01
Overview
The application processes information required to operate accounts, forms, responses, optional uploads and integrations, analytics, and product support. The exact controller, processor, legal basis, and retention obligations depend on the deployment and the form owner's use case.
Form owners control the questions they publish and the response content they collect. Respondents should contact the form owner directly for requests related to a specific form submission.
The source does not define one universal production retention period. Account, form, response, draft, analytics, and delivery-log records persist according to deletion and operational cleanup behavior configured for the deployment. Provider-side retention must be reviewed separately before release.
02
What We Collect
Categories of data we process.
Account Data
Information you provide when creating an account.
- Email address
- Profile name when provided
- Avatar URL when provided
- Authentication metadata
Form Response Data
Data collected through forms you create.
- Respondent answers
- Submission and draft timestamps
- Uploaded file URLs when configured
- Session and funnel identifiers
Usage Data
Information about how you use our service.
- Page and route visits
- Conversion-event properties
- Core Web Vitals
- Referrer and device information
03
Processing Services and Destinations
Infrastructure and optional destinations used by the current application.
Supabase
Provides authentication and the application database used for accounts, forms, responses, drafts, configuration, and operational logs.
Cloudflare R2
Stores respondent uploads only when file storage is configured and a published form accepts an eligible upload.
Umami
Measures anonymous pageviews, defined conversion events, and Core Web Vitals under the controls described in the Cookie Policy.
Owner-selected destinations
A form owner can configure signed delivery to a Salesforce Marketing Cloud CloudPage and mapped Data Extension workflow.
The current product does not implement advertising or data-broker workflows. Service providers process data to operate the application, while configured integrations deliver data according to the form owner's instructions. Processor terms, regions, retention, and international-transfer requirements must be approved before production.
04
Your Rights
Depending on applicable law and the organization responsible for the data, you may have the following rights.
Access
Request a copy of your personal data
Correction
Update inaccurate or incomplete data
Deletion
Request removal of your personal data
Portability
Export your data in a common format
Privacy Requests
For account-level access, correction, or deletion requests