Privacy Policy
Last updated: September 9, 2026 (V33)
Our Commitment to Privacy
Eformogi is operated by Eformogi, Inc., a Delaware corporation ("Eformogi", "we", "us"). Eformogi is built on the principle that your family's records belong to you. This policy explains exactly what data we collect, how we process it, and which third-party services are involved. We believe in transparency over marketing.
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address (for login and communication)
- Name (optional, for personalization)
- Authentication is handled by Supabase Auth
Your Record
The personal information you enter into your record (name, address, school info, and the rest) is stored in our database hosted on Supabase. A local copy is also cached in your browser's IndexedDB for performance.
Documents You Upload
Documents you upload for extraction are sent to an AI vision model, and the extracted structured data is stored in your record. On the family upload path we do not permanently store the original document images on our servers. Documents uploaded by a counselor or school on your behalf (see “Records Uploaded by Counselors and Schools” below) are stored in a private storage bucket so the counselor can work from them; they are covered by the same deletion rights as the rest of your data.
Records Uploaded by Counselors and Schools
Counselors and schools that serve your family can upload education records (for example, a prior transcript) into their Eformogi workspace to prepare plans and transcripts for you. Those files are stored in a private, access-controlled storage bucket, are processed with the same AI extraction described above, and are never shared onward without a signed, revocable consent. If you want a counselor-uploaded record removed, contact us at privacy@eformogi.com and we will delete it.
Usage Data
We collect basic usage data to improve our service:
- Features used and form fill statistics
- Error logs (to fix bugs)
- Device type and browser (for compatibility)
- IP address (for rate limiting and security, not stored long-term or used for tracking)
Consent & Sharing Data
When you share data with an organization via a consent link, we record which categories were shared, with whom, and when, creating an audit trail. This lets you track and revoke consent at any time. The organization receives only the data categories you approved.
2. How We Use Your Information
- Provide the service: Store the record, process documents, facilitate consent-based sharing
- Improve accuracy: Track fill corrections to improve field matching over time
- Communicate with you: Account updates, security alerts
- Legal compliance: Respond to valid legal requests
3. Third-Party AI Processing
Consent Receipts
When you share a record with a receiver (a college, employer, agency, or scholarship program) via an intake link, only the categories you approve are transmitted. Every share produces a consent receipt: a signed, scoped, time-bound record with purpose, duration, and downstream-sharing rules. No AI is involved in this step. It's a direct, consent-gated transfer. A full audit trail is recorded including who received the record, when, and which categories. You can revoke consent at any time. Any agent can fill a form. Only the record can prove who witnessed the work.
Document Extraction (Google Gemini AI)
When you upload a document for extraction, the document image is sent to Google's Gemini AI API to extract structured data (names, addresses, dates, etc.). The extracted data is saved to your record. The document image is processed in memory and is not stored by Google after processing.
Fallback AI Processing (OpenAI)
If Google Gemini is unavailable or returns an error, Eformogi may route your request to OpenAI's API (GPT-4o-mini) as a fallback. The same data minimization principles apply: only the information necessary for the specific task is sent. Per OpenAI's API Data Usage Policy, API inputs and outputs are not used for model training and are retained for up to 30 days for abuse monitoring, then deleted.
4. AI Agent Access (Personal API Keys / MCP)
You may issue Personal API Keys that let an AI agent of your choice (Claude, ChatGPT, or any MCP-compatible client) read from your record on your behalf. Each key has its own policy across 18 data categories. Each category is set to one of three modes:
- auto: the agent may read this category without prompting you.
- ask: the agent's request is queued for your in-app approval before any data is released.
- never: the category is blocked. The agent receives no data.
Defaults are conservative: SSN is set to never; medical, insurance, financial, legal, disability, guardian, emergency, and housing default to ask. You can change any policy or revoke any key at any time. Every read produces an audit entry visible in your account.
Eformogi does not control the agent. Once data is released to an external agent or AI client, that provider's terms and privacy policies apply to anything they do with it. We log what was released, when, and to which key, but we cannot guarantee what a third-party agent does with data after release. You are responsible for the keys you issue and for choosing agents you trust.
5. What We Never Do
- We do not sell your personal data to third parties
- We do not use your data for advertising
- We do not share your record with other users without your consent
- We do not allow AI providers to use your data for model training
6. Data Security
Here's how we protect your data today:
- In Transit: All connections use HTTPS/TLS encryption
- Database: Hosted on Supabase, which publishes a SOC 2 Type II report
- Application Hosting: Hosted on Vercel, which publishes a SOC 2 Type II report
- Authentication: Managed by Supabase Auth with secure session handling
- Audit trail: Every share, every agent read, and every consent grant is recorded as an immutable log entry you can inspect.
What we're working on: We plan to add end-to-end encryption so your record is encrypted before it reaches our database. See our Security page for our full roadmap.
Breach notification. If we confirm a security incident that compromises your private information, we will notify affected users without unreasonable delay and in any event no later than 72 hours after confirmation, by email and in-app notice. The notice will describe what was affected, what we have done in response, and what (if any) action you should take. We will also notify regulators where required by law (including the New York Attorney General under New York General Business Law § 899-aa where applicable, and equivalent authorities in other jurisdictions).
