What this policy covers
This policy covers the Formly app on iOS and Android, the accounts behind it, and the servers that produce your form checks. We are the controller of the personal data described here. It does not cover what Apple, Google, or any other company does with data on their own side of an exchange with us; that is governed by their policies, not this one. Privacy questions, data requests, or anything below that did not answer your question: contact@formlyai.app.
What Formly never collects
Formly asks for a permission only at the moment you use the feature that needs it, never on launch, and declining any one of them leaves the rest of the app working. On iOS there are three in total: your camera and your microphone, when you record a clip inside the app, and notifications, if you switch on training reminders. Picking a photo or a clip you already have asks for nothing, because it opens the system photo picker, which hands Formly the one item you chose and no access to the rest of your library. On Android it asks for those three and for access to your media files. It asks for nothing else, and much of what follows follows from that. Formly collects none of the following, apart from the two exceptions named in the location bullet:
- Audio. Recording a video inside Formly opens your device’s own camera, which records sound as well as picture. That means the app asks for microphone access the first time you record, and a clip you record carries an audio track. We send the whole clip to the analysis provider, so any sound recorded with it goes too. We do not transcribe it, listen to it, or store it separately from the clip, and nothing in the analysis uses it — the feedback is based on the movement. Photos carry no audio, and a video you pick from your library carries whatever audio it already had. If you decline microphone access, the rest of the app is unaffected.
- Your location. Formly never asks iOS or Android for location access and stores no location data, so a photo taken with Formly's own camera cannot carry coordinates. Two exceptions are worth naming. If you sign in with Google, Google's own sign-in library may derive a coarse location from your connection as part of that sign-in; that happens under Google's privacy policy rather than ours, it is not sent to Formly, and signing in with Apple or with an email address avoids it entirely. And one case, described under "What leaves your device", can send location data that was already inside a file you imported.
- Analytics, crash reporting and attribution. The app contains no Sentry, Firebase, Crashlytics, Amplitude, Mixpanel, Segment, PostHog, AppsFlyer or Adjust component. Nothing measures your behaviour in the app; the only record we keep of you opening it is the streak described below.
- Advertising identifiers. Formly carries no ads, contains no advertising SDK, and does not track you across other apps or websites.
- Performance telemetry. The only timing the app records is a rolling average of how long your form checks take, used to size the progress bar. It is written to storage on your phone and never leaves it.
- Push notifications and device tokens. Formly shows two kinds of notification, and your own phone schedules and fires both of them. The first is a training reminder you switch on under Profile → Training reminders: you pick the training days and one time of day, which your phone then repeats weekly on those days. Switching that reminder on is also the only moment Formly asks for notification permission. The second tells you a form check has finished, if one completes while you are not looking at the app; it reuses that same permission and stays silent unless you have already granted it, so if you never switch reminders on you will never see it. Nothing about either reaches a server: Formly requests no push token, holds no device token, and has no way to send you a notification from our side.
- Contacts, calendar entries, and health or fitness data held elsewhere on your device.
- Payment card numbers. Purchases are handled by the App Store or Google Play; the card never reaches us.
What we collect and store
Everything Formly itself stores about you sits in our database and your sign-in record. Group records hold nothing about you until you join a challenge or club. The published challenge catalogue contains no user data. Two things sit outside the database and are listed here too: the request logs our hosting provider keeps, and the subscriber record RevenueCat holds. A small amount of data also stays on your phone, described under "What stays on your phone". That is the whole picture:
- Your account: email address, your display name, and sign-in details for email codes, a password (stored as a hash, never as text), or Sign in with Apple or Google. We also store your self-declared age eligibility, the accepted Terms version, and when account setup was completed. We do not collect a date of birth.
- Form checks: one row each, holding the score, the potential score, the activity the model identified, its written summary, the strengths, improvements, drills, body points, movement phase and next-session goal it produced, your optional note from the "Anything to focus on?" box, and the time it was created. The activity stored is the one the model detected; the label you sent is used only when the model returned none. No image, no frame, no file reference.
