Formwork's AI features use a large language model to answer your questions and to draft and edit text. This page says plainly what that means for your data.
Nothing is sent unless you use an AI feature
AI features only run when you start them: sending a message to the AI Assistant, prompting the AI Document Editor, clicking an Autogenerate button, generating a QMS, or when your own AI calls Formwork through MCP. Formwork does not send your QMS to any AI provider in the background.
Who processes it
Formwork's AI features are powered by OpenAI's models, accessed through OpenAI's business API.
Your data is not used to train OpenAI's or anyone else's models.
When you connect your own AI via MCP, your data additionally goes to that AI's provider (Anthropic for Claude, OpenAI for ChatGPT and Codex, and so on) under the terms you have with them. Formwork's MCP server only answers the requests your AI makes; it does not send anything on its own.
What is sent
Only what is needed to handle your request:
- AI Assistant: your messages, and the items the assistant looks up to answer them: search results, the documents, records and items it reads, and the content it creates or edits.
- AI Document Editor: your prompt and the content of the document being edited.
- Autogenerate and generation features: the product's title, description and intended use, plus the existing items of the same kind, or the template being tailored.
- PDF conversion: the uploaded file.
- MCP: whatever your own AI asks for, which is why a read-only connection is a sensible default for exploring.
The assistant and MCP always work as you: they can only reach what your account can open, in the company you are working in.
What Formwork stores
- Assistant chats are stored per user, visible only to you, until you delete them.
- AI Document Editor conversations are stored with the draft they belong to.
- Files uploaded through the AI or MCP that are never attached to anything are removed after 24 hours.
- MCP request log: Formwork records each MCP tool call (which app or token, which tool, which item type, whether it succeeded, how long it took, and a shortened copy of the request) to keep the service reliable and to understand how it is used. File contents are never stored in this log.
Reviewable content AI creates or changes lives in Formwork as a draft and follows the same version history, review and audit trail as anything you write yourself. Where Formwork records an author, such as on documents, records and comments, it records you. Tasks, folders and other items without a review lifecycle are created directly.
What Formwork does not do
- No AI feature approves, releases, rejects, archives or deletes anything.
- No AI feature reads data from a company you are not a member of, or from restricted folders you cannot open.
- No background processing: the AI provider only ever sees data as part of a request you or your connected AI triggered.
Where the details are
- Privacy policy: https://app.openregulatory.com/privacy_policy
- Data processing agreement: available under Settings → Compliance files, including the current list of subprocessors.
- Questions from your auditor or notified body about AI in your QMS: If you're a QMS+TD subscriber you can reach out in the support chat; we are happy to provide what they need.