Privacy policy
Last updated 30 September 2026 · Bionic Forms is made by Bionics LLC · Questions: matt@bidwellhq.com
What we collect
- Account details. Your name, email address and a hashed password — or, if you sign in with Google or Facebook, the name and email their sign-in shares with us. We never see those passwords.
- The data you put in your apps. Records, files and app designs you or your team create. It is yours; we store and sync it to run the service and for no other purpose. Apps keep a full revision history by design — deleting a record removes it from views, while deleting an app removes the app's data outright.
- Billing. Payments run through Stripe. Card numbers go to Stripe directly and never touch our servers; we keep the subscription status.
- Devices. The desktop app registers each device you approve, so sync knows who is allowed to ask.
- Plain visit counts. Our own first-party record of how visitors reach this site (the page you landed on, where the link came from). No cross-site tracking and no advertising identifiers. The one outside script that records visits is the support chat, next.
- The support chat. The chat bubble in the corner is run for us by Coasting (their privacy policy). Its code loads from coasting.app on every page, which tells them your IP address and which page you were on — that is true of any hosted script and we would rather say it than not. We have also switched on their visitor tracking, so on every page they receive the page’s title, the site you came from, your browser and screen size, and a signal every thirty seconds while the tab stays open. That is how we see which pages people are on. It is not tied to an advertising identifier and it does not follow you to other sites. If you open the chat, they also receive your messages, any name or email you type, and the page you are on, so that we can answer you. Until September 2026 this page said we had not switched this on and would not; we changed our minds, and would rather say so than quietly edit the sentence.
The AI assistant
When you ask the assistant to build or change an app, we send your request to Anthropic, who run the model that answers it. So that the answer is about your app rather than a generic one, we send the app's name, its document types, fields and views, and the titles of recent records alongside your message.
The contents of your records are not sent. The assistant works from the shape of your app, not from what is in it. Titles go because they are how the assistant can tell a "Customer" from an "Invoice" in your own words — but a title can itself be a customer's name, so it is worth knowing that is what leaves.
That paragraph is about the assistant. There is one other way record contents can reach the model, and it only happens if you ask for it. A workflow step can put a question to the AI — "is this message urgent?", "sort this into one of these three piles" — and a question like that is written by you, in a workflow you build yourself, naming the fields it should look at. When such a step runs on one of your records, the contents of that record's named fields go to Anthropic with the question. Nothing is guessed on your behalf: an app with no AI step in any workflow sends no record contents at all, and the workflow screen shows you the sentence the step was built from. It is still never used to train models, and the answer comes back into your own app.
We do not use anything you send the assistant to train models, and we do not send it anywhere else. If you would rather nothing at all left your machine, the desktop app works without the assistant.
We do keep a copy of assistant conversations to check the quality of the answers. Your message and the assistant's reply are stored on our servers for 90 days and then deleted automatically. We read them for one reason: to find answers that were wrong or unhelpful and fix them. Only we can see them, they are never shared or sold, and they are still never used to train models. If you would like yours deleted sooner, email support@bionicforms.com and we will remove them.
Where your data lives
The desktop app is local-first: its databases are encrypted files on your own computer, with the keys protected by your operating system's secure storage. Apps also sync to your account, so a copy of your records is on our servers as well — that is what puts the same app on your other devices and in a browser, and what means losing the laptop does not lose the data. The local copy is what makes the app work with no connection; you can remove it from a given machine, and that app then reads live from the server instead.
Anonymous public forms
A form set to “anyone, anonymously” records no name, no email address and no network address — the page says so, and the server keeps that promise. Rate limiting for those forms uses a one-way hash, so raw addresses are not held even in memory.
We send transactional email through Resend: receipts, sign-in verification, invitations, and notifications you configure in your own apps' workflows. Workflow email can only go to an app's own owner and members — the platform refuses arbitrary recipients, so it cannot be used to send bulk or cold email. We do not send marketing email.
Google Sheets import
When you paste a link to a Google Sheet, we fetch that sheet once, over HTTPS, only to build the import you started. If you later connect Google Sheets with your Google account, we will access only the spreadsheets you pick, only to import or sync them into your app. Bionic Forms' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is never used for advertising and never sold.
Who else touches data (subprocessors)
- Stripe — payments.
- Resend — transactional email delivery.
- Google / Meta — only if you choose their sign-in, or import a Google Sheet.
- Our hosting provider — runs the servers the hosted service lives on.
That is the whole list. No data brokers, no ad networks.
Your choices
- Export your apps at any time — Settings offers a full portable copy (design and every record).
- Delete an app and its hosted data goes with it.
- Delete your account yourself, from inside the app: open your profile (your avatar, top right) and choose Delete account. It removes your account, every app you own and everything in them, and cancels your subscription first. It cannot be undone, so export anything you want to keep before you do it. If an app you own has other members, we stop and tell you which, so nobody else loses their work. Deleted data leaves the live service straight away; copies stay in our nightly database backups for up to 30 days and are then deleted for good.
- Email matt@bidwellhq.com if you would rather we deleted it for you, or to ask anything this page doesn't answer. A real person reads it.
Changes
If this policy changes, the date at the top changes with it. Material changes get an email to account holders.