Log in / Register

Transparency and control

Privacy & cookies

This notice explains how forMika processes the data needed to coordinate shared gatherings and which browser technologies it uses.

Last updated: 28 July 2026
ControllerData we processDietary dataProvidersRetentionCookiesYour rights

01

Controller and contact

The data controller for the free service available at https://www.formika.app is Lorenzo Castiglione, established in Italy. Contact address for privacy requests: privacy@formika.app.

02

Data processed and purposes

  • Identity and session: user identifier, verified email, display name, language, acceptances and security data.
  • Gathering data: title, description, date, place, attendance, menu, quantities, contributions and shared updates.
  • Technical data: IP address, requests, errors and operational metadata processed by infrastructure and security providers.

The usual legal bases are performance of the requested service, compliance with legal obligations and the legitimate interest in protecting and maintaining a reliable service. Consent-based processing is identified separately.

03

Allergies and dietary requirements

Allergies, intolerances and some dietary requirements may reveal health-related or other sensitive information. Sharing them is always optional: a person can participate without providing them.

  • Sharing with other people in the gathering requires a separate explicit confirmation and may use the person's name or a summary without profile association.
  • Including the data in the minimized context sent to OpenAI when the host asks Mika for a review requires an additional optional choice.
  • OpenAI does not receive participant names in Mika’s context. It receives only attendance, authorized requirements and the summarized menu state.
  • Consent can be withdrawn from the profile by removing the information or disabling its use by Mika; the change is applied to active gatherings.

The intended legal basis is explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR. Withdrawal does not affect processing carried out before consent was withdrawn.

04

Providers and recipients

Supabase
Authentication, sessions, database and access control.
Cloudflare
Hosting, delivery, network protection, Turnstile and minimized operational logs.
Google Places
Place autocomplete through server-to-server calls; the typed query and a random session token are sent to Google.
OpenAI
Generation of Mika’s private reviews using a minimized context without participant names.

Some providers may process data outside the European Economic Area under the transfer mechanisms set out in their respective data-processing agreements.

05

Retention and security

Gathering data is retained while the gathering or controlling identity remains active, unless deleted earlier or retained to meet legal obligations. Sessions end on logout, revocation or configured expiry. Workers Logs are sampled and automatic URL invocation logs are disabled; Cloudflare documents a maximum retention of 3 days on Free or 7 days on Paid.

OpenAI requests use store:false so response application state is not retained. Security and abuse-prevention logs under the OpenAI agreement may still apply. Results saved by forMika remain in the gathering database.

06

Cookies and technical technologies

forMika currently uses no analytics, advertising or profiling cookies. Cookie consent is therefore not requested; the initial notice is informational only.

Name/technologyPurposeDurationServiceCategoryConsent
formika_localeChosen interface language1 yearforMikaTechnical / functionalNo
formika_privacy_noticeRemembers that the technical-cookie notice was closed180 daysforMikaTechnical / functionalNo
sb-<project-ref>-auth-token and chunksMaintains the authenticated Supabase sessionBrowser limit up to 400 days; actual session ends on logout, revocation or configured expirySupabase through forMikaStrictly necessaryNo
…-code-verifierTemporarily completes secure PKCE email authenticationNormally removed when the authentication flow completesSupabase through forMikaStrictly necessaryNo
formika_pending_invite (localStorage)Returns the person to the invitation after authentication or email confirmationUp to 30 minutes; removed when usedforMikaStrictly necessary / functionalNo
Turnstile tokenProtects registration, login and recovery flows from automated abuse5 minutes, single use; no cf_clearance cookie in the current configurationCloudflareStrictly necessary securityNo
Google Places session tokenGroups autocomplete requests for one place selectionMemory only, until selection or page closureforMika / GoogleFunctionalNo
Cloudflare NEL policyAllows the browser to report network failuresUp to 7 days when enabled; not a cookieCloudflareTechnical diagnosticsNo

If optional technologies are introduced, they will remain disabled by default and this interface will be replaced or expanded with granular, revocable choices.

07

Rights and complaints

Where provided by the GDPR, you may request access, correction, deletion, restriction, portability and objection, and withdraw consent at any time. You may also lodge a complaint with your competent data-protection authority.

Privacy contact: privacy@formika.app

Use of the service is also governed by the Terms & conditions.

Back to forMika

Powered by Mika

Privacy & cookiesTerms & conditionsSupport
Only technical cookies, for now.

forMika uses technical cookies for language, secure sessions, form protection and to remember this notice. No analytics, advertising or profiling cookies are active.

Privacy & cookies