Legal

Privacy Policy

Last updated: April 2026

1. Introduction

FormFlows.ai (“we”, “us”, “our”) provides a conversational form-building platform that replaces static HTML forms with AI-powered chat experiences. This Privacy Policy explains how we collect, use, share, and protect personal information when you use our website, dashboard, embedded forms, and APIs (collectively, the “Service”).

2. Information We Collect

Account Information

When you create an account we collect your name, email address, organization name, and authentication identifiers from providers such as Google. We do not store passwords — authentication is handled via OAuth and magic links.

Form Submissions

Forms you create may collect data from end users (your respondents). The structure and contents of those submissions are determined entirely by you. We process and store this data on your behalf as a data processor.

Usage Data

We collect aggregate usage metrics — page views, feature adoption, error logs, and API request volumes — to improve the Service and diagnose issues.

3. How We Use Information

  • To deliver, maintain, and improve the Service
  • To process AI conversations and extract structured field data
  • To send transactional email (account, billing, security notices)
  • To detect, investigate, and prevent abuse or fraud
  • To comply with legal obligations

4. Third-Party Services

We use carefully selected sub-processors to operate the Service. They receive only the data necessary to perform their function:

  • Anthropic (Claude) — AI conversation and field extraction
  • Stripe — billing and payment processing
  • Resend — transactional email delivery
  • ElevenLabs — text-to-speech voice synthesis
  • Railway / PostgreSQL — application hosting and database

5. Data Retention & Deletion

We retain account data for the lifetime of your account. Form submissions are retained until you delete them or terminate your organization. Deleted data is purged from primary storage immediately and from backups within 30 days. You may export or delete your data at any time from the dashboard.

6. Cookies & Tracking

We use essential cookies for authentication and session management. We use minimal first-party analytics to measure aggregate Service performance. We do not sell tracking data or use third-party advertising cookies.

7. Your Rights (GDPR & CCPA)

If you reside in the EEA, UK, or California you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Receive your data in a portable format
  • Opt out of the “sale” of personal data (we do not sell data)

To exercise any of these rights, contact [email protected].

8. Contact

Questions about this Privacy Policy? Email [email protected].