Privacy
Privacy Policy
Last updated August 6, 2026
This Privacy Policy explains how Formala (“Formala,” “we,” “us”) handles personal information when you use our website and the Formala service (the “Service”).
Two roles. For information about your own account (the business that signs up), we act as a data controller. For information your Formala widget collects from your website visitors (names, emails, chat messages, etc.), we act as a processor on your behalf — you are the controller of that data, and you are responsible for having a lawful basis and giving your visitors notice.
1. Information we collect
Account information. When you create an account we collect your name, email address, and authentication credentials (handled by our authentication provider), and any details you add to your forms and profile.
Billing information. Paid plans are processed by Stripe. We do not store your full card number; Stripe processes payment details and shares limited information with us (such as plan, status, and the last four digits) to manage your subscription.
Visitor / lead data. When a visitor chats with a Formala widget you've installed, we process the conversation and any details it collects — which may include name, email, phone number, message content, and other fields you configure — so we can generate replies and deliver the resulting lead to you.
Usage & device data. We collect basic technical data such as IP address, browser type, and interactions with the Service, used for security, rate-limiting, and improving reliability.
Cookies. We use strictly necessary cookies to keep you signed in and to operate the Service, plus one local-storage item on our public site recording how you first found us. See “Cookies & local storage” below.
2. How we use information
To provide, operate, secure, and improve the Service; to generate AI assistant replies and extract structured lead details; to deliver leads and notifications to you; to process payments and manage subscriptions; to communicate with you about your account; to prevent fraud, spam, and abuse; and to comply with law.
We do not sell personal information, and we do not use your visitors' lead data for our own advertising.
3. AI processing
Formala uses a third-party AI provider (currently Anthropic) to generate the assistant's responses and to extract lead fields from conversations. Conversation content is sent to that provider's API for this purpose. We select providers that do not use API-submitted content to train their models, but you should review the current provider's terms for the authoritative position.
4. Google Calendar data
If you choose to connect a Google Calendar, Formala requests two narrow permissions and uses them only as described here.
Availability (calendar.freebusy). We read only the free/busy times on the calendar you select: the start and end of each block, and nothing else. We do not read, request, or store event titles, descriptions, locations, guests, or attachments. Those busy periods are stored as time ranges alone and are used for one purpose, which is to remove times you are already committed from the slots your customers are offered.
Bookings (calendar.events). When a customer books through Formala we create the corresponding event on your calendar, update it if the booking changes, and delete it if the booking is cancelled. We only ever touch events that Formala itself created.
Your Google account address (openid, email). Used to show you which account is connected and to keep the right connection attached to the right calendar. It is not used for advertising and is never sold.
Limited Use. Formala's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve this feature, do not use it for advertising, and do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.
Disconnecting. You can disconnect a calendar at any time from your booking settings, which deletes the stored tokens and the mirrored busy times. You can also revoke Formala's access directly from your Google account permissions page.
5. How we share information
We share information with service providers (“sub-processors”) that help us run the Service, under contracts that require them to protect it. As of the date above these include, for example:
• Anthropic (AI responses & lead extraction) · Supabase (database, authentication, file storage) · Stripe (payments) · Resend (email delivery) · Netlify (application hosting) · Plausible (website analytics).
Analytics. We use Plausible on our public website to count visits and see which pages bring people to us. It sets no cookies, does not track anyone across sites, and collects no personal data. It does not run on the signed-in dashboard at all, so no lead or form information is ever sent to it.
Owner-directed sharing. If you configure a webhook or integration (e.g. Zapier, a CRM, or Slack), we send lead data to the endpoint you specify, at your direction.
We may also disclose information to comply with law, enforce our terms, or protect rights and safety, and in connection with a merger, acquisition, or sale of assets.
6. Data retention and deletion
We keep account and lead data for as long as your account is active and as needed to provide the Service, unless a longer period is required by law. We do not delete leads automatically because they are old — deletion is something you do.
There are two ways to delete a lead, and they differ in whether it can be undone. Deleting from your lead list — selecting leads and pressing Delete, or running a bulk cleanup from Settings — moves them to a trash. They leave your list immediately and stop appearing in exports, counts, and follow-ups, and stay recoverable by you for 30 days, after which an automated daily job permanently removes them from our database.
Delete lead, on an individual lead's own page, is immediate and permanent. The record and its conversation are removed from our database at once, with no recovery period — which is what makes it the right tool when someone asks you to erase their data. The button says so before it acts.
Deleting your account removes your forms, leads, and conversation content on that same 30-day basis. Records we are required to keep for legal, tax, or accounting reasons — invoices and payment records held by our payment processor, for example — are retained separately for as long as the law requires.
Backups are retained on a rolling basis for disaster recovery and are overwritten in the ordinary course. Data you delete may persist in a backup until it is overwritten; we do not restore deleted records from backups except to recover from a system failure.
We do not use your leads or conversations to train AI models — not ours, and not a provider's. We do not sell them, and we do not use them to build datasets or to improve the Service for other customers. What we do use them for is running the Service for you: generating replies, extracting lead fields, and producing the aggregate operational counts described above.
7. Security
We use encryption in transit, access controls, and reputable infrastructure providers to protect information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these, contact us at hello@formala.ai.
If your personal data was collected through a business using Formala, that business is the controller — please direct your request to them; we will assist them as their processor.
United States. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Depending on your state (for example, California under the CCPA/CPRA, and comparable laws in other states), you may have the right to know what personal information we hold about you, to access, delete, or correct it, and not to be treated differently for exercising these rights. To make a request, email hello@formala.ai; we will verify it before acting on it.
EEA & UK visitors. Formala is based in the United States and offered primarily to businesses in the US, but our site is accessible internationally. Where the EU or UK GDPR applies to you, our legal bases for processing are performing our contract with you, our legitimate interests in operating and securing the Service, and your consent where required. You also have the rights to restrict or object to processing, to data portability, to withdraw consent, and to lodge a complaint with your local supervisory authority. When we transfer data internationally, we use the safeguards described under “International transfers” below.
9. International transfers
We and our providers may process information in countries other than yours. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for these transfers.
10. Cookies & local storage
We use only the cookies necessary to authenticate you and operate the Service. We do not use third-party advertising cookies.
Our public website also stores one item in your browser's local storage recording how you first arrived (for example, a campaign tag on the link you clicked, or the site that linked to us). It is not a cookie, is never sent with your requests, and is never shared with anyone. If you create an account, we attach it to that account once so we can tell which of our own marketing actually works. If you never create an account, it never leaves your browser, and clearing site data removes it.
11. Children
The Service is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the “Last updated” date, and will provide additional notice where required.
13. Contact
Questions about this policy or your data? Contact Formala at hello@formala.ai.