LLendForma

AI intake and privacy

AI can organize the story. You control the statement.

LendForma separates conversation, structured validation, and form mutation so a model cannot silently write into your financial statement.

What the live interview sends

After consent and microphone permission, browser audio travels to OpenAI over an encrypted WebRTC connection. A minimized statement index supplies section names, row names, current amounts, and stable identifiers so the interview can recognize duplicates or conflicts. It excludes applicant names, addresses, Social Security numbers, dates of birth, signatures, full account numbers, and row details.

What LendForma retains

Raw audio and working transcripts are not stored by LendForma by default. Only user-approved changes and operational metadata—such as model, request ID, latency, token use, and status—are retained. OpenAI states that API data is not used to train its models by default; abuse-monitoring logs may retain content for up to 30 days unless separate retention controls apply.

Review is the mutation boundary

  • The interview can ask questions but cannot directly edit the statement.
  • Structured validation produces editable proposal cards.
  • Conflicts and ambiguities must be resolved rather than guessed.
  • Accepted proposals apply together as one restorable revision.
  • If the statement changes concurrently, stale proposals are rejected for re-review.

Document extraction

When enabled, a user-submitted PDF or image is sent transiently to OpenAI to propose supported facts. LendForma does not retain the binary as a document vault. Approved facts may keep a sanitized source label, confidence, date, and one-way fingerprint. “Document-backed” is not the same as bank-verified.

Keep identity data out of AI intake

Do not speak, type, or upload more personal information than the workflow needs. Avoid Social Security numbers, dates of birth, signatures, full account numbers, and unnecessary applicant names or addresses.

Start a free PFS →