formli AI logoformli AI

/ Legal

Privacy Policy

Last updated: April 9, 2026

1. Introduction and Controller Identity

This Privacy Policy explains how formli AI (https://formli.ai) collects, uses, stores, and protects your personal data. We are committed to complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection laws.

formli AI is an AI-powered PDF form-filling tool. You upload a PDF form, and our AI assistant guides you through completing it via an interactive chat. The completed PDF is then generated for you to download.

Data Controller: The Managing Director of formli AI

Contact: support@formli.ai

Website: https://formli.ai

This policy is drafted in clear, plain language as required by GDPR Article 12. If you have any questions, please contact us at the email address above.

2. What Data We Collect

2.1 Document Data

When you upload a PDF form, we process the document content to identify form fields and assist you in filling them out. Uploaded documents may contain personal data such as names, addresses, dates of birth, tax identification numbers, or other sensitive information depending on the form type.

2.2 Chat and Interaction Data

During a form-filling session, we process your chat messages, the questions asked by the AI, and the form field values you enter. This data is necessary to provide the service.

2.3 Account and Payment Data

Payment information (credit card numbers, billing addresses) is collected and processed by our payment provider Stripe. We do not store your full payment card details on our servers. Stripe provides us with transaction identifiers and limited billing information necessary for record-keeping.

2.4 Technical Data

Our servers automatically collect technical information when you visit our website, including your IP address, browser type and version, operating system, referring URL, and pages visited. This data is recorded in server logs.

2.5 Analytics Data

With your explicit consent, we use Google Analytics 4 (GA4) to collect anonymized usage data such as page views, session duration, and general geographic location. Analytics data is only collected after you provide consent via our cookie banner.

2.6 Learning System Data

We store anonymized patterns and aggregated form-field data in our EU-based database (Neon PostgreSQL, hosted in Frankfurt, Germany) to improve the accuracy and reliability of our service. Where possible, this data is anonymized before storage.

3. How We Use Your Data

Under GDPR Article 6, every processing activity requires a lawful basis. The following table links each purpose to its specific legal basis:

PurposeLegal Basis
Core service delivery (AI-assisted form filling)Contract performance โ€” Art. 6(1)(b)
AI processing of uploaded documentsContract performance โ€” Art. 6(1)(b)
Payment processing via StripeContract performance โ€” Art. 6(1)(b)
Website analytics (Google Analytics 4)Consent โ€” Art. 6(1)(a)
Security monitoring and fraud preventionLegitimate interest โ€” Art. 6(1)(f)
Service improvement (learning system)Legitimate interest โ€” Art. 6(1)(f)
Tax record retentionLegal obligation โ€” Art. 6(1)(c)

Where we rely on legitimate interest (Art. 6(1)(f)), we have conducted balancing tests to ensure that our interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interest at any time (see Section 9).

4. AI Processing and Transparency

formli AI uses artificial intelligence to provide its core service. Transparency about how AI processes your data is central to our approach.

4.1 What the AI Does

When you upload a PDF form, its content is sent to our AI providers for analysis. The AI reads the document content, identifies form fields, generates questions to guide you, and suggests values for form entries based on your responses. Two AI providers are used:

  • Anthropic (Claude) โ€” Provides the AI chat and document analysis that powers the form-filling experience.
  • Google (Gemini) โ€” Provides AI vision capabilities for label assignment and field detection.

4.2 No Training on Your Data

Neither Anthropic nor Google uses your data submitted through our API to train their AI models. Anthropic's API data usage policy and Google's paid API tier both explicitly exclude API data from model training.

4.3 Human Review Required

The AI assists you โ€” it does not make decisions for you. All AI-generated suggestions are presented to you for review and approval before being applied to the document. You control what goes into the final PDF.

4.4 No Automated Decision-Making

formli AI does not make automated decisions with legal or similarly significant effects as described in GDPR Article 22. The AI is a tool that generates suggestions; you make all final decisions about form content.

