Legal

Privacy Policy

How Phorma Labs collects, uses, and protects your data

Last updated: 05/08/2026

1. Overview

Phorma Labs (“Phorma”, “we”) builds Phorma Agent Studio, a desktop application and optional cloud service for designing, debugging, and deploying multi-agent AI workflows.

This policy explains what we collect, why we collect it, and what choices you have.

It applies to the phorma-labs.com website, the Phorma Agent Studio desktop app, and Phorma Cloud.

2. Local-first by design

  • The desktop Studio runs on your machine. Workflows, run traces, and prompts you create locally are stored locally on your device by default.

  • API keys and provider credentials you enter in the desktop app are stored in your operating system’s secure credential store on your machine. They are not transmitted to Phorma Labs.

  • You can build and run workflows locally, for example against Ollama, without an account.

3. Information we collect

a) Information you provide

  • Account details: name, email address, and authentication identifiers when you create an account or sign in.

  • Billing details: handled by our payment processor. We receive limited billing metadata such as plan, status, and the last four digits of a card. We do not store full card numbers.

  • Support and sales correspondence you send us.

b) Information collected automatically

  • Website analytics: pages visited, referrer, approximate location derived from IP address, device type, and browser type.

  • Product telemetry from the desktop app: version, operating system, crash reports, and aggregate feature usage.

  • Download and update check requests.

Website analytics are provided by [Google Analytics] and our hosting request logs are kept by [Cloudflare]. Desktop telemetry is opt-in. It is off until you turn it on, and you can turn it off again at any time in Studio under Settings, then Privacy. Crash reports are only sent when telemetry is enabled.

c) Information processed when you use Phorma Cloud

  • Workflow specifications you choose to deploy.

  • Run inputs, outputs, and execution traces generated by deployed workflows.

  • Connection credentials you store for cloud execution, held encrypted at rest.

d) Information we do not collect

  • We do not sell personal data.

  • We do not use your workflow content or run data to train our own models.

4. How we use information

  • Provide, operate, and secure the Studio, the website, and Phorma Cloud.

  • Authenticate users and manage subscriptions and credits.

  • Diagnose crashes, fix bugs, and improve reliability and performance.

  • Communicate about releases, security notices, and support requests.

  • Detect and prevent abuse, fraud, and security incidents.

  • Comply with legal obligations.

If you are in the EEA or the UK, we rely on these legal bases: performance of a contract, to give you the service you signed up for; legitimate interests, to keep the service secure and reliable; consent, for analytics and marketing email; and legal obligation, where the law requires us to keep or disclose data.

5. Model providers and your prompts

  • When you configure a model provider such as Anthropic, OpenAI, Google Gemini, OpenRouter, Ollama, Agent Studio, or Phorma Cloud inference, your prompts and workflow data are sent to that provider under the provider’s own terms and privacy policy.

  • For local providers such as Ollama and Agent Studio, data stays on your machine.

  • Where you use your own API keys, Phorma acts as a conduit. The provider is an independent controller of that data.

  • Phorma Cloud inference on credits is routed through [OpenRouter] for model access, [Cloudflare] for execution and networking, and [Stripe] for payment. Please review their privacy policies for details on how they handle data.

  • We recommend that you avoid sending sensitive personal data in prompts unless your agreement with the provider permits it.

6. Sub-processors and third parties

We use a small number of service providers to run Phorma. Each one only handles the data it needs.

Provider

Purpose

Data handled

Location

Cloudflare

Hosting, Workers, Durable Objects, CDN, DDoS protection

Workflow specs, run data, request logs

Global edge network

Stripe

Subscription billing

Billing metadata

United States, EU

Clerk

Authentication

Account identifiers

United States

Google Analytics

Website analytics

Usage events

United States, EU

Gmail

Transactional and product email

Name, email address

United States

We maintain an up-to-date list of sub-processors and will give notice of material changes before they take effect.

7. Data retention

  • Account data is retained while your account is active and for 14 days after closure.

  • Run traces and workflow versions in Phorma Cloud are retained per your plan’s retention setting, currently [14 days], and are deleted on request.

  • Crash reports and analytics are retained for 12 months in aggregate form.

  • Local desktop data lives on your machine until you delete it.

8. Security

  • Data is encrypted in transit with TLS, and stored credentials and run data are encrypted at rest.

  • Credentials are stored outside workflow specifications, in a dedicated connections store.

  • We use access controls, least-privilege internal access, and audit logging.

No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify you and any relevant regulator without undue delay, and within 72 hours where the law requires it.

9. Your rights and choices

  • Access a copy of the personal data we hold about you.

  • Correct data that is wrong or out of date.

  • Delete your data, subject to legal retention limits.

  • Port your data to another service in a common format.

  • Restrict or object to certain processing.

  • Withdraw consent for analytics or marketing at any time.

To exercise any of these rights, email hello@phormalabs.com. We respond within 30 days.

California residents. Under the CCPA and CPRA you have the right to know what personal information we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined, and we do not discriminate against you for exercising your rights.

EEA and UK residents. You have the right to lodge a complaint with your local supervisory authority. Where we transfer personal data outside the EEA or the UK, we rely on the Standard Contractual Clauses together with additional safeguards.

10. Cookies and similar technologies

  • Strictly necessary cookies: used for authentication and to keep your session active. These cannot be turned off.

  • Analytics cookies: used to understand which pages people visit. These are optional.

You can accept or reject analytics cookies in the cookie banner shown on your first visit, and change your choice later from the cookie preferences link in the footer. You can also block or delete cookies in your browser settings.

11. Children’s privacy

Phorma is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, email us and we will delete it.

12. Changes to this policy

We will post updates on this page and change the “Last updated” date above. If a change is material, we will give notice by email or in the app before it takes effect.

13. Contact

Phorma Labs Pty Ltd, 3217 Victoria, Australia.

Privacy questions: hello@phormalabs.com

General enquiries: hello@phormalabs.com

Phorma Agent Studio

Design agents on a canvas.
Watch them think.
Ship them to your cloud.

© 2026 Phorma Labs Pty Ltd.

ABN 48 700 243 723

All systems operational