FormGoat

FormGoat Privacy Policy

Version: 3.0
Effective date: 23 August 2026
Applies to: formgoat.ai, FormGoat Chrome Extension, FormGoat DS-160 Desktop App (Windows / macOS), PDF Goat

This English version is the governing version of this Policy. Translations into other languages are provided for convenience only; in the event of any discrepancy, this version prevails (section 11).


1. Data controller

The controller of personal data (the "controller", "we", "us") is:

Pavel Kanakhistov — sole trader (autónomo)
NIF: Z1825610J
Country of establishment: Spain
Postal address: available on request (contact below)

Contact for privacy matters, the exercise of your rights, and complaints: [email protected]. This address serves as the single point of contact under every data-protection regime applicable to the Service (section 13).

A representative in the EU under Article 27 GDPR is not required — the controller is established in the EU (Spain).


2. What data we collect

2.1. User profile and account sign-in

  • Name and email address — from Google where you sign in with Google.
  • Google account identifier.
  • Sign-in by one-time email code. If you sign in with a code, we store your email address, a cryptographic hash of the code (the code itself is never stored in clear text), its validity period — 10 minutes — and a counter of the attempts made to enter the code. The record is deleted immediately upon a successful sign-in or on expiry.
  • Abuse-prevention records: counters of the frequency of code requests, tied to the address and to the Service as a whole.
  • Registration date, plan, remaining balance.

We neither receive nor store your password under any sign-in method.

2.2. Subscription and transaction data

  • Plan, payment history, invoices.
  • Payments are processed by Stripe; your card details do not reach us and are not stored by us. From Stripe we receive a customer identifier, the subscription status and invoice data.

2.3. Document and application data

The documents you upload (passports, questionnaires, official certificates and statements, bookings, previous applications and the like) are processed using OCR and AI in order to extract data. In connection with providing the Service we process:

  • the uploaded files — until their automatic deletion (section 4);
  • the application profile — structured data derived from the documents;
  • page-level application data — which fields have been completed and with what values;
  • bulk-import data — where you upload a consolidated spreadsheet (Excel / CSV) we store the original "field name — value" pairs for each person, in order to use them when completing the application. Such a file will typically contain the data of many individuals (section 2.5);
  • the DS-160 security question answer — if you save it, we store it on the server together with the application so that it is available to you from any device and is entered automatically. This answer is required in order to retrieve the application on ceac.state.gov; treat it as an access credential. Storage and deletion are governed by section 4;
  • the provenance of each value — the document from which it was obtained.

2.4. Special categories of data (Article 9 GDPR)

Documents used to complete visa and other official forms may contain special categories of personal data — in particular data revealing racial or ethnic origin (nationality, place of birth, a name in a national alphabet) and, in certain cases, biometric data (photographs in documents).

We process such data solely on the basis of your explicit consent (Article 9(2)(a) GDPR), which you give when uploading documents. You may withdraw your consent at any time by deleting the relevant data or your account; withdrawal does not affect the lawfulness of processing carried out before it.

2.5. Third-party data and use through an agency

You may upload documents containing the data of other persons — relatives or clients, where you use the Service as an agent, migration adviser or other representative, including through the bulk import of a consolidated spreadsheet. In that case you act as the controller of such data and you warrant that you have a lawful basis for processing it: that you are the data subject, their legal representative, or that you have obtained their explicit consent (including consent to special categories of data under Article 9 GDPR).

We process such data as a processor on your instructions, solely for the purposes of the services you request from FormGoat. A data processing agreement (DPA) is available to business users on request. In the terminology of Indian data-protection law, in this scenario you are the Data Fiduciary and we are a Data Processor.

2.6. Improving the quality of the Service

We may use data processed in the course of providing the Service in order to improve the quality of our algorithms and of the Service in general, including the development and training of our models.

For these purposes we use data in de-identified form: identifying elements (names, document numbers, dates of birth, addresses and other direct identifiers) are removed before use. To the extent that such data is anonymous, it falls outside the scope of the GDPR. Beyond that, we rely on legitimate interests (Article 6(1)(f) GDPR) — the improvement of the Service — and apply technical and organisational data-minimisation measures. You may object to this processing (Article 21 GDPR) by writing to us.

2.7. Fill-quality telemetry

In order to understand where the algorithm goes wrong, we record for each completed field the fact alone: whether a value was suggested and whether the user changed it, together with the model's confidence, the source of the value, and the identifier of the form page.

Field values are not included in telemetry — neither those suggested nor those corrected. We separately record the fact that the App encountered an unfamiliar page structure, so that we are able to release support for the changed form.

The log of network requests in the DS-160 App is kept in the memory of your device only and serves the purpose of self-diagnosis; it is not transmitted to the server. You may copy it and send it to us yourself when contacting support — in which case you control precisely what is sent.

The legal basis is legitimate interests (Article 6(1)(f) GDPR) in maintaining the operability and quality of the Service.


