EFFECTIVE — JUNE 2026
01Our privacy principles
Your data is encrypted, minimal, and yours — we collect little, explain everything, and delete on request.
Privacy at Formilist starts from four commitments that shape every product decision we make:
- All data encrypted at rest and in transit, using AES-256 and TLS 1.3
- Transparency about what we collect and why — in plain language
- You stay in control: access, export, correct or delete at any time
- Minimal collection — if a feature doesn’t need it, we don’t store it
We are GDPR-compliant and you can request complete deletion of your data whenever you like.
02Information we collect
Account basics, the content you create, and enough usage data to keep the service working well.
We collect four categories of information:
- Account details — email address, name and optional profile information
- Your content — tasks, notes, boards and anything else you create in Formilist
- Usage metrics — which features are used, so we can improve the right things
- Device information — browser, operating system and IP address, for security
03How we use your information
To run and improve Formilist, personalize your experience, and keep your account secure. We never sell personal data.
Your data powers service delivery, personalization, essential account communications and security measures such as fraud prevention. We use aggregated, de-identified usage patterns to decide what to build next.
We do not sell personal data to third parties. We do not run advertising. Your plans are not a product.
04AI and your data
AI features read your content to help you — your content is never used to train models without your explicit consent.
AI features operate on secure systems to generate suggestions, briefings and automations from your own workspace. Processing happens to serve you a result — not to build a training set.
We do not use your personal content to train our AI models without explicit consent, and we maintain zero-training agreements with every model provider we work with.
05Data sharing
Only with service providers who run the product, when the law requires it, or when you explicitly say so.
Information leaves Formilist in exactly three situations:
- Vetted service providers that support operations — under strict agreements
- Legal requirements — when we are legally compelled to disclose
- Your explicit permission — for example, an integration you connect
In team workspaces, what teammates can see follows your workspace settings and role-based permissions.
06Your rights
Access, correct, export or delete everything — from account settings or a single email.
You can access, correct, delete and export your data directly from account settings, or by writing to us. Deletion is complete — not a soft hide.
Privacy questions go to privacy@formilist.com — a human answers, usually within one business day.