- A finished report waiting to be collected. If the app loses its connection, is backgrounded or is closed while a check is running, the server finishes the analysis anyway and holds the written report in a row of its own so the app can collect it when you return — otherwise you would have paid for a check you never received. It holds the same report text described above and the time it was written, and it is deleted the moment the app collects it. One row per person at most: a newer report replaces an older one. Deleting your account deletes it with everything else.
- Usage counters: how many form checks you have used, when your allowance last reset, whether your subscription is active, your best score, XP and badges, your streak and the date you last opened the app. Most of it exists to enforce the limits of your tier, which are set out in the Terms of Service. The streak and the last-opened date exist so the streak can be counted, and are written once per session when you open the app — not when you run a check. Two columns here counted messages to the AI coach; the feature is gone and nothing increments them any more, but a number one of them already holds stays on your account until you delete it.
- Request safeguards: one reservation row per form-check attempt that passed the usage gate, holding your account identifier, the type of request, when it began, whether it used the free allowance, the previous free-allowance state needed for a refund, and when it was refunded if the request failed. A separate rate-limit row holds your account identifier joined to the request type, the start of the current one-minute window and its request count. No app can read either table. Both are deleted with your account.
- Subscription state, from RevenueCat and the app stores: which plan you are on and whether it is active. Never the card.
- Preferences: your display name, plus values kept from onboarding — appearance, fitness level, primary sport, primary goal and weekly goal. Two are read by the app: your display name, and primary sport, which becomes the activity label sent with a form check. Four notification fields remain from older test builds. Three of them — daily reminders, weekly summaries and marketing — are neither read nor written by this version. The fourth records whether a finished form check should notify you; this version reads it each time a check completes and never writes it, so it stays at whatever it already was, and a finished check notifies you unless that value is already off. If answers from an older onboarding flow are still in this app's storage on your phone, signing in copies the fitness level, sport and goal into these columns, and the goal and the obstacle you named into your sign-in record.
- Answers from earlier versions. If you used a version that asked onboarding questions, what you answered — training goal, what was stopping you, fitness level, primary sport — is still on your account. The current app asks none of them.
- Rows left behind by removed features. Three tables belong to features the app no longer has: the two behind training plans, and the one that held AI coach conversations. Anything you made with either before it went is unreachable from the app — it can neither show you those rows nor delete them one at a time. Deleting your account deletes them, and so does emailing us.
- Challenges you join: one membership row holding your account, the challenge and when you joined. Progress is not stored in another row; each time you open Challenges, Formly counts your existing form checks that match the challenge activity and dates. Other athletes receive only the aggregate number of people who joined, never your identity or progress. Leaving deletes the membership row.
- Groups you are in, if you join one: the group's name, its invite code and who created it, plus one membership row per person holding the group, the member, whether they own it and when they joined.
- Checks you publish to a group: one row per group per check, holding the display name you had set for Groups at that moment, the score, when the check was taken, when you published it, and a pointer to the check itself — which is what lets the other members open the report. Taking the check down deletes the row.
- The weekly board: one row per group, per member, per week, holding your best published score for that week and the display name it was published under. It is a high-water mark rather than a running total — taking a check down does not lower it, and it is deliberately kept when you leave the group, so that leaving and rejoining cannot reset a week.
- Reactions: one row per person per published check for the "cheer" tap, holding who reacted, to what, and when.
- Workout plans written for a group, across three tables: the plan itself, holding its title, your optional note, who wrote it and the display name they had at the time; one row per exercise on it, holding the name and a short line of detail; and one row for each published check a member attaches to an exercise, holding who attached it and which check. A plan is written by hand — nothing generates one — and attaching a check only points at a check already published to that group.
- Reports and blocks. A report holds who reported which check or workout plan, in which group, the reason, and a snapshot of what was reported — for a check, the display name it was published under, its score and its date; for a plan, its title, your note, the author's display name and how many exercises it had — kept so that the report still means something after the content itself is gone. A block holds the two accounts and the time, and applies in both directions.
- Join attempts: the account and the timestamp of each attempt to join a group with a code, kept only to throttle code-guessing to ten attempts an hour. Nothing else about the attempt is recorded, and no app can read this table.
