FormProof

Privacy policy · FormProof desktop

Your forms stay yours.

This policy describes the FormProof native desktop application. FormProof is designed so its complete Local mode works without an account, network connection, or cloud processing.

Local mode

Subject records, pack data, check sessions, findings, and form images are stored on your device. Payloads are encrypted with AES-256-GCM. A passphrase is optional. By default, a random unlock secret is saved in Windows Credential Manager or macOS Keychain. If you add a passphrase, FormProof derives its wrapping key with Argon2id and removes automatic device unlock. Record identifiers, versions, and update times may remain unencrypted so the local database can manage them; values derived from personal data are not used as plaintext indexes.

Image and OCR processing

OCR and image preprocessing run on your device. FormProof does not upload form images to an OCR provider. Decrypted image pixels exist in memory while you review them and are removed when the session closes or the vault locks. FormProof does not capture your screen, enumerate windows, or request screen-recording permission.

Optional sync and accounts

If you choose Synced mode, the service stores end-to-end encrypted record and document blobs, wrapped key material, and operational metadata: your account email and creation time, record identifiers, versions, sizes and timestamps, device identifiers, and the sharing graph. A complete database compromise can expose that metadata, but not plaintext form fields or images. Signing in controls transport; it does not unlock the local vault. Email magic link and Google are the only sign-in methods.

Exports and sharing

When you explicitly export a report or subject data, the selected file may contain plaintext personal information. It is written only to the location you choose. Local share bundles and encrypted backups are designed to remain encrypted and signed. You are responsible for protecting exported plaintext reports.

Retention and deletion

Local data remains on your device until you delete a subject, session, image, or the application data. FormProof provides data export and record deletion from the desktop app. Removing a subject also removes that subject’s local sessions and encrypted image blobs. Returning from Synced to Local mode keeps the local vault and requests deletion of the account's FormProof database rows and encrypted Storage objects before the app signs out. If that request fails, the app stays connected so you can retry rather than claiming deletion succeeded.

Diagnostics

FormProof does not put subject field values into diagnostic metadata. A production crash-reporting feature, if introduced, will be opt-in and documented here before activation.

Contact and changes

Material changes will be published on this stable page and called out in release notes. Questions can be directed through tanziro.com.

Effective 28 July 2026 · FormProof 0.1