Formpost

Privacy Policy

Last updated 3 August 2026

This policy explains what Formpost does with the data that passes through it — both yours and your visitors'. It is written to be read, not to be skimmed past.

1.Two kinds of data

Formpost handles two distinct kinds of information, and they are governed differently. Account data is what you give us to run your account: your email address, your form settings, and billing records. Submission data is what your visitors send through your forms.

For submission data we act as a processor on your behalf. You decide what your form asks for, how long it is kept, and when it is deleted. We process it to deliver it to you and to run the spam checks you enabled — nothing else.

2.What we collect

Account data: your email address, authentication records, plan and usage counters, and — if you subscribe — a customer reference held by our payment processor. We never see or store full card numbers.

Submission data: the fields your form sends, plus limited request metadata used for abuse prevention — IP address, user agent, and the referring page. Metadata is shown to you alongside the submission and is removed when the submission is.

3.How we use it

To deliver submissions to the address you configured, to apply the spam controls you turned on, to enforce plan limits, to bill you if you are on a paid plan, and to respond when you contact support.

We do not use submission content to train models, we do not build advertising profiles of the people who fill in your forms, and we do not sell any data to anyone.

4.Retention and deletion

Submissions are retained according to your plan: thirty days on Free, one year on Pro, and until you delete them on Business. You can delete an individual submission, or an entire form and everything attached to it, at any time from the dashboard.

Deleting a form removes its submissions permanently and immediately. Notification emails already delivered to your inbox are yours and are not affected.

Account data is deleted when you close your account, except records we are legally required to keep, such as invoices.

5.Service providers

We use a small number of processors to run the service: a managed database and authentication provider, a transactional email provider to deliver notifications, and a payment processor for subscriptions. Each is bound by a data processing agreement and receives only what it needs to perform its function.

If you enable webhooks or a chat integration, submissions are also sent to whichever destination you configured. What happens to the data after it arrives there is governed by that service, not by us.

6.Security

Data is encrypted in transit and at rest. Access to production systems is restricted and audited. Access keys are scoped to a single destination address, so a leaked key cannot be used to read your submissions or redirect them elsewhere.

No system is perfect. If we ever become aware of a breach affecting your data, we will tell you promptly and describe what happened.

7.Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. The dashboard covers most of this directly — export and deletion are self-service.

For anything the dashboard does not cover, write to hi@formpost.ai and we will respond within thirty days.

8.Your obligations to your visitors

You control what your form asks for, so you are responsible for telling your visitors how their information will be used and for having a lawful basis to collect it. If your form asks for sensitive information, that responsibility is heavier — please make sure you actually need it.

9.Changes

If this policy changes materially, we will update the date at the top and notify account holders by email before the change takes effect.