ID — protects your locally stored form data. Your biometric template never leaves the iOS Secure Enclave; we only ask iOS to verify your identity.
Chrome extension
- Active tab — to read the structure of the web form you want to populate.
- Storage — to save templates and authentication tokens.
- Local network — to communicate with your paired iPhone over your local Wi-Fi.
Third-party services (subprocessors)
We use the following services to run Form Link. Data flows to them only as described above.
- Supabase — database and authentication. Stores your email, organization, usage metadata, and device records.
- Cloudflare — serverless backend infrastructure (Workers). Handles API requests, auth validation, and rate limiting. Receives captured image data whenever cloud OCR is used, which is the default mode.
- Stripe — payment processing. Holds customer, subscription, and payment method data under their privacy policy.
- Google Cloud Vision — cloud OCR text recognition. Receives captured image data whenever cloud OCR is used, which is the default mode.
- Google Gemini — automatic field classification and template field detection. Receives captured image data and extracted text whenever cloud OCR is used.
- Anthropic — cloud text extraction. Receives captured image data whenever cloud OCR is used.
- Google Sheets — optional export destination. Receives extracted form field data that you explicitly choose to export.
- Google Analytics — aggregate website traffic measurement on form-link.ai. Runs cookieless (all consent signals denied) and receives page views and link clicks, never form content.
- Sentry — application error monitoring. Receives error messages, stack traces, and user IDs.
- Apple — beta distribution via TestFlight. Apple handles device identifiers for app delivery under their terms.
Each of these services has its own privacy policy and terms. We choose providers who offer strong security and privacy practices.
Google API Services — Limited Use Disclosure
Form Link's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We access Google Sheets only to write form extraction results that you explicitly choose to export — no data is read back or retained by us.
- Google user data obtained through OAuth is used solely to provide the Form Link service to you.
- We do not use Google user data to serve advertisements or for any purpose unrelated to the service.
- We do not allow humans to read your Google user data.
- We do not share Google user data with third parties except as necessary to provide the service (Supabase for authentication; no Google data is passed to Supabase).
- We do not use Google user data to train machine learning models.
Data storage and security
- Data in transit is encrypted with TLS (HTTPS).
- Your Supabase workspace data is protected by row-level security policies so members of one organization cannot read or modify data belonging to another.
- Your iPhone-stored captured data is encrypted with AES-256-GCM; the encryption key is held in the iOS Secure Enclave and can only be unlocked with Face ID.
- Session tokens between the extension and iPhone are cryptographically generated and time-limited.
- We have not had a data breach. If we ever do, we will notify affected users by email.
Data retention
- Account data — kept while your account is active. Deleted (or anonymized where legally required) when you close your account.
- Usage logs — currently retained while your account is active so we can investigate billing disputes and debug issues. We plan to introduce a finite retention window as we scale; we will update this policy when we do.
- Billing records — retained in Stripe per their retention policy, and in our database for as long as they remain relevant to active or recent subscriptions.
- On-device data on your iPhone — you control this. You can delete individual captures or wipe the entire archive from within the app.
Your rights and choices
- Access — you can view your account and organization data in the dashboard at any time. For a complete copy of the underlying data rows we hold about you (profile, memberships, usage records, devices), email [email protected] and we will send a JSON export within 30 days.
- Correction — update your email, organization name, and member list directly from the dashboard.
- Deletion — delete your account from Settings → Delete Account. See the Account deletion section below for what gets removed.
- Data portability — export your captured form data to Google Sheets at any time from within the app. For a structured export of account data, email [email protected].
- Object to processing — if you believe we are processing your data in a way that is not justified by a legitimate purpose, email [email protected].
- OCR mode — cloud OCR is the default and there is currently no control to switch modes; on-device OCR is used only as an automatic fallback when credits reach zero. If you would rather your captures were never sent for cloud processing, email [email protected].
Account deletion
You can delete your account yourself from Settings → Delete Account in the dashboard. Deletion is immediate and permanent — there is no grace period. If you cannot access your account, email [email protected] from the address associated with your account and we will process the request manually.
Deleting your account:
- Removes your email and authentication record from Supabase
- Cascades to your organization membership records and device registrations
- Cancels any active Stripe subscription
- Does not automatically delete data stored locally on your iPhone — you can delete that directly from within the app
Certain records may be retained where required by law (for example, Stripe keeps payment history for tax reporting obligations).
California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act and its amendment (CPRA) give you the following rights:
- Right to know — you have the right to know what personal information we collect, use, and disclose about you. This policy describes that in full. For a complete data export, email [email protected].
- Right to delete — you can delete your account and all associated data from Settings → Delete Account. See Account deletion above.
- Right to correct — you can update your email, organization name, and member roles from the dashboard at any time.
- Right to opt out of sale or sharing — we do not sell or share your personal information with third parties for advertising or cross-context behavioral purposes. There is nothing to opt out of.
- Right to non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise your rights, use the self-serve controls in the dashboard or email [email protected]. We will respond within 45 days as required by law.
EU and UK residents (GDPR / UK GDPR)
If you are in the EU or UK, you have the following rights under the GDPR and UK GDPR. Form Link is operated from the United States; by using the service you acknowledge that your data is transferred to and processed in the US.
- Right of access (Art. 15) — request a copy of the personal data we hold about you. Email [email protected] and we will send a JSON export within 30 days (extendable to 60 days for complex requests).
- Right to rectification (Art. 16) — correct inaccurate data from the dashboard (email, organization name, member roles).
- Right to erasure / right to be forgotten (Art. 17) — delete your account from Settings → Delete Account. This removes your authentication record, organization memberships, device registrations, and usage logs from our systems immediately.
- Right to data portability (Art. 20) — export your captured form data to Google Sheets from within the app. For a structured export of account data in machine-readable format, email [email protected].
- Right to object (Art. 21) — if you believe we are processing your data without a legitimate basis, email [email protected] and we will review your request.
To exercise any of these rights, use the self-serve controls in the dashboard or email [email protected]. We will respond within 30 days as required by GDPR Art. 12.
Children's privacy
Form Link is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have collected data from a child, email [email protected] and we will delete it.
International users
Form Link is operated from the United States. If you use Form Link from outside the US, your data is transferred to and processed in the US. We honor data subject requests from EU, UK, and California residents as described in the sections above. Email [email protected] for any request we cannot fulfill through the self-serve dashboard controls.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. The "Last updated" date at the top of this page reflects the most recent revision.
Contact
Questions about this policy? Email [email protected].
Form Link is operated by DATAWAND LLC.