formtrove
PLAIN-ENGLISH PRIVACY

Your files are yours.

FormTrove is designed to complete the job you ask for and stop there. No document-data sales. No targeted advertising based on your files. No training AI models on your files.

Effective July 19, 2026Last updated July 19, 2026
Service statusFree early access · live customer billing remains disabled

What FormTrove needs

To provide the service, FormTrove may process account details, saved contacts and autofill profiles you create, device and security logs, support messages, and the files or form fields you intentionally submit. We aim to collect the minimum needed for the requested task.

How files are used

Files are used to compress, convert, combine, sign, fax, store, autofill, scan, or otherwise complete the action you choose. They are not sold, used to build advertising profiles, or used to train FormTrove or third-party AI models.

Temporary and saved files

Browser-based tools, including interactive PDF autofill, process files on your device. Fax files use application-layer encryption in isolated temporary storage and are removed after final delivery status or within 24 hours. OCR and password-protection PDFs are sent to Adobe only for the requested job; FormTrove requests deletion of Adobe assets immediately after the result returns. Intake uploads and packet templates are screened, encrypted with AES-256-GCM, and stored under account-isolated object keys.

Security screening

FormTrove validates file size, declared type, binary signature, and active or executable content before accepting supported uploads. Cloudmersive receives the supported file transiently only to return a malware-scanning result. Production uploads fail closed: files are rejected and not placed in durable customer storage when the required scanner is unavailable or blocks them.

Your choices

You can edit or delete saved contacts, autofill profiles, reusable packets, and intake workflows from your workspace. You may request account deletion at any time. FormTrove will complete a verified deletion request within 30 days unless a limited record must be kept for fraud prevention, billing, a dispute, or another legal requirement. The general document vault remains unavailable until its separate product review is complete.

Questions and requests

Email privacy@formtrove.com for access, correction, export, or deletion requests. We aim to acknowledge privacy requests within five business days and complete verified requests within 30 days, subject to applicable law.

CURRENT VENDOR REGISTER

Who helps FormTrove operate

The full register distinguishes active providers from optional providers that receive nothing until approved and enabled. Read the vendor and subprocessor register.

ClerkActive

Account sign-in, sessions, passkeys, and multi-factor authentication.

Receives account identifiers, sign-in data, and security metadata.
OpenAI Sites + CloudflareActive

Application hosting, encrypted database and temporary object storage, networking, and platform security.

Receives application requests and the data needed to operate the selected feature.
TelnyxActive

Fax transmission and carrier delivery status.

Receives the destination number, FormTrove fax number, requested PDF, and delivery metadata.
Adobe PDF ServicesActive

Requested OCR and PDF password protection.

Receives only the PDF and, for protection, the chosen password for that one job.
Google WorkspaceActive

Messages sent to hello, support, and privacy email addresses.

Receives sender details, message content, attachments, and account or administrator metadata.
ResendActive

Sanitized operational and security-alert email.

Receives the recipient, subject, alert category, and limited operational metadata—never document contents.
Better StackActive

Independent uptime monitoring, alerting, and public incident history.

Receives public health responses, timing, route, and incident-contact metadata—not customer files.
StripeTest environment connected

Sandbox subscription checkout, billing portal, webhook status, and payment-flow testing.

Only signed-in test users can open sandbox checkout. Live customer charges remain disabled until FormTrove completes launch review and activates separate live credentials.
FORMTROVE RETENTION SCHEDULE

What is kept—and for how long

Local browser tool filesNot uploaded to FormTrove.

Temporary fax PDFDeleted after final delivery status or within 24 hours.

Fax and PDF job records90 days; includes status, timestamps, account reference, and limited delivery metadata—not the document.

Secure intake uploadsWhile the request is active, then automatically deleted 30 days after expiration or closure.

Reusable packet templatesUntil the account owner deletes the packet or completes an account-deletion request.

Encrypted backup snapshots30 days; each snapshot is integrity-checked through a restore drill before being marked verified.

Security and activity logsNormally 12 months; document contents and passwords are excluded.

Adobe PDF assetsDeletion requested immediately after the result returns; Adobe documents a 24-hour maximum for transient assets.

Contacts and autofill profilesUntil you delete them or complete an account-deletion request.

Support and privacy emailNormally up to 24 months after the last message, unless still needed for an active request or legal obligation.

Payment and tax recordsNot active yet. Stripe/Link will retain regulated records according to its legal schedule when paid checkout launches.

Provider-level fraud, security, billing, and legal records may follow the provider’s own required schedule. FormTrove will not use those exceptions to keep document contents longer than the periods above.