- Temporary video upload records: your account identifier, a random request and file identifier, file size, format, duration, status and timestamps. Only our server can access these records. The upload address is removed after confirmed cleanup; deleting your account removes the account link. The remaining technical record is retained to account for uploads and prevent abuse.
- Server logs. Our hosting provider, Supabase, records technical request information such as IP addresses and timestamps. Formly's own server code logs error messages and table names only, never message content, image data or email addresses.
What we use it for
Every purpose is listed here. There are no others.
- Producing your form checks. This is the only purpose for which your images and your notes leave our systems.
- Keeping your history, so you can reopen a check and watch your scores move.
- Running the Groups features you choose to join: calculating your own challenge progress; and, inside private clubs, showing the other members the checks you publish, building the weekly board from them, carrying the workout plans anyone writes for the club, and handling the reports and blocks that keep a club usable. Nothing is published to a club without you switching it on for that club.
- Signing you in and keeping your account secure.
- Counting your usage against the limits of your tier, and confirming your subscription with RevenueCat and the store. That is the other purpose that sends anything outside our systems, and what it sends is your Formly account identifier and nothing else.
- Diagnosing failures, from the error messages and table names in our logs.
- Sending the emails the account needs: address verification and password resets. There is no marketing email and no way to opt into one.
- Answering you when you write to us, and meeting our legal obligations.
What leaves your device, and where it goes
Nothing is sent for AI processing until you have given permission for that account. A form check is the only thing that sends anything to an AI provider, and Google is the only AI provider Formly uses. Small media passes through Formly's server function, hosted by Supabase, to Google's Gemini API. Large videos upload directly to Google into temporary storage after our server authorizes the upload. Google receives your IP address for that direct connection. We request deletion after analysis or cancellation; interrupted uploads may remain with Google for up to 48 hours. Media is not stored on Formly's servers. Our server retains temporary upload metadata to enforce ownership, expiry and cleanup.
- From a video: the clip file itself, up to 60 seconds and roughly 200 MB, encoded as you recorded it (typically MP4 or MOV). Clips longer than 60 seconds are refused on the phone before upload, and so is a file over the size limit.
- From a photo: the whole image file, as Formly receives it after any on-device conversion. A photo over roughly 5 MB is refused on the phone. HEIC and HEIF photos are converted to JPEG on your device before upload — they are not refused at the picker.
- Photos and their metadata: a photo chosen from your photo library is re-encoded before Formly ever reads it, and in our testing that re-encode drops the file's EXIF metadata, including any GPS tag, for JPEG and PNG images on iOS. A photo imported through the Files browser is copied byte for byte and sent unchanged, so if that file carries GPS coordinates, those coordinates travel to Google inside the image.
- With a form check: an activity label and your optional note. If an earlier version of the app recorded a sport for you — on your account, or in this app's own storage on your phone — that sport is the label, and it is still sent with every check. If it did not, the label is "Any activity". This version of the app gives you no way to choose one.
- Nothing else about you reaches Google with it: no name, no email address, no account identifier, no subscription status, and nothing from any other check. Confirming that your subscription is active is a separate request to RevenueCat, described under "Who else receives your data".
- When you publish a check to a group, no media and no new text leaves your device. The check is already stored in your account; publishing writes a row that points at it, alongside your display name, the score and the date. Who can then read it is set out under "Who else receives your data".
Your permission to use AI
Before your first form check, the app asks for explicit permission to send that data to Google, and lists what will be sent. Google is the only AI provider Formly uses, so that one permission covers every AI request the app can make. If you decline, form checks do not run and the rest of the app works normally.
How that permission is stored changes what withdrawing it means, so we will be exact about it. It is a timestamp written into the app's own storage on your phone, against your account. We hold no copy on our servers, and there is no server-side consent record for anyone here to change. This version of the app has no in-app switch to turn it back off.
The routes that genuinely stop future AI processing are therefore these three: decline when you are asked; delete the app, which takes the app's storage with it; or delete your account, which clears that account's consent timestamp on this device and stops the account being able to make another AI request. Writing to us cannot directly clear a flag held only on your phone. Whichever route you take, it governs future requests only. Nothing already sent to Google can be recalled.