4.5 AI Provider Data Retention

Anthropic retains API input and output data for up to 30 days for safety and abuse monitoring purposes, then deletes it. Google retains paid API data for up to 55 days for abuse monitoring, then deletes it.

4.6 EU AI Act Compliance

We are committed to transparency in our use of AI in accordance with the EU AI Act (Regulation 2024/1689). formli AI is classified as a limited-risk AI system, and we provide this transparency information to meet our disclosure obligations.

5. Data Sharing and Third-Party Processors

We share your data only with the service providers necessary to operate formli AI. We do not sell your personal data. Each provider listed below acts in a specific capacity:

Anthropic (Claude API)

  • Role: Data processor
  • Data received: Document content, chat messages, form field values
  • Purpose: AI-powered document analysis and form-filling assistance
  • Location: United States
  • Privacy policy: anthropic.com/privacy

Google (Gemini API)

  • Role: Data processor (paid API tier)
  • Data received: Document page images for field label detection
  • Purpose: AI vision for form field identification
  • Location: United States
  • Privacy policy: policies.google.com/privacy

Stripe

  • Role: Data processor (payment processing) and independent data controller (fraud prevention)
  • Data received: Payment card details, billing address, transaction amounts
  • Purpose: Secure payment processing
  • Location: United States / Ireland (EU entity: Stripe Payments Europe, Ltd.)
  • Privacy policy: stripe.com/privacy

Google Analytics (GA4)

  • Role: Data processor
  • Data received: Anonymized usage data (page views, session duration, general location)
  • Purpose: Website analytics and service improvement
  • Location: United States
  • Note: Only activated after explicit cookie consent. IP anonymization is enabled.
  • Privacy policy: policies.google.com/privacy

Cloudflare

  • Role: Data processor
  • Data received: HTTP request data (IP addresses, request headers); uploaded PDF documents; session state data
  • Purpose: Application hosting (Workers), serverless compute for PDF analysis, object storage (R2) for uploaded files
  • Location: EU (R2 bucket EU-pinned; Workers globally distributed with EU edge preference)
  • Privacy policy: cloudflare.com/privacypolicy

Neon (PostgreSQL Database)

  • Role: Data processor
  • Data received: Learning system data, anonymized form-field patterns
  • Purpose: Persistent storage for service improvement data
  • Location: Frankfurt, Germany (EU โ€” no third-country transfer)
  • Privacy policy: neon.tech/privacy-policy

6. International Data Transfers

Some of our service providers are based in the United States, which means your data may be transferred outside the European Economic Area (EEA). We ensure that all such transfers are protected by appropriate safeguards as required by GDPR Chapter V:

ProviderDPF CertifiedTransfer Mechanism
AnthropicNoEU Standard Contractual Clauses (SCCs)
Google (Gemini + GA4)YesEU-US Data Privacy Framework + SCCs
StripeYesEU-US Data Privacy Framework + SCCs
CloudflareYesEU-US Data Privacy Framework + SCCs
NeonN/ANo third-country transfer (Frankfurt, Germany)

We continuously monitor legal developments regarding international data transfers, including the status of the EU-US Data Privacy Framework, and will update our transfer mechanisms as necessary.

7. Data Retention

We retain data only for as long as necessary for the purposes described in this policy. Specific retention periods:

Data TypeRetention Period
Uploaded PDF documentsDuration of session only (RAM-based, not permanently stored)
Chat messages and form field valuesDuration of session only
Learning system dataRetained indefinitely in anonymized form
Anthropic API dataUp to 30 days (then deleted by Anthropic)
Google API dataUp to 55 days (then deleted by Google)
Server logs90 days
Payment records7 years (German tax law โ€” AO ยง147)
Analytics data (GA4)14 months (GA4 default)

8. Cookies and Tracking

8.1 Essential Cookies

We use strictly necessary session cookies to operate the Service. These cookies are required for the website to function and cannot be switched off. They do not require your consent under GDPR and the ePrivacy Directive.

