Security and compliance
A plain-language overview of how formaster.app handles data and the controls available today.
Data handling
formaster.app is designed for local document work. PDFs and completed form data stay on your device during normal use. Optional AI placement sends page content through formaster.app’s server to its AI provider, minus any areas you hid; the server passes it on and does not store it. formaster.app has no server-side storage of your documents: the only things it stores on a server are account, credit and subscription records, and only about the account you sign in with.
Security controls
What formaster.app does to protect your data today:
- Your documents are processed in your browser; there is no upload step for ordinary editing and export.
- The AI provider’s key is held only by formaster.app’s server. It is never sent to your browser, and when the AI fails, what you are told leaves out the provider’s address and what it said.
- The server talks to the AI provider over https:// (unless the model runs on the server’s own network), so its key is not sent unprotected.
- The AI instructions are kept on the server, and the server checks every request: who is asking, whether their plan includes the AI, how large the request is and whether there are credits for it. Credits are checked and charged before the AI is asked, in a way that two requests at once cannot spend the same credit, and each person’s requests are rate-limited.
- Payments are handled entirely by Paddle; formaster.app never sees your card details. Whether a subscription is active is checked with Paddle by formaster.app’s server whenever you use the AI (an answer is reused for up to a minute, and if Paddle can’t be reached the last saved record is used for a while), so a failed payment takes effect within moments. A cancelled subscription keeps its plan until the end of the period you paid for.
- Signing in is handled by Firebase Authentication. The account database cannot be reached from browsers at all: only formaster.app’s server reads or writes it, and only after Firebase has confirmed who is asking.
- Areas you hide from the AI are painted over before the page picture is made, and their text is removed before the request is built.
- You can delete your documents, templates, signatures and saved settings from this device on the privacy page.
What you are responsible for
Browser storage is controlled by your browser and device. formaster.app does not encrypt what it stores there, so anyone who can use your browser profile can read it. Protect your device, avoid shared profiles for sensitive documents, and delete local data when appropriate. Decide whether you are comfortable sending a page to the AI at all, and hide what you would rather not send.
Compliance status
formaster.app does not claim certification under SOC 2, ISO 27001, HIPAA, or another independent security or privacy audit. This page describes current product behavior; it is not a certification, audit report, or promise that a particular regulatory regime applies.
formaster.app is not designed as a healthcare records system, and you should not treat it as a HIPAA-compliant service. Organizations remain responsible for assessing whether their use of formaster.app and its AI provider meets their legal, contractual, and internal requirements.
Responsible use of AI
AI-generated field placements require human review. You are responsible for verifying document contents and for having permission to process documents through formaster.app’s AI provider.