Privacy policy

What we collect, why, who else handles it, and how to have it removed.

Last updated 5 October 2026

chatform is a form builder at chatform.in. This policy covers two groups of people: those who create an account to build forms, and those who answer a form somebody else built.

If you answered a form

The person or business that built the form decides what it asks and what happens to your answers. We store and process those answers for them. To see, correct or delete what you submitted, ask the form’s owner first. If you cannot reach them, contact us and we will pass the request on.

What we collect

From people with an account

  • Your name, email address and, if you set one, a password. We store the password as a hash, never as text.
  • If you sign in with Google: your name, email address and profile picture.
  • Your organization, its workspaces and the teammates you invite.
  • What you make: forms, themes, images, and any files you add to a form’s knowledge base.
  • Your plan and billing status. Card details go to our payment provider and never reach our servers.

From people answering a form

  • The answers, any files uploaded, and the conversation the form had with you.
  • When the response started and finished.
  • The page the form was opened on, the page that linked to it, and any campaign tags in the link.
  • Your country and your browser and device type.
  • A device signal computed in your browser. It is used to hand a half-finished response back to you and to notice the same device answering twice. It is scrambled differently for every form.
  • If the form asks you to sign in: your Google name, email address and picture, or the phone number or email address you verified.
  • If the form takes a payment: the amount, its status and the payment reference. The payment itself happens on the form owner’s own Stripe, Razorpay or Cashfree account. We never see card or bank details.

From everyone

  • Requests reach us with an IP address. We use it for short-lived rate limiting and to work out a country, and some records keep a hashed form of it.
  • Page views on our own website, counted by us.
  • On our website and dashboard we also load Google Tag Manager, the Google Ads tag and Microsoft Clarity, which records how pages are used. None of these load on the forms people answer.

What we use it for

  • Running the product: showing forms, storing responses, and showing results to the form’s owner.
  • Having the AI draft forms, ask questions and read answers.
  • Sending email: sign-in codes, notifications, receipts, and the follow-ups a form owner sets up.
  • Billing, enforcing plan limits and stopping abuse.
  • Working out what to fix and what to build next.

We do not sell personal data. We do not use your forms or your responses to train AI models.

How the AI handles your data

When a form is drafted or answered, the relevant text (the questions, the answers so far, and passages from the form’s knowledge base) is sent to an AI model to produce the next reply. Requests go through OpenRouter to Google’s Gemini models. Knowledge base files are indexed with Cloudflare’s AI services. A record of each AI request is kept in Langfuse so we can watch cost and quality.

Information from Google

We ask Google for information in three situations, and only when you start them.

  • Signing in to chatform with Google. We receive your name, email address and profile picture, and use them to create and show your account.
  • Signing in to answer a form with Google. When a form requires it, we receive the same three things and show them to the form’s owner beside your response.
  • Connecting Google Sheets. When you press Connect Google Sheets on a form, we ask for permission to see, edit, create and delete only the specific Google Drive files you use with chatform. We use it to create one spreadsheet for that form and to write the form’s responses into it. We cannot see any other file in your Drive.

For the Google Sheets connection in particular:

  • We store an access token, encrypted, so we can keep the sheet up to date. We store nothing from your Drive.
  • We read only the header row and the first column of the sheet we created, to find where each response belongs.
  • We do not use this access for advertising, and we do not use it to train AI models.
  • We do not share it with anyone, except Google itself when writing to your sheet.
  • Nobody at chatform reads your sheet, unless you ask us to for support, or it is needed for security or to comply with the law.
  • To remove access, press Disconnect on the form, or remove chatform at myaccount.google.com/permissions. The sheet stays in your Drive.

chatform’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Who else handles it

These companies process data for us so the product can work:

  • Cloudflare: hosting, databases, file storage, email delivery and AI indexing.
  • OpenRouter and Google: the AI models.
  • Langfuse: records of AI requests.
  • Resend: email delivery.
  • Google Firebase: sending and checking the SMS code when a form verifies a phone number.
  • Dodo Payments: payment for chatform plans.
  • Google and Microsoft: Tag Manager, the Ads tag and Clarity on our website and dashboard.

A form owner can also send responses elsewhere: to Google Sheets, to their own server through webhooks, to an AI assistant they connect, or to their own payment provider. Those are their choices, and those services handle the data under their own terms.

We may disclose data when the law requires it. If chatform is ever sold or merged, data moves with it under this policy.

Where it is kept

On Cloudflare’s network, and with the providers above, some of whom are in the United States and other countries. Your data may be processed outside the country you live in.

How long we keep it

  • Forms and responses: until the form’s owner deletes them or deletes their account.
  • A deleted form: kept for 30 days so it can be restored, then erased with its responses.
  • A deleted account: kept for 30 days so it can be recovered, then erased.
  • Test responses made in the builder’s preview: 30 days.
  • Webhook delivery records: 30 days.

Your choices

  • See and export your responses from the results page of any form.
  • Delete a response, a form, or your whole account from the dashboard.
  • Stop follow-up emails with the unsubscribe link in each one.
  • Disconnect Google Sheets or any other connection from the form’s Integrate tab.

Depending on where you live, you may have the right to access, correct, delete or move your personal data, or to object to how it is used. Contact us and we will respond.

Cookies

We set a cookie to keep you signed in and remember your display preferences. The Google and Microsoft tools named above set their own cookies on our website and dashboard.

Security

Data is encrypted in transit. Credentials for services you connect, such as Google Sheets or a payment provider, are encrypted before they are stored. No system is perfectly secure, and we will tell you if a breach affects your data.

Children

chatform accounts are for adults. Form owners are responsible for who their forms are aimed at and for any consent that requires.

Changes

When this policy changes we update the date at the top. For a change that matters, we also email account holders.

Contact

Questions and requests go through the contact page.