3. Legal bases for processing (Articles 6 and 9 GDPR)

Category of dataPurposeLegal basis
Account profileAuthentication, administration of the accountPerformance of a contract — Art. 6(1)(b)
One-time sign-in codes (hash)Verifying control of the email address at sign-inPerformance of a contract — Art. 6(1)(b)
Request-frequency countersPreventing abuse and the sending of codes to third-party addressesLegitimate interests — Art. 6(1)(f)
Subscription and balancePlan management, billingPerformance of a contract — Art. 6(1)(b)
Ordinary document and application dataCompleting forms at your requestPerformance of a contract — Art. 6(1)(b)
Security question answerAuto-filling the answer into the application form, and access to the saved form from any devicePerformance of a contract — Art. 6(1)(b)
Special categoriesCompleting visa and other official formsExplicit consent — Art. 9(2)(a)
Fill-quality telemetry (no field values)Detecting errors of the algorithm and changes to the formLegitimate interests — Art. 6(1)(f)
De-identified dataImproving and training algorithms, quality of the ServiceLegitimate interests — Art. 6(1)(f); anonymous data outside the scope of the GDPR
Payment recordsCompliance with tax and accounting lawLegal obligation — Art. 6(1)(c)
Consent recordsDemonstrating consentLegal obligation — Art. 6(1)(c), Art. 7(1)
Analytics (cookies)Improvement of the ServiceConsent — Art. 6(1)(a)
Dispute resolution, securityProtection of rights and prevention of abuseLegitimate interests — Art. 6(1)(f)

We do not sell your data and do not use it for behavioural advertising. Every form-filling outcome requires human review; we do not take solely automated decisions producing legal effects within the meaning of Article 22 GDPR.


4. Retention periods

CategoryPeriodNote
User profile (name, email, account)Until the account is deletedRetained while the account is active
Uploaded files14 days from uploadAutomatic deletion
Extracted data, application profiles, page data1 yearAutomatic scheduled deletion
Bulk-import data (spreadsheets)1 yearDeleted together with the application data
Security question answerUntil the application or the account is deleted, and no longer than 1 yearDeleted together with the application data
Fill-quality telemetry (flags, no field values)Retained while the account exists; de-identified on deletionContains no field values; on deletion of the application form or the account the link to you ceases to exist (section 9)
One-time sign-in codes10 minutes, or until a successful sign-inOnly the hash is stored
Request-frequency countersup to 24 hoursOperational records
Consent recordsTerm of the account plus the limitation periodEvidence of consent (Art. 7(1) GDPR)
Payment records and invoices6 years (Código de Comercio, Art. 30)Legal obligation; not deleted on request before that period expires

Product specifics

Chrome Extension: the uploaded file — 14 days; the application profile — 1 year.

DS-160 Desktop App: application data — 1 year. Under the BUSINESS plan the retention period is agreed individually and may be indefinite, in which case the data is retained until the application or the account is deleted. Where an application is deleted manually, all personal data relating to it, including the security question answer and the page data, is destroyed without undue delay; a record containing no personal data is retained for statistical purposes.

PDF Goat: working session — 24 hours; application profiles — 1 year.

Outdated document data is deleted automatically on a schedule. The user profile and payment records are not affected by that process.


5. Recipients and processors

To provide the Service we engage processors — service providers processing data on our instructions (where, under section 2.5, we act as your processor, they are sub-processors). With each of them a data processing agreement (Article 28 GDPR) has been concluded or accepted. The categories of recipients are disclosed below; those with whom you interact directly are named.

Category of recipientRegion
Application hosting and databaseEU (Netherlands)
Document recognition (OCR) and AI data extractionUSA
Payment processing — StripeUSA
Email delivery, including sign-in codesUSA
Site protection and content delivery (CDN)Global network
App stores — Microsoft Store, Chrome Web StoreUSA
Web analytics — Google Analytics · cookie consent — iubenda (only after consent)USA · EU

The contents of uploaded documents are received only by the OCR and AI providers, by hosting and by the database; the other categories do not receive them. The set of OCR and AI providers may change — the requirements placed upon them and the transfer safeguards under section 6 remain the same.

A current full list of providers is available on request at [email protected], and to business users as part of the DPA, together with the procedure for notification of a change of sub-processor.


6. International transfers

Hosting and the database are located in the EU (Netherlands) — no transfer outside the EU/EEA takes place in respect of them. The providers of OCR and AI, payment processing, email delivery and the CDN process data in the USA or outside the EU/EEA. In respect of such transfers we ensure the safeguards of Chapter V GDPR: Standard Contractual Clauses (SCC) approved by the European Commission, and/or certification of the recipient under the EU-U.S. Data Privacy Framework (DPF). A copy of the safeguards and a list of recipients may be requested at [email protected].


7. Security

We implement appropriate technical and organisational measures in accordance with Article 32 GDPR:

  • encryption in transit — HTTPS / TLS on all connections;
  • encryption at rest at the infrastructure level — managed databases and disk volumes are encrypted by the infrastructure provider;
  • authentication via OAuth 2.0 / OpenID Connect and one-time codes — we neither receive nor store your password; one-time codes are stored as a hash only;
  • secure authorisation tokens and verification of the owner of the data on every request;
  • isolation of user data;
  • rate limiting and protection against automated abuse;
  • minimisation: fill-quality telemetry contains no field values, and the App log does not leave your device.