  • Session cookie โ€” Maintains your session state during form-filling. Expires when you close your browser.

8.2 Analytics Cookies (Consent Required)

Google Analytics 4 sets cookies to collect anonymized usage data. These cookies are only activated after you provide explicit opt-in consent via our cookie banner.

  • _ga โ€” Distinguishes unique visitors. Expires after 2 years.
  • _ga_* โ€” Maintains session state for GA4. Expires after 2 years.

8.3 Managing Your Cookie Preferences

You can withdraw your consent for analytics cookies at any time by clearing your browser cookies or using the cookie settings on our website. You can also install the Google Analytics Opt-out Browser Add-on to prevent Google Analytics from collecting data across all websites.

Most browsers allow you to manage cookies through their settings. Note that disabling essential cookies may prevent the Service from functioning correctly.

9. Your Rights Under GDPR

Under the General Data Protection Regulation, you have the following rights regarding your personal data:

  • Right of access (Art. 15) โ€” You have the right to obtain confirmation as to whether personal data concerning you is being processed and, if so, to receive a copy of that data along with information about how it is processed.
  • Right to rectification (Art. 16) โ€” You have the right to request correction of inaccurate personal data or completion of incomplete data.
  • Right to erasure (Art. 17) โ€” You have the right to request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
  • Right to restriction of processing (Art. 18) โ€” You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
  • Right to data portability (Art. 20) โ€” You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Right to object (Art. 21) โ€” You have the right to object to processing based on legitimate interest (Art. 6(1)(f)) at any time. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent (Art. 7(3)) โ€” Where processing is based on consent (e.g. analytics cookies), you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Right to lodge a complaint (Art. 77) โ€” You have the right to lodge a complaint with a data protection supervisory authority (see Section 13).

To exercise any of these rights, contact us at support@formli.ai. We will respond to your request within one month. This period may be extended by two further months for complex or numerous requests, in which case we will inform you of the extension and the reasons for the delay within the first month.

Since our service is session-based and we do not permanently store your uploaded documents or form data, many of these rights are satisfied automatically by design.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:

  • Encryption in transit โ€” All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
  • Security headers โ€” We use Helmet.js to set HTTP security headers including HTTP Strict Transport Security (HSTS) and Content Security Policy (CSP).
  • No permanent document storage โ€” Uploaded PDFs are processed in memory during your session and are not written to permanent storage.
  • Rate limiting โ€” AI endpoints are rate-limited to prevent abuse and protect service availability.
  • CORS restrictions โ€” Cross-origin resource sharing is restricted to allowed origins only.
  • Access controls โ€” Internal access to systems and data is restricted on a need-to-know basis and subject to monitoring.

11. Children's Data

formli AI is not intended for use by persons under 16 years of age, in accordance with GDPR Article 8. We do not knowingly collect or process personal data from children under 16.

If we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to promptly delete that data. If you believe a child under 16 has used our service, please contact us at support@formli.ai.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this page.

For material changes that significantly affect how we process your personal data, we will provide prominent notice on our website. Continued use of the Service after the updated policy takes effect constitutes your acknowledgement of the changes.

We encourage you to review this policy periodically to stay informed about how we protect your data.

13. Contact and Supervisory Authority

13.1 Contact Us

For all privacy-related questions, requests, or complaints, please contact us at:

Email: support@formli.ai

13.2 Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that our processing of your personal data violates applicable data protection law.

For users in Germany: You may contact the data protection authority (Landesdatenschutzbeauftragte) of the federal state in which we are registered, or the authority responsible for your place of residence.

For users in other EU/EEA member states: You may contact the data protection authority in your country of habitual residence, place of work, or the place of the alleged infringement.

A list of EU data protection authorities is available at: edpb.europa.eu/about-edpb/about-edpb/members_en