Health information
One place in the app can carry health information you volunteer: the "Anything to focus on?" note on a form check. An injury you are working around, pain in a particular movement, a condition you want the feedback to account for. That note is sent to Google with the analysis request, and it is stored on that form check until you delete the check or your account, exactly like any other text you write.
It can reach another person, and only if you send it there. Publishing a check to a group sends the whole stored check, the note included, even though the app displays that note to nobody. A note cannot be edited once the check is made, so if you would rather one stayed between you and the model, the way to keep it that way is to leave it off a check you might publish.
We never ask for it. The field does not need it, a form check works with the box empty, and nothing in the app treats a check with a note differently from one without.
Where the GDPR applies, health information is special-category data, and the only basis we rely on for processing it is your explicit consent: the permission you give before your first form check, which names the note box among the things that are sent. That permission is recorded as a timestamp on your phone rather than on our servers. Deleting a check removes the text from our database; deleting your account removes all of it.
Form checks are not medical advice
A form check is not a diagnosis. It is generated by an AI model and it can be wrong — about your movement and about you. Before starting or changing a training programme, especially with an injury, pain or a medical condition, ask a doctor or a qualified coach. If something hurts, stop and speak to a professional.
What we never store
No photo or video file is stored on our servers after analysis. Formly has no file-storage bucket for your clips. Small media passes through in memory; larger videos go directly to temporary Google storage, with deletion requested after analysis or cancellation. The written results are stored in your account.
Who else receives your data
There are two kinds of recipient and no others: the companies below, which handle data for us, and — only for what you deliberately publish to a group — the other members of the groups you are in. Supabase, Google and RevenueCat handle this data for us under their own data processing terms. Apple and Google set their terms and we accept them. Google is the only AI provider on this list, and the only one there is: what you submit for a form check reaches Google, either through Supabase or by an authorized direct video upload, and no other AI company receives it.
- Other members of a group you publish a check to. This is the one place your data reaches people rather than companies, and it happens only because you switched a specific check on for a specific group. They receive the display name you set for Groups, the score, the activity, the date and the written report, and your best score each week appears on that group's board under the same name. A workout plan you write for a group is the same kind of disclosure and reaches the same people: its title, your note, the exercises you listed, and your display name beside them. A group holds up to 40 people. They do not receive your email address, your account identifier, your video or your photo. Two honest details: the check they can open is the whole stored check, including the optional "Anything to focus on?" note — nothing in the app displays that note to them, but it travels with the row, so leave it out of a check you plan to publish if you would rather it stayed private; and anything another person has already seen cannot be recalled, which is what makes this different from every other row in this policy.
- Supabase hosts our database, sign-in and server functions. Photos and small clips pass through it in memory on their way to Google. Large video files upload directly to Google; Supabase holds the upload metadata and authorizes the analysis.
- Google (Gemini) runs the model that produces your form checks. It receives your photo or video clip plus the activity label and optional note. Under Google's API terms, inputs and outputs are handled according to their data processing terms and are not used to improve Google's products without separate permission.
- RevenueCat manages subscription entitlements. We send it your Formly account identifier as your RevenueCat user id, both from the app when you sign in and in a server-side lookup that runs on every AI request to confirm your subscription is active. RevenueCat therefore holds a subscriber record keyed to your account.
- The Apple App Store and Google Play take the payment and manage the subscription. We receive your subscription state from them and never receive card details.
- Apple and Google, if you use their sign-in. Sign in with Apple asks them to release your name and email address to us, and the name is written to your account record. Sign in with Google returns an identity token that we exchange for a session. What Apple or Google observe on their own side of that exchange is governed by their privacy policies, not this one.
- Have I Been Pwned, and only when you set a new password. Before a new password is accepted the app checks whether it appears in known public breaches. It does this without sending the password: the app hashes it on your device and sends only the first five characters of that hash, receives back every leaked hash starting with those five, and does the matching on your phone. Have I Been Pwned therefore sees your IP address and a five-character fragment shared by many thousands of different passwords — never your password, never your email address, and nothing tying the request to your account. If the service cannot be reached the check is skipped and your password is accepted.
