FORM

UPDATED SEPTEMBER 20, 2026

Privacy at FORM.

FORM Geometry is a browser-based CAD workspace. This notice describes how the current preview uses information when you visit formgeometry.com, save projects, or connect an agent.

Account information

When you sign in with Google, Google shares your account identifier, email address, and basic profile information, such as your name and profile image, with our authentication provider, Supabase. We use this information to create and secure your FORM account and associate your projects with you. FORM does not request access to your Google Drive, Gmail, contacts, or calendar.

Your projects and files

Geometry is calculated in your browser. While signed in, project documents, saved revisions, and exported files are stored in Supabase under your account. New account projects are public by default, including projects created by connected agents or copied from device storage. Existing projects keep their visibility setting. Public designs share their name, object count, and a rotating 3D preview in Community, which anyone can view without signing in. Public previews update when you edit a design. You can change a design to Private in the workspace to remove it from Community. Editable source documents, saved revisions, and exported files remain private to your account. Authorized service administration may access stored data to operate the service and respond to support requests.

The browser also keeps project copies and pending changes in device storage so the editor can work quickly and recover interrupted saves. Guest projects stay in that browser unless you export them or choose to copy them into an account. Signing out ends the session but does not erase these device copies. You can remove them by clearing FORM’s site data in your browser.

Community likes

Likes require sign-in. We store one like per account and design, and show the total publicly. Your email and the identities of people who like a design are not shown in Community. You can remove your like by selecting the thumbs-up again. Making a design private stops new public preview requests; it cannot remove copies someone has already saved.

Connected agents

If you approve an OAuth agent connection or give a FORM API key to an MCP client, that client can read and edit all projects in your account. Requests, results, and operation records pass through FORM’s hosted endpoint and Supabase to your browser. You can revoke API keys and OAuth connections from Connect agent. FORM does not run an AI model for you. Information you send to an external AI service is also handled under that service’s own privacy terms.

Improving agent modeling

For signed-in agent use, FORM records first-party operational measurements: tool names, call and batch counts, retry indicators, coarse error categories, request and response sizes, waiting time, operation outcomes, and whether a saved revision changed. These are proxies for effort, not AI token counts, approval counts, or proof that a model meets your intent. We do not include prompts, argument values, project names, model geometry, screenshots, file contents, credentials, or raw error messages in these measurements.

Restricted records are linked to your account so we can enforce your preferences and delete them. Daily pseudonymous workflow and connection identifiers let us study repeated steps; these records are not anonymous. Measurements are enabled by default for signed-in agent use. You can turn off “Help improve agent modeling” in Account; this also deletes your retained measurements. Guest modeling is not included. We use the measurements to improve FORM’s tools, guidance, and geometry engine, not for advertising.

A daily cleanup deletes measurement records older than 30 days (up to 31 days between cleanup runs). Provider backups may retain earlier copies under their own retention policies. The saved projects and short-lived operation receipts needed to run the service are separate from this optional measurement system.

Contact inquiries

When you use the contact form, your name, email address, inquiry topic, message, and any organization you provide pass through FORM’s server to FormSubmit for delivery to FORM’s email inbox. We use these details to respond to your inquiry, including product questions, feedback, investment, and partnership conversations. Submitting the form does not subscribe you to marketing emails. FORM applies submission limits and spam checks. FormSubmit retains submissions for 30 days. Correspondence may remain in our inbox; you can contact us to request deletion. See FormSubmit’s privacy policy for its data practices.

Providers and technical information

Vercel hosts the websites and MCP endpoint. Supabase provides authentication, database, file storage, and live event delivery. Google provides Google sign-in. These services process the information needed to deliver their functions and may retain technical logs, including network addresses and request metadata, for operation and security. Browser storage is used for sessions and project recovery. The public FORM website uses Ahrefs Analytics to measure site visits. The first-party agent measurements described above use our existing service infrastructure.

Retention and your choices

Saved projects remain associated with your account. FORM keeps a limited revision history and operation records for recovery and troubleshooting. You can export your models, revoke agent keys, sign out, and remove local site data. To request deletion of your account and cloud projects, or ask about your information, use our contact form. A deletion request may require verifying account ownership; provider backup retention can differ from the live application’s data.

We will update this page when the service’s data practices change.

Back to FORM