Privacy Policy
Last updated October 2026
What this covers
This policy explains what Formac collects, why, and the choices you have. It covers three groups: people who browse the directory, developers who submit an app, and people who create an account.
Browsing the directory
Browsing needs no account. We count how many times each app page is viewed and how many times its "Visit website" button is used. These are totals per app, not a record of who you are. When you follow a link to a developer's website we add a "ref" value to the address so they can see the visit came from this directory.
Submitting an app
When you submit an app we store what you type in the form (the app's name, description, website, category and price), the icon and screenshots you upload, the developer name, your name if you give it, your email address and the IP address the form was sent from. The listing text, icon and screenshots are published when the app is approved. Your email address and IP address are never published: we use the address to write to you about the listing, and the IP address to limit abuse of the form.
Images you upload are checked, re-encoded and stored on our file storage (Cloudflare R2) at a public address. They are deleted when the listing is deleted.
The badge check
For a free listing we fetch the web page you give us and look for a link back to this directory, when you submit and about once a week afterwards. We read only that public page and store only whether the link was found and when.
Payments
Paid listings are paid for through Stripe. Your card details go directly to Stripe and never reach our servers. We store the amount, the plan, the payment status and the Stripe identifiers needed to match a payment to a listing and to refund it.
Accounts
An account is optional. If you create one we store your name, email address and your password as a one-way hash (bcrypt), never the password itself, or your Google account identifier if you sign in with Google. Listings submitted from your address appear on your dashboard once you have confirmed that address.
For each sign-in, failed attempt and password change we record the IP address, the approximate location derived from it and the browser and device type. You can see this log in your security settings. Sessions use short-lived tokens and a session token that changes every time it is used and is stored only as a hash.
Emails we send you
We email you about your listing (received, approved or not accepted, a payment receipt, the end of a featured period) and about your account (confirming your address, password resets, sign-ins from a new place). We keep a record of each of these emails (the address, the subject, when, and whether it was handed to our email provider) so we can help when one does not arrive. We do not send marketing email.
Website analytics
We may use Google Analytics to understand how Formac is used: which pages are visited, roughly where visitors are, and the browser and device type. Google sets cookies in your browser to tell visits apart. You can block it with a browser setting or extension.
Service providers
We rely on providers to run the service: a database host, Cloudflare for file storage, Stripe for payments, an email provider for the messages above (Mailgun), an IP geolocation service (ipinfo.io) for sign-in records, and Google Analytics for usage statistics.
Access by our staff
A small number of staff review submissions and can see the information sent with them, account information and sign-in records, to run the directory, provide support and prevent abuse. Every action they take on a listing or an account is recorded in an audit log.
Retention and deletion
A listing stays up until you ask us to remove it or we remove it. To have a listing removed, or to close your account and delete its data, contact support@formac.app from the address you used. Payment records and audit records may be kept after that where the law requires it.
Contact
Questions about this policy can be sent to support@formac.app.