No system affords absolute security. In the event of a breach entailing a risk to your rights, we will notify the supervisory authority within 72 hours (Article 33) and, where the risk is high, you (Article 34). In respect of data subjects in India, the procedure in section 13 applies.


8. Your rights (GDPR)

  • Access (Art. 15) — to request a copy of your data.
  • Rectification (Art. 16) — to have inaccuracies corrected.
  • Erasure (Art. 17) — to have data deleted; the right is not absolute — payment records are retained by virtue of a legal obligation.
  • Restriction of processing (Art. 18).
  • Portability (Art. 20) — to receive your data in a machine-readable format.
  • Objection (Art. 21) to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of past processing.

To exercise your rights: [email protected]. We respond within 30 days.

Right to lodge a complaint. You have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR) — in your country of residence or in the country of the controller's establishment. The controller's supervisory authority is the Agencia Española de Protección de Datos (AEPD), www.aepd.es.


9. Account deletion

How to delete: through the App settings, or by writing to [email protected].

What is deleted: your name, email, all uploaded files, extracted data, profiles and application data across all products, including the security question answer — within 14 days of the request. Residual copies in backup storage are removed in the course of ordinary rotation. Individual processors may retain data for their own limited periods in accordance with their terms, over which we cannot always exercise control.

What is retained: payment records (for the statutory retention period, section 4) and records of the consents obtained, as evidence that they were obtained — without the contents of your documents.

Records retained for statistical purposes. We maintain a record of the volume of work performed — how many applications were processed, which models were applied, and fill-quality metrics. Upon deletion of data such records are not deleted but de-identified: the personal fields are cleared, and the record itself remains, without the contents of your documents and without data enabling you to be identified. The legal basis is our legitimate interest in record-keeping and quality control (Article 6(1)(f) GDPR), as described in section 2.6; you may object to this processing (Article 21 GDPR).


10. Minors

The account holder must be a person who has attained the age of 18 (or the age of majority in your jurisdiction). The Service may be used to process the data of minors where the account holder acts as their legal representative (for example, when completing a visa application for a child). We do not knowingly create accounts for minors, do not track the behaviour of children, and do not serve them targeted advertising.


11. Changes to this Policy

We will give not less than 14 days' notice of material changes by email. Previous versions are retained in the documentation repository.

This Policy may be translated into other languages for convenience. In the event of any discrepancy, this English version prevails, except where mandatory rules require interpretation in the language of the data subject.


12. Contact

[email protected]
Postal address: available on request.


13. Global standard and regional specifics

13.1. A single standard. We apply one standard of personal-data protection to all users, irrespective of the country in which they are located. It is based on the GDPR: the legal bases for processing, the rights of data subjects, retention periods, the requirements placed on processors, and the transfer safeguards set out in sections 2–12 apply to everyone. Where the mandatory rules of your country of residence afford you greater rights or shorter periods, those rules apply.

13.2. Roles. In different legal systems our role bears different names — controller, Data Fiduciary, controlador, responsable, owner or operator of a personal data database. The allocation of responsibilities does not change on that account: in respect of the data of your account we act as the controller; in respect of the data of your clients which you upload (section 2.5) you are the controller and we act as processor, processing that data only on your instructions.

13.3. Where to turn. First, to [email protected]; we respond within 30 days at the latest. If our response does not satisfy you, you have the right to lodge a complaint with the supervisory authority of your jurisdiction, where local law provides for one. The controller's supervisory authority is the Agencia Española de Protección de Datos (AEPD), Spain, www.aepd.es; if you are in the EU/EEA you may also lodge it with the authority of your country of residence.

13.4. Regional specifics. Certain legal systems add the following to the baseline standard.

  • India (Digital Personal Data Protection Act, 2023) — the right to obtain a summary of the personal data processed and details of the recipients, and to nominate another person to exercise your rights in the event of death or incapacity; grievances are made through the contact above and thereafter to the Data Protection Board of India; on request we will provide this Policy in any language specified in the Eighth Schedule to the Constitution of India.
  • Latin America — in Brazil (LGPD) you have the right to request a review of a decision taken solely by automated processing: the Service takes no such decisions, final values being reviewed by a person (section 3), but we will consider any such request and provide an explanation. In Mexico this Policy serves as the aviso de privacidad, and the ARCO rights — access, rectification, cancellation, objection — are exercised through the same contact.
  • Kazakhstan — processing is carried out on the basis of your consent in the form provided for by local legislation. The legislation of the Republic imposes requirements as to the place of storage of personal data; until such time as we offer the Service on terms meeting those requirements, you consent to the processing and storage of data on the servers identified in sections 5 and 6.

13.5. Other countries. If the law of your country of residence confers rights not listed above, you may exercise them by writing to [email protected]. We apply the baseline standard in 13.1 and comply with the mandatory rules applicable to the processing of your data.