Privacy Policy

Last updated: 27 July 2026 · Русский · Español

This Privacy Policy explains how Formora ("we", "the app") handles your data when you use the iOS application. Formora keeps your health information on your device and, when you use the backup, in your own iCloud — we run no servers that hold your measurements, photos or cycle data. This document tells you exactly what is stored, where, and what you can do about it.

1. Who runs the app

Formora is an independently developed iOS application. If you need to reach us, write to krispo.dev@gmail.com.

2. What data the app handles

2.1 Measurements you enter

The body measurements you record yourself — weight, body fat, lean mass, circumferences (chest, waist, hips, thigh, etc.), height, and any custom measurements you add — are saved in the app's local database on your iPhone. They are never sent to us or to any third party. A copy is placed in your own iCloud if the backup is on; see §2.9.

2.2 Progress photos

Photos you take or import as progress photos are stored in the app's private container on your device. They are never shared with us, and are deleted when you delete the photo from the app or uninstall it. If the backup is on, each photo is also encrypted and copied to your own iCloud; see §2.9.

2.3 Apple Health (HealthKit)

If you turn on Apple Health sync in Settings, Formora reads weight, body fat percentage, lean body mass, height, and waist circumference samples from Apple Health, and writes the matching measurements you save in Formora back to Apple Health.

If you also turn on cycle sync, Formora reads your menstrual flow records from Apple Health in order to draw period days and cycle phases on your charts. This access is read-only: Formora never writes period or cycle data back to Apple Health.

HealthKit data is exchanged directly between the app and the iOS Health database — it never reaches us. You can revoke read or write access at any time in iOS Settings → Health → Data Access & Devices → Formora.

2.4 Cycle data

If you use the cycle features, the app works out your period start dates and cycle phases and shows them on your measurement charts. This information comes from one of two places: the menstrual flow records it reads from Apple Health (§2.3), or the cycle day you record yourself alongside a measurement.

The cycle day you enter is stored as part of that measurement record, which means it is kept and backed up on the same terms as every other measurement (§2.1, §2.9). Cycle phases beyond a recorded period start are estimates the app calculates on your device; they are not medical predictions.

Menstrual data is treated as sensitive health information. It is never sent to us, never included in analytics or crash reports, and never shared with any third party.

2.5 Profile data

You may optionally enter a name, gender, date of birth, and height so the app can compute BMI, body fat, and lean mass. These values are stored locally, are never transmitted to us, and are included in your own iCloud backup if it is on (§2.9).

2.6 Subscriptions (PRO)

If you purchase a PRO subscription, the purchase is processed by Apple's App Store using the Apple ID associated with your device. We rely on RevenueCat (a third-party service operated by RevenueCat Inc.) to validate purchases and check subscription status. RevenueCat receives an anonymous device identifier and the Apple transaction receipt for that purpose — no personal information, no measurements, and no photos. See RevenueCat's privacy policy.

2.7 Diagnostic data

If a crash occurs, an anonymised crash report (technical details such as the file name and line where the crash happened, iOS version, and device model) may be collected to help us fix the issue. These reports contain no measurements, photos, cycle data, or personally identifiable information. Crash reports are only sent if you enabled anonymous diagnostics (the same consent as §2.8 — off by default) and can be disabled at any time in the app's Settings.

2.8 Anonymous usage analytics

The app sends anonymous usage events (e.g. "user opened the Statistics screen", "user tapped a locked PRO feature") to PostHog Cloud (EU region, hosted in Frankfurt) so we can understand which parts of Formora are used and where people get stuck. Each event carries:

No measurement values, photos, cycle data, names, dates of birth, or weights are ever sent. The legal basis for this processing under GDPR is your consent: analytics is off by default and only starts after you tap “Allow” on the consent screen shown during onboarding. You can withdraw consent at any time in Settings → Privacy → Send anonymous usage data, which immediately stops new events and clears the per-install identifier from our analytics backend.

2.9 iCloud backup and sync between your devices

Formora keeps an encrypted backup in your own iCloud Drive storage, so you can restore everything on a new iPhone and so your devices stay in step with each other. This is on by default and can be turned off at any time in Settings → iCloud Backup.

What is worth knowing about it:

3. What we do NOT collect

4. How long data is kept

Your measurements, photos, profile and cycle data stay on your device until you delete them or uninstall the app.

If the iCloud backup is on, a copy also stays in your own iCloud storage until you delete it (§5). Because the app retains up to 7 daily and 4 weekly snapshots, a record you delete on your device can remain inside a retained snapshot for up to roughly a month before that snapshot is dropped.

Subscription receipts are kept by Apple and RevenueCat for the lifetime of the subscription as required for billing and compliance.

5. Deleting your data

On your device. Settings → Data & Backup → Reset all data removes every measurement, photo and preference from the iPhone you are using. Uninstalling the app also removes its local data container, including the database and stored photos.

In iCloud. Neither of those deletes the backup, and neither removes the encryption key from your iCloud Keychain. If you want the iCloud copy gone as well:

If you would rather not do this yourself, write to us and we will walk you through it — but note that we cannot delete it for you: the data is in your iCloud account, which we have no access to.

6. Data security

On the device, data is stored in the app's private container, protected by iOS file-system encryption when your device is locked. In iCloud, the backup is encrypted with AES-GCM before upload, and the key is held in your iCloud Keychain rather than by us (§2.9).

Because your data lives in your own device and your own Apple account, its security depends on the security of those — we recommend a strong passcode, Face ID / Touch ID, and two-factor authentication on your Apple ID.

7. Children

Formora is intended for users aged 13 and over. We do not knowingly collect data from anyone under 13. If you believe a child has used the app and entered data, please contact us so we can advise.

8. Your rights

Because your data lives on your device and in your own iCloud, you control it directly: view it in the app, edit any record, export everything to CSV/PDF (PRO), or delete it at any time (§5). If you live in the EU/EEA, the UK, or California, you may also email us to ask what diagnostic data tied to your device (if any) we hold; we will reply within 30 days.

9. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes will be highlighted in the app's release notes.

10. Contact

For privacy questions: krispo.dev@gmail.com.