Skip to content

HOW FORMLY HANDLES YOUR DATA

Privacy notice.

Your account

For email accounts, Formly stores your verified email, display name and a salted password hash. It does not store your password in plain text. Verification and reset emails are delivered through the configured mail provider; links expire after 20 minutes. Password reset ends all sessions for that email account.

When you sign in with Google or GitHub, Formly stores your provider’s account identifier, name, email when available, and avatar URL when provided. We use this information to recognize your account and associate your cloud designs with you. Formly does not ask for or store your Google or GitHub password.

Accounts from different providers are kept separate, even when their email addresses match.

Your designs and AI requests

Cloud storage includes design names, prompts, model source, parameters, completed STL files, version history, job status, and generation usage records. AI generation sends your modeling request and relevant model context to the configured AI service. Avoid including passwords or unrelated sensitive information in modeling requests.

Reference images are uploaded when you send a message, resized and stored with the design, and sent to the configured AI service for discussion, generation and review. Camera metadata is removed. Image access requires the owning account.

Template designs saved locally are stored in your browser. They are not automatically uploaded to your cloud account.

Sessions and browser storage

Browser storage also remembers your selected interface language.

Formly uses a session cookie to keep you signed in, and a short-lived cookie to verify a sign-in attempt. Browser storage remembers local templates and the current account identity so open tabs can respond to account changes. Logging out ends the current session; it does not delete your cloud designs or your locally saved templates.

Site usage statistics

Formly records first-party page visits on its main public pages to help the operator monitor use. It stores the page path, time, broad device and source categories, and the signed-in account identifier when present. A random tab identifier is hashed with a daily key; full URLs, query strings, raw IP addresses and raw browser identifiers are not stored in these statistics. Records are kept for up to 90 days, with a limit of 200,000 visits. The browser Do Not Track setting disables this collection. Account last-visit times are retained with the account. Server access logs are separate from these page statistics.

Access and retention

Cloud designs and reference images are accessible through their owning account. Deleting a design permanently removes its versions, conversations and reference images from active storage. The operator can access stored data for maintenance; protected operational backups may retain earlier data. Self-service account deletion is not currently available.

Google, GitHub, and the configured AI service handle information under their own policies. This notice may be updated as Formly’s features change.

Back to Formly →