No sale, no advertising
We do not sell your personal information and we do not share it for cross-context behavioural advertising. Formly carries no advertising, contains no advertising or analytics component, and does not use your photos, your clips, your notes or your account data to target anything at you.
Who operates Formly
Formly is operated by Adrien Bodson, 4041 avenue Marcil, Montréal, Québec H4A 2Z7, Canada. Questions, complaints and claims about the app can be sent to that address, or by email to contact@formlyai.app.
Security
Specifics rather than adjectives:
- All traffic between the app, our servers and our providers is encrypted in transit.
- Every AI request carries your sign-in token, which our server function verifies before anything is forwarded.
- Row-level security is enabled on every one of our tables without exception, and its policies — not the app — decide who may read a row. Your form checks, preferences and usage counters are restricted to your own account, and so is everything left behind by the removed training-plan and coach features. The published challenge catalogue is readable by signed-in athletes; a challenge membership row is readable only by the athlete it belongs to, while a server routine exposes only the aggregate number joined and calculates progress only from the caller's own checks. Private-club tables are restricted to the members of that club, with two accounts that have blocked each other excluded from each other in both directions. A club's contents are unreachable to anyone outside it, including through a direct request to the database with a valid sign-in token. A workout plan someone writes for a club, and the checks members attach to its exercises, sit under the same rule: a plan is readable only inside its own club, and an attached score is only ever a check its owner had already chosen to publish there — attaching cannot publish anything, and taking the check down removes the score from the plan in the same instant.
- Passwords are stored by our database provider as a hash. We never hold the text of one.
- Your usage counters are read-only to the app. Only server-side routines can move one, so a modified client cannot grant itself more form checks.
- Database permissions are deny-by-default: a new table or function arrives with no client access at all until access is granted deliberately.
- Text you type is escaped and marked as untrusted before it is placed in a model prompt.
- No method of transmission or storage is completely secure, and we do not claim otherwise. If you find a security problem, email contact@formlyai.app.
How long we keep it
Saved checks stay until you delete them or delete your account; we do not delete dormant accounts on our own initiative. Temporary video files are different: we request deletion from Google after analysis or cancellation. Interrupted uploads may remain there for up to 48 hours. Our upload records retain technical metadata after the file is deleted, with the account link removed on account deletion. The following records have separate retention rules:
- Your usage records, which are kept independently of what they count. Deleting a form check deliberately does not reduce the number of checks you have run or remove its request-reservation record, because that would turn deleting your history into resetting your free allowance or erase the record used to make a failed-request refund idempotent. The one-minute rate-limit row is reused for later requests. These rows last until you delete your account.
- A free-check eligibility record survives account deletion if your identity has used its free check. It contains a fingerprint derived from a normalized email address and a server-held secret, the deletion timestamp and a counter of recorded deletions. It contains no plaintext email, account identifier or analysis content. We compare this fingerprint with later registrations to prevent repeated free checks through account deletion or email aliases. It has no automatic expiry and is retained for this abuse-prevention purpose. Email us if you believe it incorrectly prevents your free check or want to exercise your privacy rights.
- Rows from the removed training-plan and AI coach features, which no in-app control can delete individually. Deleting your account removes them, and so does emailing us.
- Server logs, which Supabase discards on the retention schedule of the plan we hold with them — a matter of days, not months. Email us if you need the current figure.
- Your rows on a group's weekly board. Your best published score for a week, and the display name it was published under, is a high-water mark: taking the check down does not lower it and leaving the group does not clear it, because otherwise leaving and rejoining would erase a week. Deleting your account does clear it.
- A report somebody filed about a check you published, which holds a snapshot of the display name, score and date it carried at the time. It is kept so that a moderation decision can still be reviewed after the content is gone, and it outlives both the check and your account. A report you filed about somebody else is deleted with your account.
- Records held by Apple, Google and RevenueCat, kept under their own terms for billing, fraud prevention, safety and legal obligations. RevenueCat's subscriber record is keyed to your Formly account identifier and is not touched by account deletion.
