Back to home
Legal

Privacy Policy

We built FormSnapp to be a tool you can trust. This policy explains exactly what data we collect, why we collect it, and how we keep it safe. No legal maze — just plain language.

Last updated:

Overview

FormSnapp ("we", "us", "our") operates the FormSnapp form-builder platform, including the website at formsnapp.com, the dashboard at app.formsnapp.com, and the form-renderer at forms.formsnapp.com.

This Privacy Policy describes how we handle personal information when you use our services. By using FormSnapp, you agree to the practices described here.

The short version: you own your data. We process it only to run the service. We never sell it, and we never will.

Information we collect

Account information. When you sign up, we collect your name, email address, and a profile picture (if provided via Google sign-in). This information is stored in our database to identify your account.

Form content. Forms you build — including titles, questions, logic rules, and settings — are stored so we can render them to your respondents.

Response data. When someone fills in your form, we store their answers on your behalf. You are the controller of this data; we process it only as instructed by you.

File uploads. If your form includes a file-upload field, uploaded files are stored in Cloudflare R2 object storage and linked to the response record. You are responsible for any personal data contained in uploaded files.

Usage & technical data. We collect anonymised usage events (pages visited, features used) and error reports to understand how the product is being used and to fix bugs. This data does not identify you individually.

Payment data. If you upgrade to a paid plan, payment is processed by Dodo Payments. We never see or store your full card number. We receive only a plan identifier and subscription status.

How we use it

We use the information we collect to:

  • Provide, maintain, and improve the FormSnapp platform
  • Authenticate your account and keep it secure
  • Deliver responses and notifications to you as configured
  • Process payments and manage your subscription
  • Send transactional emails (e.g. new response notifications, receipts)
  • Diagnose errors and monitor platform health
  • Understand how features are used so we can build better ones
  • Comply with legal obligations

We do not use your form content or your respondents' answers to train AI models, for advertising, or for any purpose other than running the service you signed up for.

Data sharing

We do not sell, rent, or trade your personal information. We share data only with the sub-processors required to operate FormSnapp:

  • Google Firebase — authentication (sign-in, session management)
  • MongoDB Atlas — primary database (forms, responses, accounts)
  • Cloudflare R2 — file upload storage
  • Resend — transactional email delivery
  • Upstash Redis — rate limiting and short-lived caches
  • Inngest — background job queue for notifications and webhooks
  • Dodo Payments — payment processing and subscription billing
  • Anthropic — AI form generation (prompt sent to API; responses not retained by Anthropic for training under our enterprise agreement)
  • PostHog — anonymised product analytics
  • Sentry — error monitoring and crash reporting

All sub-processors are bound by appropriate data processing agreements. We review them regularly and update this list when our stack changes.

We may disclose information if required by law, court order, or to protect the rights, property, or safety of FormSnapp, our users, or the public.

Data retention

We keep your account data and form content for as long as your account is active. If you delete a form, its responses are permanently deleted within 30 days.

If you close your account, we delete your personal data within 60 days, except where we are required to retain it for legal or financial compliance (e.g. billing records, which we keep for 7 years in line with standard accounting requirements).

Response data submitted by your respondents is subject to your own retention decisions. You can delete individual responses or clear all responses from a form at any time from your dashboard.

Security

We take the security of your data seriously:

  • All data is encrypted in transit via TLS 1.2+
  • Data at rest is encrypted by our storage providers (MongoDB Atlas, Cloudflare R2)
  • Authentication uses short-lived session cookies (httpOnly, Secure, SameSite=Lax)
  • Rate limiting and bot protection are applied to all form submission endpoints
  • Access to production systems is restricted to authorised personnel

No system is perfectly secure. If you discover a security issue, please disclose it responsibly by emailing navjotsumandev@gmail.com.

Your rights

Depending on where you are located, you may have the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to fix inaccurate or incomplete data
  • Deletion — request that we delete your personal data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to certain types of processing
  • Restriction — ask us to limit how we use your data while a dispute is resolved

To exercise any of these rights, email us at navjotsumandev@gmail.com. We will respond within 30 days. We may ask you to verify your identity before acting on a request.

Cookies & analytics

FormSnapp uses a small number of cookies:

  • fs_session — an httpOnly session cookie used to keep you logged in. It does not track you across sites.
  • PostHog analytics cookies — anonymised usage tracking to help us improve the product. No personal identifiers are sent.

We do not use advertising cookies, cross-site tracking pixels, or third-party marketing cookies. If you disable cookies, you will not be able to stay logged in.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or with an in-app notice.

Your continued use of FormSnapp after changes are published constitutes your acceptance of the updated policy.

Contact

If you have any questions about this Privacy Policy or how we handle your data, please reach out:

  • Email: navjotsumandev@gmail.com
  • Response time: within 5 business days