Privacy Policy

Last updated: April 25, 2026

Introduction

FormNode is a product of Symao Systems LLC ("FormNode," "we," "us," or "our"), an Indiana limited liability company operating from Valparaiso, Indiana, United States. We provide the FormNode platform at formnode.io and app.formnode.io. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

By using FormNode, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the service.

Information We Collect

Account Information

  • Email address and display name (provided at registration)
  • Authentication credentials managed via magic links or Microsoft SSO — we never store passwords
  • API key hashes — raw API keys are never stored; only cryptographic hashes are retained

Workspace and Organization Data

  • Workspace names, settings, and membership information
  • Organization names and integration mappings (e.g., external system IDs)
  • Role assignments and access control configurations

Form and Submission Data

  • Form definitions (field types, labels, and configurations)
  • Submission data entered by end users — encrypted at rest using AES-256-GCM with PBKDF2 key derivation and per-record salt
  • File uploads associated with form submissions

Usage and Operational Data

  • Form analytics (view counts, submission counts) — used for dashboard reporting
  • IP addresses for rate limiting and abuse prevention — not stored long-term
  • Webhook delivery logs — automatically purged based on your workspace retention settings

How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the FormNode platform
  • Authenticate your identity and manage access to workspaces
  • Process and deliver form submissions, including webhook and email notifications
  • Display usage analytics within your workspace dashboard
  • Enforce rate limits and protect against abuse
  • Send transactional emails (submission confirmations, magic links, approval requests)
  • Respond to support requests and communicate service updates

We do not use your data for advertising, behavioral profiling, or any purpose unrelated to delivering the service.

Data Security

Security is central to how FormNode is built. We implement multiple layers of protection:

  • Encryption at rest — All form submission data is encrypted using AES-256-GCM with PBKDF2 key derivation and a unique per-record salt
  • Edge computing — The platform runs on Cloudflare Workers, providing DDoS protection and global edge security
  • Session cookies only — We use httpOnly, secure, sameSite=lax session cookies. We do not use tracking cookies, Google Analytics, Facebook pixels, or any third-party trackers
  • API key security — API keys are hashed before storage; raw keys are never persisted
  • Role-based access control — Workspace access is governed by a multi-level RBAC system (Owner, Admin, Member)
  • Rate limiting — All endpoints are rate-limited to prevent abuse
  • XSS prevention — Input sanitization and content security policies are enforced across the platform

Cookies

FormNode uses only essential session cookies required for authentication and platform functionality. These cookies are:

  • httpOnly — Not accessible via JavaScript
  • Secure — Transmitted only over HTTPS
  • SameSite=Lax — Restricted to first-party context

We do not use advertising cookies, analytics cookies, or any form of cross-site tracking.

Third-Party Services

We use a limited number of third-party services to operate FormNode. Each is selected for its security posture and processes data only as necessary:

Cloudflare

Hosting (Workers), database (D1), file storage (R2), CDN, and DNS services. Cloudflare processes requests to deliver and protect the platform. Cloudflare Privacy Policy

Creem.io

Payment processing. Creem.io acts as the merchant of record for all transactions. We do not store credit card numbers or payment credentials — all payment data is handled entirely by Creem.io. Creem.io Privacy Policy

SMTP2GO

Transactional email delivery (magic links, submission notifications, approval requests). Workspaces on paid plans may use their own SMTP server instead. SMTP2GO Privacy Policy

Microsoft

SSO authentication via Microsoft identity platform. Used only when a user chooses to sign in with their Microsoft account. Microsoft Privacy Statement

Data Retention

  • Form submissions — Retained based on your workspace plan settings. You may delete submissions at any time.
  • Webhook delivery logs — Automatically purged based on your workspace retention policy.
  • Approval workflow instances — Expired instances are cleaned up automatically.
  • Account data — Deleted within 24 hours after subscription cancellation.
  • IP addresses — Used for real-time rate limiting only and are not stored long-term.

Your Rights

You have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Request correction of inaccurate or incomplete data.
  • Deletion — Request deletion of your personal data. Account data is automatically deleted within 24 hours of subscription cancellation.
  • Export — Export your submission data via the FormNode dashboard or REST API.
  • Data portability — Access your data programmatically through our REST API for transfer to another service.
  • Withdraw consent — You may stop using the service at any time and request deletion of your account.

To exercise any of these rights, contact us at support@formnode.io.

GDPR Compliance (European Economic Area)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Legal basis — We process your data based on contractual necessity (to provide the service you signed up for) and legitimate interests (to maintain platform security and prevent abuse).
  • Data transfers— Your data is processed on Cloudflare's global edge network. Cloudflare maintains appropriate safeguards for international data transfers.
  • Right to lodge a complaint — You have the right to file a complaint with your local data protection authority.
  • Data minimization — We collect only the data necessary to provide and secure the service.

CCPA Compliance (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to know — You may request details about the categories and specific pieces of personal information we have collected.
  • Right to delete — You may request deletion of your personal information, subject to certain exceptions.
  • Right to opt out of sale — We do not sell your personal information. We never have and never will.
  • Non-discrimination — We will not discriminate against you for exercising your CCPA rights.

Data Processing

FormNode processes data solely for the purpose of delivering the service. Specifically:

  • We do not sell personal data to third parties.
  • We do not use personal data for advertising or marketing profiling.
  • We do not share personal data with third parties except as described in the Third-Party Services section above.
  • Submission data entered by your end users is encrypted and accessible only to authorized members of your workspace.

Children's Privacy

FormNode is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at support@formnode.io and we will promptly delete the information.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of FormNode after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Symao Systems LLC
FormNode is a product of Symao Systems LLC.
Valparaiso, Indiana, United States
Email: support@formnode.io
Website: formnode.io