Deleting your data
There are three routes. The first two take effect the moment you tap. The third depends on us reading your email, and we will answer within one month, or sooner where the law requires it.
- One form check: delete it in the app. The row is removed from the database, scoped to your account. It is not merely hidden. One exception, and only if you had published that check to a group: the report goes with the check, but the score, your display name and the date stay with the group. Take it down from the group first — one tap on the check — and the group's copy goes too. Its weekly board keeps the score either way, because that is a high-water mark; only deleting your account clears it.
- Everything: "Delete account", at the bottom of the Profile tab beneath "Log out". It calls a server function that verifies you are signed in, then deletes, for your account only, your form checks, preferences and usage counters, along with everything the removed training-plan and coach features left behind. Your Groups data goes in the same operation as your sign-in record: your membership of every challenge and club, every check you published to a club, every workout plan you wrote for one and every check you attached to somebody's plan, your rows on every weekly board, your reactions, your blocks and the reports you filed. A club you created is not destroyed with you — ownership passes to its longest-standing remaining member, exactly as it does when an owner leaves, and the club is deleted only if you were the last person in it. Then your sign-in record itself. It cannot be undone.
- Anything the buttons cannot reach — a correction, a copy of your data, a row left behind by a removed feature, the RevenueCat subscriber record: email contact@formlyai.app.
What deleting your account does not reach
Deletion is bounded, and the boundaries are worth stating exactly.
- The free-check eligibility fingerprint described under "How long we keep it". Account deletion does not reset a used free check. The fingerprint and its deletion timestamp and counter remain for abuse prevention; contact us to ask about this record or an incorrect eligibility decision.
- Your subscription. Deleting your account does not cancel App Store or Google Play billing, and charges continue. A subscription renews automatically unless you cancel at least 24 hours before the current period ends, so cancel first — in your device's subscription settings, or through the Formly Pro card in the Profile tab. Refunds are handled by Apple or Google under their own policies, not by us.
- Anything already sent. Media and text already delivered to Google cannot be recalled by us; it is governed by Google's retention, described above. The same applies to anything already written to server logs, and to a check another person has already read in a group.
- A report another member filed about a check you published. It holds the snapshot described under "How long we keep it" — a display name, a score and a date — and it is kept so the decision made on it can still be reviewed. Deleting your account does not clear it.
- Some device preferences. Deleting your account signs you out and clears that account's AI-processing consent timestamp, local profile picture, locally retained replay clips, subscription display seed and onboarding fitness answers. Device-wide choices such as language and theme, plus the last-viewed group identifier and anonymized duration history used to estimate wait times, remain until you delete the app.
- Your RevenueCat subscriber record, which is keyed to your Formly account identifier. The deletion function does not call RevenueCat. Email us if you want it removed as well.
- Records that Apple, Google or our hosting provider are required to keep for billing, security, fraud prevention or legal obligations.
What stays on your phone
Formly is an app rather than a website. It sets no advertising cookies and uses no cross-site tracking technology of any kind. Separately from our servers, it keeps a small amount of data in its own storage on your device: your sign-in token, your AI-processing consent timestamp, your theme choice, which group you were last looking at, your local profile picture if you choose one, locally retained replay clips, and the rolling average of how long your form checks take. Anything an earlier version of the app wrote there may also remain.
All of it is needed for the app to work, and none of it is used for advertising. Your sign-in token is the one piece that leaves the phone: it goes to our own server with every request, so the server can confirm the request is yours. The rest stays put.
Signing out clears your sign-in token but keeps local account data so it is available if you sign back in. Deleting your account also clears that account's AI consent, profile picture, replay clips, subscription display seed and onboarding fitness answers from this device. Device-wide language and theme, the last-viewed group identifier and anonymized duration history remain. Deleting the app clears everything.
Your rights
Wherever you live, you can email contact@formlyai.app and ask us to act on any of these. It costs nothing, we will not ask you for more information than we need to find your account, and exercising a right will never get you a worse service.
- Access a copy of what we hold about you.
- Correct anything that is wrong.
- Delete your data, either in the app or by asking us.
- Restrict or object to processing that relies on our legitimate interests.
- Receive your data in a portable form.
