Request Forms

Request Forms privacy policy

How Request Forms handles account data, form answers, and public crawlers.

Request Forms stores the account you create (email, optional name, optional avatar) and the forms you save. Published forms collect answers that you choose to request. File uploads go to our file storage. Payment fields use Stripe Connect. Money goes to the organization's Stripe account. We do not sell form answers as a data product.

Session cookies authenticate the website. The public site loads the Atributi tracker from atribusi.com. It records page events and session replay. It does not run on localhost. Assistants connect through the hosted MCP server with OAuth. We store OAuth client records, consent grants, and hashed access and refresh tokens so we can revoke them. API keys are organization secrets. You can revoke a key on the organization page. Public form pages are reachable without an account. Do not put secrets in a published form. Webhook URLs you configure receive submit payloads that you chose to send.

Public marketing pages, docs, pricing, templates, and compare tables are meant to be crawled. robots.txt allows search and AI crawlers. /llms.txt lists the pages we want agents to read. Markdown is available on those pages when the client sends Accept: text/markdown. Private workspace routes under /app require sign-in and are not a public corpus.

To ask a question about stored account data, or to request deletion of an account you own, email [email protected] from that account address. Password login must work, or you must complete the reset flow first. This page describes the product as it works on requestforms.io. It is not legal advice for your respondents.