Privacy policy
Koaform is a form builder. That means two very different kinds of data pass through it, and this policy keeps them separate throughout — your account, and the answers strangers give to your forms.
Last updated 11 August 2026
The short version. We collect the minimum needed to run the service. We do not sell data, we do not advertise, and we never use the answers submitted to your forms for anything except delivering them to you. You can export or delete your data at any time.
Two roles, and why the difference matters
Under the GDPR and similar laws, whoever decides why personal data is collected is the controller; whoever handles it on their instructions is the processor. Koaform is both, depending on the data:
| Data | Our role | What that means |
|---|---|---|
| Your account — email, name, the forms you build | Controller | We decide what to collect and why. This policy governs it. |
| Answers people submit to your forms | Processor | You are the controller. You chose the questions, you decide why you are asking them, and you are responsible for telling your respondents what you do with their answers. We only store and deliver them to you. |
If you collect personal data through a koaform form, your own privacy notice — not this one — is what your respondents are entitled to read.
What we collect
If you build a form without an account
You can build a form before signing up. When you do, we set a cookie holding a random identifier so we can give your draft back to you, and we store the draft itself. We do not know who you are. Anonymous drafts and their cookies are deleted 30 days after you last touch them.
If you create an account
- Email address — your identity and how you sign in.
- Name, if you provide one — used to address you in email.
- Your forms and their responses, until you delete them.
- Sign-in sessions. The session token in your browser is stored on our side only as a SHA-256 hash, so a copy of our database cannot be used to sign in as you.
If you sign in with Google, we request only openid, profile and email — enough to know who you are. We do not request access to your Gmail, Drive, Calendar or contacts, and we cannot read them. You can revoke access at any time in your Google account settings.
From people who fill in your forms
Their answers, the time of submission, and a hashed version of their IP address. The hash is used to stop one machine flooding a form with thousands of submissions; it cannot be turned back into an address. Respondents do not need an account and we do not build profiles of them.
Automatically
- Server logs — request paths, timings, status codes and hashed IPs, kept briefly for debugging and abuse investigation.
- Form view counts — a daily tally per form, so you can see how many people opened it. Not tied to individuals.
Where your data is stored
Koaform runs on Google Cloud in us-central1, in the United States. If you or your respondents are in the EU or UK, this means personal data is transferred outside your jurisdiction. We rely on the European Commission's Standard Contractual Clauses with our providers for those transfers. We are telling you plainly rather than burying it: if EU-only data residency is a requirement for you, koaform does not currently offer it.
Data is encrypted in transit with TLS, and encrypted at rest by Google Cloud.
Who else touches the data
We use a small number of subprocessors. Each does one job, and we share only what that job needs.
| Provider | What for | What it sees |
|---|---|---|
| Google Cloud | Hosting, database, file storage | Everything, as our infrastructure provider |
| Resend | Sending email — sign-in codes, response notifications | Recipient address and message content |
| Cloudflare Turnstile | Telling humans from bots on public forms | IP address and browser signals, at the moment of the check |
| Microsoft Clarity | Understanding how the builder is used | Interactions inside the app only. Response content is explicitly masked — see below. |
| Plausible | Marketing site visitor counts | Aggregate page views. No cookies, no cross-site tracking, no personal data. |
A specific note on session recording
Microsoft Clarity records how the builder is used so we can find confusing parts of the interface. The responses table and the single-response view areexplicitly masked before anything is sent: every cell was typed by a stranger and may be a home address, a salary or a medical detail, and none of it belongs in a session replay. Clarity does not run on public form pages at all, so filling in someone's form is never recorded.
What we never do
- Sell or rent your data, or your respondents' data, to anyone.
- Show advertising, or build advertising profiles.
- Read your form responses, except when you ask us to for support.
- Email your respondents on our own behalf. Notification emails go toyou, at the verified address on your account — never to an arbitrary address someone types into a form.
How long we keep things
| Data | Kept |
|---|---|
| Anonymous drafts | 30 days after last edit, then deleted automatically |
| Sign-in sessions | 30 days, extended as you use it |
| Sign-in codes | 15 minutes, and destroyed once used |
| Forms and responses | Until you delete them, or you close your account |
| Email delivery logs | Kept to diagnose bounces |
Your rights
If you are in the EU, UK, or a jurisdiction with comparable law, you have the right to access, correct, export, delete, or restrict the processing of your personal data, and to object to it. In practice:
- Access and export — your responses export to CSV from the app at any time. For account data, email us.
- Correction — change your name in account settings; email us to change your sign-in address.
- Deletion — delete individual responses or whole forms in the app. To close your account entirely, email us and we will remove your data.
If you are a respondent wanting your answer removed, please contact the person whose form you filled in — they control that data, and we act on their instructions. If you cannot reach them, write to us and we will help.
You also have the right to complain to your local data protection authority.
Children
Koaform is not directed at children and we do not knowingly collect their personal data. If you use a form to collect data from children, that is your responsibility as the controller, and additional laws may apply to you.
Security
- TLS in transit; encryption at rest.
- Session tokens stored only as hashes, so they cannot be replayed from a database dump.
- Uploaded files belonging to respondents are held in private storage with public access prevented at the bucket level, not merely by application code.
- Bot protection and rate limiting on every public endpoint.
No system is perfectly secure. If you believe you have found a vulnerability, please email us before disclosing it publicly.
Changes
If we change this policy in a way that materially affects you, we will email account holders rather than quietly editing the page. The date at the top always reflects the current version.
Questions about anything here? Emailsupport@koaform.com and a person will answer.