- Withdraw your consent to AI processing. Because that permission lives on your phone rather than on our servers, you withdraw it by deleting the app or deleting your account, as described under "Your permission to use AI" — not by asking us to change a server record that does not exist. Write to us anyway if you want help with either, or want to know what it means for the data we already hold. Withdrawal stops future processing and does not undo processing already carried out.
Legal bases (UK and EEA)
Where the GDPR applies, every purpose needs a lawful basis. Ours are:
- Performance of our contract with you: creating and running your account, producing the form checks you ask for, keeping your history, running the groups you choose to join and publishing the checks you choose to publish, and enforcing the usage limits and subscription entitlement you signed up to.
- Your consent: sending your media, the activity label and your note to Google for a form check. Where a note contains health information, your explicit consent is also the basis on which we process and store that information. You can decline, and form checks then do not run.
- Our legitimate interests: keeping the service available and secure, preventing abuse of the usage limits and of the invite codes, moderating what is published to a group and keeping a report after the content is gone so the decision on it can be reviewed, and diagnosing failures. We pursue those without any analytics or behavioural telemetry.
- Legal obligations: where we are required to retain or produce records.
Complaints (EU, UK and EEA)
If you are in the European Union, the United Kingdom or the wider EEA and you believe we have handled your data unlawfully, you may lodge a complaint with your national data protection supervisory authority. You do not have to contact us first, though we would rather you did.
California
California residents have the right to know what personal information we collect and why, to have it deleted, and to have it corrected. In the categories California law uses, we collect identifiers (email address, name, account and sign-in identifiers); commercial information (your subscription status and usage counts); internet or network activity (server logs); your own content (the notes you type, and anything you write in a group — its name, a workout plan, a report); visual information (the photos and video clips you submit, which we transmit for processing and do not retain on our servers, and video replay copies kept locally on your device when available); inferences the model draws about your movement; and, if you choose to type it into a note, health information. Each category, the purpose it serves and who it is disclosed to are described above — including the other members of any group you publish a check to, who are the only recipients that are people rather than service providers.
We collect all of it directly from you, with two exceptions: your subscription status, which comes from RevenueCat and the app stores, and our server logs, which are generated automatically when the app talks to our servers.
Two of those categories are sensitive personal information under California law: health information, if you type it, and your account sign-in credentials. We use both only to provide the service you asked for, to secure your account, and for the other purposes listed under "What we use it for" — all of them permitted purposes under California law. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for any purpose that would give you a right to limit it. You can still ask us to delete it.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as California law defines those terms. That includes the personal information of consumers under 16. We offer no financial incentive in exchange for personal information, and exercising any of these rights will not get you a different price or a worse service.
Children
Formly is for adults aged 18 and over, or the higher minimum age required where they live. People under 18 may not use Formly, including with parental permission. We do not market Formly to children.
Account setup requires an explicit declaration of adult eligibility and acceptance of our current Terms. We store the minimum age confirmed, the Terms version and the completion time. Existing accounts must make a new declaration when the eligibility policy changes; an earlier 13+ confirmation is insufficient. We do not collect a date of birth or independently verify age; we rely on this declaration.
If you believe someone under 18 has created an account, email contact@formlyai.app. We will investigate and delete ineligible accounts and their data, subject to the limited retention described in this policy.
International transfers
Your data may be processed outside the country you live in, and in most cases it is. Our database and server functions run in Supabase's us-east-1 region, in the United States. Google processes form-check requests in the United States. RevenueCat, Apple and Google operate internationally.
For transfers of UK and EEA personal data to the United States we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved. They form part of the data processing terms in our agreements with Supabase, Google and RevenueCat, and where a provider is certified under the EU-US Data Privacy Framework we rely on that as well. Email contact@formlyai.app for a copy of the safeguards relied on for any particular provider.
Changes to this policy
When this policy changes, the new version replaces this one in the app and the date under Last Updated changes with it. If a change materially affects how we handle your data, we will say so in the app rather than leave you to notice.
Contact
Privacy questions, data requests, or anything in this document that did not answer your question: contact@formlyai.app.
Last Updated
September 14, 2026