Privacy notice
A plain-language description of how DigitalForms.ai handles data.
This is a draft for an early-stage product. It is not legal advice and has not been reviewed by a lawyer. It will be replaced by a formal policy before wider launch.
What we store
- Account details: your name, email address and an encrypted password (handled by Supabase Auth).
- Forms you create, and the answers and documents people submit to them.
- AI results for each document: extracted fields, a summary, observations and missing information, plus a summary for each submission.
- A usage log of AI requests (counts, token numbers and estimated cost) to apply each plan's limits.
Where it's stored
- Data is stored in Supabase (Postgres database and private file storage). Access is restricted per account with row-level security.
- Uploaded documents are private. They can only be opened by the form owner, through links that expire after about a minute.
- Submitters' IP addresses are not stored. A one-way keyed hash is kept only to limit abuse.
- The app runs on Netlify. Public forms may use Cloudflare Turnstile, a privacy-focused check that tells people and bots apart without tracking cookies.
How AI is used
- Form descriptions, uploaded documents and answers are sent to OpenAI's API to generate forms and to extract and summarise information. Documents are sent with a neutral file name.
- The AI is told not to extract dates of birth or nationality, to keep only the last 4 characters of ID and account numbers, and never to comment on protected characteristics such as age, sex, race, religion, family status or health.
- Requests are sent with storage disabled. Under OpenAI's API terms, API data isn't used to train their models by default; OpenAI may retain requests for a limited period for abuse monitoring.
- AI output is a review aid. It is never used to automatically approve or reject anyone.
Your control
- Form owners can delete individual submissions, whole forms, or their whole account (Settings → Delete account). Deleting removes the related files from storage.
- People who submitted a form should contact the form owner about their data; the owner decides how long to keep it.