NY SHIELD Act. Eformogi, Inc. operates in the State of New York and maintains the administrative, technical, and physical safeguards required by the New York Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) for any business that holds the private information of New York residents. This includes designated security personnel, vendor due diligence (Supabase, Vercel, Google, OpenAI, Stripe), encryption in transit, access controls, and incident response procedures.
7. Where Your Data Is Processed
Eformogi's primary servers and database are hosted in the United States. Our third-party AI processors (Google and OpenAI) may process requests in any region they operate. If you access Eformogi from outside the United States, your data will be transferred to and processed in the United States. By using the Service you consent to this transfer.
8. Your Rights
You have the right to:
- Access: View all your stored data in your record.
- Correction: Update or correct your information at any time.
- Deletion: Delete your account and all associated data.
- Portability: Export your record in a structured format.
- Consent receipts: Download the signed consent artifact for any share you've made.
- Revocation: Revoke any active consent or any Personal API Key, with effect going forward.
- Objection: Opt out of non-essential communications.
To exercise these rights, contact us at privacy@eformogi.com, or use the in-app controls in Settings.
9. Data Retention
We retain your record for as long as your account is active. When you delete your account, we delete it within 30 days, except where required by law.
Audit and consent records are retained for seven (7) years after the related share or agent read, even if the underlying record is deleted. This retention period exists so you, the receiver, and regulators can verify what was shared and under what consent, which is the entire point of a record you can prove. Audit records contain only metadata (categories shared, recipient, timestamps, consent scope). They do not contain the underlying values from your record.
10. Third-Party Services
We use the following third-party services:
- Supabase: Database, authentication, and cloud infrastructure (US-hosted; Supabase publishes a SOC 2 Type II report).
- Google Gemini AI: Form field matching and document extraction (primary).
- OpenAI: Form field matching and document extraction (fallback).
- Vercel: Application hosting (Vercel publishes a SOC 2 Type II report).
- Stripe: Payment processing for paid plans, including Family Pro and paid receiver plans. Stripe receives the billing details needed to process your payment; we do not store full card numbers.
- Resend: Transactional and notification email delivery (e.g. sign-in links, receipts, deadline notes).
- Google Analytics 4: Aggregate, privacy-limited page-view analytics.
- Sentry: Error and performance monitoring to diagnose crashes.
11. Children's Privacy & Parental Data
Eformogi is designed for use by parents and guardians to manage family paperwork. We do not knowingly collect personal information directly from children under 13.
Parental management of children's data: Parents may store information about their minor children (names, school records, medical information, and the like) within their own Eformogi account for the purpose of filling out forms on their children's behalf. By storing children's data, the parent represents that they are the child's parent or legal guardian and consent to the processing described in this policy.
Children under 13: A child under 13 cannot create an Eformogi account. A parent or guardian creates the record, enters what it holds, and controls who sees it. We do not collect information directly from children, and nothing on the family side is designed for a child to use without a parent. The Children’s Online Privacy Protection Act (COPPA) is the federal law that governs how an online service collects personal information from children under 13; the practice above is how we operate.
Educational records: Eformogi is not a school or educational institution. On the family side, parents voluntarily enter educational information (grades, GPA, test scores, etc.) that they already possess and manage entirely themselves. Separately, a counselor or school working with your family may upload education records into their Eformogi workspace to serve you (see “Records Uploaded by Counselors and Schools” above). A counselor or school that uploads records into its own Eformogi workspace decides for itself what the Family Educational Rights and Privacy Act (FERPA, 34 CFR Part 99) requires of it. We use those records only to provide the service, we never sell or share them, and the counselor data processing agreement at /counselors/dpa says so in writing. We make no determination about a school’s FERPA obligations.
If you believe a child under 13 has created an account without parental consent, contact us immediately at privacy@eformogi.com and we will promptly delete the account and associated data.
12. Changes to This Policy
We may update this policy periodically. We'll notify you of significant changes via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.
13. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to know: What personal information we collect, the categories of sources, the business purpose, and the categories of third parties with whom we share it (described above).
- Right to delete: Request deletion of your personal information.
- Right to correct: Request correction of inaccurate personal information.
- Right to limit use of sensitive personal information: Eformogi does not use sensitive personal information beyond what is necessary to provide the Service. We do not use it for inferring characteristics, advertising, or any secondary purpose.
- Right to opt-out of sale or sharing: We do not sell or share personal information for cross-context behavioral advertising.
- Right to data portability: Receive your personal information in a portable format.
- Non-discrimination: We will not discriminate against you for exercising your rights.
To exercise these rights, contact us at privacy@eformogi.com. We will verify your identity before fulfilling the request and respond within 45 days.
Categories of personal information collected in the past 12 months: Identifiers (email, name); customer records (what you choose to enter into your record); commercial information (subscription status, if applicable); internet activity (basic usage telemetry); geolocation (coarse, derived from IP for security); and the categories of sensitive personal information you choose to enter (e.g., health, financial, or precise government-ID data).
14. Contact Us
Questions about privacy? Contact us: