FormPilot

Privacy & data use

Updated 25 September 2026 — version 1.2.0 draft

What the extension processes

FormPilot reads files you select or text you paste, and the labels and values of form controls on the page you ask it to scan. It uses that information to suggest values for your review. It does not submit the form automatically.

On your device

Pasted text and plain-text files are initially read on your device. When you scan a form, the source text and field labels are sent over HTTPS to FormPilot for matching. Small matching requests are processed in memory. Large matching and document jobs use the encrypted queue described below. The extension keeps loaded document text and the current filling plan in side-panel memory. Removing a source clears the current filling preview. Document questions and answers remain in panel memory until New form or panel closure. Language preference and an account connection token are saved in Chrome local storage. You can remove extension data through Chrome or by removing the extension.

Document extraction

PDF, Office and image files selected for extraction are transmitted over HTTPS to the FormPilot service. The legacy extraction endpoint processes bytes in memory. The new background processing API temporarily stores encrypted uploads and results. Infrastructure logs may contain request metadata such as IP addresses and request times. Do not upload information you are not authorized to process.

Optional desktop transfer and document questions

If you enable Desktop, the separately installed local helper reads labeled editable fields in the window you select. Field labels and source documents are sent to FormPilot for matching. Existing desktop field values and window titles are not sent in matching requests. Reviewed values are sent to the local helper only after confirmation; it does not press Save or Submit. The native helper keeps scan state in memory and requires a new scan after a completed transfer. Document questions are sent with the loaded source text through the same matching service and use the processing allowance. They do not execute application actions.

Older DOC/XLS/PPT documents may be processed by an administrator-configured internal Apache Tika service. That service may use temporary storage during parsing; it must be configured with appropriate cleanup and access controls before deployment.

Cloud OCR

When the administrator selects GLM-OCR, uploaded PDF, JPG and PNG bytes are sent to Z.ai for text and table recognition, including PDFs that already contain text. This is independent of the matching model setting. Z.ai processing is subject to its service terms. Table output is treated as document text, not executed HTML. There is no automatic fallback to another provider. With Tesseract selected, OCR runs on the FormPilot server instead.

AI processing

When AI matching is enabled, source text and field labels are sent through the server to the explicitly configured provider (Google Gemini or OpenAI) to extract supported answers. Review all suggestions. Processing counters and token totals are stored without source text. There is no automatic fallback to a different provider. Up to three processing batches per included form are available per billing period. Large-document extraction and matching consume this allowance per batch.

Google sign-in

If you choose Google sign-in, Google authenticates you and provides your verified email address and account identifier. FormPilot stores these to create or link your account. We do not request Gmail, Drive or Calendar access. Google access tokens are used temporarily to verify your identity and are not stored. Login state expires after 10 minutes; account sessions last up to 7 days. Google sign-in is separate from optional Gemini document processing.

Accounts, usage and payments

The service stores your account identity, trial start, subscription status, billing period and usage records to enforce your allowance. Usage requests contain a one-way fingerprint generated on your device, not the document text or page address. Authorized administrators can view account identity and usage totals. Stripe processes payment details; the extension does not receive your full card number.

Web table rows

In the table beta, you select a target table and an optional Add row button. After reviewing column mappings and confirming, FormPilot can add missing blank rows and fill their fields. It does not press Save or Submit, but a target application may autosave field changes. If a transfer stops midway, already created rows or filled cells may remain.

Background jobs and application integrations

Explicitly uploaded documents, structured application data, matching inputs and results are encrypted at rest in the job queue. Jobs expire after 24 hours and are deleted by the active cleanup worker. APIs refuse access after expiry even if cleanup is delayed. Completed extension-created jobs are deleted after retrieval. Deleting a running job stops it at a subsequent checkpoint; a provider request already sent may finish. Infrastructure backups may retain encrypted records according to the operator’s backup policy. API keys are stored only as hashes, expire after 30 days, are scoped and can be revoked. Connected applications can read jobs belonging to the same account using their granted scopes. Exporting a visible web form requires confirmation and stores its labels and values in that account’s queue. No destination URL is fetched from imported data.

Choices and contact

Review and edit suggested values before confirming. Use subscription management to manage billing. For access, correction or deletion requests, or questions about data processing, contact [email protected]. Billing records may need to be retained where applicable requirements require them.

Türkçe özet

Yapıştırılan metin ve düz metin dosyaları önce cihazınızda okunur; form tarandığında kaynak metin ve alan etiketleri eşleştirme için HTTPS üzerinden FormPilot sunucusuna gönderilir, Büyük belge ve API işleri kuyrukta en fazla 24 saat şifreli saklanır; API üzerinden erken silinebilir. PDF, Office ve görseller metin çıkarımı için FormPilot sunucusuna gönderilir. GLM-OCR seçiliyse PDF/JPG/PNG dosyalarının tamamı tablo ve metin okuma için ayrıca Z.ai hizmetine gönderilir; bu seçim eşleştirme modelinden bağımsızdır. Dil tercihi ve hesap bağlantı anahtarı Chrome yerel depolamasında tutulur. Hesap, abonelik ve kullanım kayıtları kota kontrolü için saklanır. Yönetici paneli belge içeriğini göstermez. Ödemeleri Stripe işler. Veri talepleriniz için yukarıdaki e-posta adresine yazabilirsiniz.