Privacy Policy
Last updated: June 18, 2026.
What CFM Form Builder does
CFM Form Builder converts blank PDF clinical forms into PS Suite Custom
Form (.cfm) files. The Service is designed to operate on blank form templates
only. It does not process patient health information (PHI). Once the generated
.cfm is imported into your PS Suite EMR and the form begins auto-populating
with patient data, that data lives inside your EMR and never reaches our servers.
What we collect when you use the Service
- Account information. Your email address and authentication state.
- Billing information. If you purchase a credit pack, our payment processor issues us a customer identifier and a record of the purchase. We never see your card number.
- Uploaded blank PDFs. When you upload a PDF the file is held in a temporary location on our server for the duration of the request and is then deleted. We do not retain uploaded PDFs after the response is returned.
- Saved templates. If you choose to Save template on a form you have corrected, we store the field layout (positions, types, autopop keywords) in our database so future uploads of the same blank PDF can reuse your corrections. Saved templates contain no patient data — only the form's field geometry and the autopop keys you assigned.
- Usage records. Your credit balance, lifetime forms generated, and the SHA-1 fingerprint of PDFs you have built (used for the 5-minute grace window re-download feature).
What we do not collect
- Patient health information (PHI).
- Filled-in PDFs. The Service is designed for blank templates only; do not use the Service for filled-in forms.
Service providers we use
We rely on the following third-party providers to operate the Service. Each receives only the data they need for their specific function:
- Clerk (clerk.com) — authentication.
- Stripe (stripe.com) — payment processing.
- Render (render.com) — hosting (United States, Ohio region).
- Anthropic (anthropic.com) — only when you opt in to AI-assisted field detection. The blank PDF is sent to Anthropic's Claude API for analysis. This feature is off by default.
We do not sell your data and we do not share it with advertising or analytics providers.
Cookies
We use only the cookies needed to operate the Service. Our authentication provider (Clerk) and payment processor (Stripe) set cookies required to keep you signed in and to process payments securely. We do not use advertising or third-party analytics cookies.
How long we keep your data
We keep your account information, saved templates, and usage records for as long as your account is active, and until you ask us to delete them. Uploaded blank PDFs are not retained — they are deleted as soon as the request that processed them completes. Billing records held by our payment processor are kept as required for tax and accounting purposes.
Your rights
You may ask us to access, correct, or delete the personal information we hold about you, or to close your account. To make a request, email support@cfmformbuilder.com — this address is our contact for privacy requests. We aim to respond within 3–5 business days.
Account deletion, data questions, or other requests
Email support@cfmformbuilder.com. We aim to respond within 3–5 business days.
Changes to this policy
The "last updated" date above reflects the most recent revision. Material changes will be communicated to active account holders.