FormProof

Privacy policy · FormProof desktop

Your forms stay yours.

This policy describes the FormProof native desktop application. FormProof is designed so its complete Local mode works without an account, network connection, or cloud processing.

Local mode

Subject records, pack data, check sessions, findings, and form images are stored on your device. Payloads are encrypted with AES-256-GCM. A passphrase is optional. By default, a random unlock secret is saved in Windows Credential Manager or macOS Keychain. If you add a passphrase, FormProof derives its wrapping key with Argon2id and removes automatic device unlock. Record identifiers, versions, and update times may remain unencrypted so the local database can manage them; values derived from personal data are not used as plaintext indexes.

Image and OCR processing

OCR and image preprocessing run on your device. FormProof does not upload form images to an OCR provider. Decrypted image pixels exist in memory while you review them and are removed when the session closes or the vault locks. FormProof does not capture your screen, enumerate windows, or request screen-recording permission.

Optional sync and accounts

You can connect the trips.quest account you already use and import copies of its saved people and supported documents. The browser handles sign-in and sends the desktop app a time-limited, device-scoped credential; FormProof does not receive or store your website password. Imports are additive: they write into the encrypted vault on this device and do not change or delete website data. Disconnecting removes the device credential but keeps data you already imported. The separate advanced encrypted-transport feature stores end-to-end encrypted blobs, wrapped key material, record identifiers, versions, sizes, timestamps, device identifiers, and the sharing graph.

Exports and sharing

When you explicitly export a report or subject data, the selected file may contain plaintext personal information. It is written only to the location you choose. Local share bundles and encrypted backups are designed to remain encrypted and signed. You are responsible for protecting exported plaintext reports.

Retention and deletion

Local data remains on your device until you delete a subject, session, image, or the application data. FormProof provides data export and record deletion from the desktop app. Removing a subject also removes that subject’s local sessions and encrypted image blobs. Returning from Synced to Local mode keeps the local vault and requests deletion of the account's FormProof database rows and encrypted Storage objects before the app signs out. If that request fails, the app stays connected so you can retry rather than claiming deletion succeeded.

Diagnostics

FormProof does not put subject field values into diagnostic metadata. A production crash-reporting feature, if introduced, will be opt-in and documented here before activation.

Contact and changes

Material changes will be published on this stable page and called out in release notes. Questions can be directed through tanziro.com.

Effective 30 July 2026 · FormProof 0.1