Privacy policy · FormProof desktop
Your forms stay yours.
This policy describes the FormProof native desktop application. FormProof is designed so its complete Local mode works without an account, network connection, or cloud processing.
Local mode
Subject records, pack data, check sessions, findings, and form images are stored on your device. Payloads are encrypted with AES-256-GCM. A passphrase is optional. By default, a random unlock secret is saved in Windows Credential Manager or macOS Keychain. If you add a passphrase, FormProof derives its wrapping key with Argon2id and removes automatic device unlock. Record identifiers, versions, and update times may remain unencrypted so the local database can manage them; values derived from personal data are not used as plaintext indexes.
Image and OCR processing
OCR and image preprocessing run on your device. FormProof does not upload form images to an OCR provider. Decrypted image pixels exist in memory while you review them and are removed when the session closes or the vault locks. FormProof does not capture your screen, enumerate windows, or request screen-recording permission.
Optional sync and accounts
If you choose Synced mode, the service stores end-to-end encrypted record and document blobs, wrapped key material, and operational metadata: your account email and creation time, record identifiers, versions, sizes and timestamps, device identifiers, and the sharing graph. A complete database compromise can expose that metadata, but not plaintext form fields or images. Signing in controls transport; it does not unlock the local vault. Email magic link and Google are the only sign-in methods.
Exports and sharing
When you explicitly export a report or subject data, the selected file may contain plaintext personal information. It is written only to the location you choose. Local share bundles and encrypted backups are designed to remain encrypted and signed. You are responsible for protecting exported plaintext reports.
Retention and deletion
Local data remains on your device until you delete a subject, session, image, or the application data. FormProof provides data export and record deletion from the desktop app. Removing a subject also removes that subject’s local sessions and encrypted image blobs. Returning from Synced to Local mode keeps the local vault and requests deletion of the account's FormProof database rows and encrypted Storage objects before the app signs out. If that request fails, the app stays connected so you can retry rather than claiming deletion succeeded.
Diagnostics
FormProof does not put subject field values into diagnostic metadata. A production crash-reporting feature, if introduced, will be opt-in and documented here before activation.
Contact and changes
Material changes will be published on this stable page and called out in release notes. Questions can be directed through tanziro.com.
Effective 28 July 2026 · FormProof 0.1