Privacy Policy

Effective Date: 14 April 2026

At Formi, privacy is our foundational architecture. The Formi Personal Operating System is built on the principle of data sovereignty. This policy explains how we minimise data collection and maximise your control in accordance with the General Data Protection Regulation (GDPR).

1. Privacy-First Infrastructure

We utilise a privacy-first architecture. This means that the core identity and biometric data you store in your Formi vault is encrypted locally on your device. Formi Systems Ltd. does not hold the decryption keys and therefore is not designed to read, access or monetise your personal data payloads.

2. Data We Collect (and Don't Collect)

Account Data: To operate the service, we store your basic account identifier (email address) and authentication tokens.

Audit Logs: We maintain a verifiable log of when you grant or revoke API access to third parties. We do not intercept the contents of the data transmitted.

We do NOT collect: Unencrypted health records, financial credentials, raw wearable streams or any payload data routed between your vault and your connected services.

3. GDPR & Data Subject Rights

You have absolute control over your data in compliance with Articles 13 and 14 of the GDPR. You may export, delete or modify your vault at any time directly through the application. If you choose to delete your Formi account, all routing connections and authentication tokens are immediately and permanently destroyed.

Your Privacy & Cookies

We use strictly necessary cookies to ensure the secure operation of your personal OS. We do not use third-party tracking. Read our Cookie Policy.