← Back

Security

Written for whoever has to sign this off. If something you need is missing, ask — you’ll get a straight answer.

Who can read responses?

The account that owns the form, and anyone that account has explicitly shared it with. Access is checked on every page and every download against the signed-in account — never against knowing a URL.

How do we remove someone who leaves?

The owner removes them from the form and access stops immediately. No password changes, no moving data.

Is data encrypted?

In transit over TLS, and at rest by the database and file storage. Backups are separately encrypted with AES-256 before they are written.

Where is it hosted?

In the United States.

What about backups?

The database is dumped nightly, encrypted, and kept for fourteen days. Restores are scripted and have been tested rather than assumed.

How long is data kept?

You decide, per form: responses can be deleted automatically after 30, 90, 180 days, a year or three, or kept until removed. The sweep runs nightly and does not depend on anyone visiting the page. A single response can also be deleted on its own, and deleting a form removes every response and the original document with it. Files generated for printing or download are deleted after a day.

Does anything leave your systems?

When an uploaded PDF has no form fields of its own, the blank document is read once by a third party to work out the questions. Responses are never sent anywhere, and nothing sent is used to train anything. Notification emails name the form, never the answers.

Can we get our data out?

Yes — every response as a spreadsheet, as individual PDFs, or as your original document with the answers filled in. No export fee, no request to make.

What happens if there is a breach?

You are told, with what we know and what we are doing, rather than after an investigation concludes.

What we don’t have yet

A data processing agreement, and the list of companies we rely on, are available on request. Ask for them.