Legal
Privacy
Last updated 4 August 2026
Forma is in pre-launch development. This page distinguishes implemented behavior from decisions that still require the owner or counsel; unresolved items are stated explicitly.
This pre-launch notice describes the behavior implemented in this repository. It is not a substitute for the legal-entity, jurisdiction, processor, retention, and contact details that the owner and counsel must approve before commercial use.
What we collect
When you request an operations audit or design-partner review, we collect what you submit: company name, work email address or phone number, industry, team size, and any optional operational note.
If you take part in an audit, we also process any documents you choose to upload (for example process notes or reports) so we can read them as part of the diagnosis.
For a managed connected pilot, supported connectors can process bounded read-only observations from Shopify, Gorgias, ShipBob, Stripe, or Xero. The exact systems, account, evidence categories, and coverage limits must be recorded in the pilot scope before connection.
How we use it
The current product uses submitted information to assess and respond to a request, scope an audit or pilot, deliver agreed analysis, protect the intake from abuse, and maintain the operator review trail.
The repository contains no advertising integration and does not sell lead details. Any processor, hosting, notification, or model-provider disclosure required for a real deployment remains deployment-specific and must be completed before commercial use.
AI processing (third-party model)
Forma's audit analysis can use Anthropic's Claude API. In live mode, when a deployment is configured with an Anthropic API key, audit text and text extracted from documents can be sent to that API for analysis. The applicable Anthropic agreement, retention settings, processing location, and any training-use commitment must be verified for the production account and disclosed before commercial use; this repository does not prove those contract terms.
In mock model mode, when no Anthropic API key is configured, audit analysis uses deterministic sample output and that analysis path does not send audit input to Anthropic or another AI provider. Model mode does not describe lead persistence, operator-notification webhooks, hosting, or other deployment infrastructure.
This deployment is currently configured for mock model mode: the audit-analysis path does not send audit input to a third-party model. The public site footer shows the current model mode; it is not an infrastructure or storage-mode indicator.
Redaction and product-improvement records
Deterministic redaction runs before model calls, but it is best-effort and is not a guarantee that all identifying or confidential information has been removed. Do not submit material that the agreed audit does not need.
The current failure-pattern record can retain a short operational reason and an internal audit-derived reference. Those records must be treated as potentially pseudonymous, not guaranteed anonymous. Commercial use requires a reviewed minimisation, retention, access, and deletion policy for this corpus.
Cookies and tracking
This site sets no advertising or third-party analytics cookies. It uses a first-party, tab-scoped session identifier to record landing, mini-audit start, and mini-audit completion. The attribution code intentionally collects only allowlisted campaign source, medium, campaign, referring hostname, and a same-origin path without a query string; it does not add contact fields, full referring URLs, user-agent data, or arbitrary event names. Campaign values are syntactically constrained, but that cannot establish their meaning: operators must never place personal data in campaign parameters.
How long we keep it
Production lead intake is intended to use the configured durable persistence adapter and fails closed when that requirement is not met. The repository does not yet establish an approved retention period for leads, audits, uploads, connector observations, credentials, or product-improvement records.
Before a paid pilot, the written scope must set the retention and deletion schedule. Offboarding must disconnect each connector, remove local credentials only after the documented provider confirmation, export or delete agreed client records, and retain only what the approved agreement or applicable law requires.
Access and identity boundaries
The current production access boundary is an interim shared operator password. It is not durable per-user identity, public self-service, tenant isolation, or proof of applied and tested per-client row-level security.
Connector credentials are server-side secrets and read access is scoped by client and connector. Unknown or indeterminate OAuth outcomes remain read-disabled until the documented provider confirmation and cleanup path completes.
Required owner and counsel decisions before commercial use
TODO — owner: identify the contracting legal entity, controller/business contact, privacy request channel, response owner, and service address. Do not infer these from the Forma brand or repository owner.
TODO — counsel: approve applicable jurisdictions and lawful bases; processor/subprocessor list and transfer terms; retention and deletion schedule; rights and appeals procedure; incident notice; and the governing commercial privacy terms for a US design-partner cohort.
Until those fields are completed and the operational process is tested, this page is a factual implementation note rather than a complete commercial privacy notice.