# Request Forms privacy policy

Last updated 16 September 2026.

This policy describes how Request Forms at requestforms.io handles personal data. It covers the website, the form builder, hosted forms, embeds, the API, the CLI, the MCP server, and related services. Support email is support@requestforms.io.

Request Forms is operated by Rami Rashid. This page is not legal advice for your respondents. You remain responsible for the questions you ask and for a lawful basis to collect those answers.

## Who this policy covers

It covers people who visit the public site, create an account, join an organization, submit a form, upload a file, pay through a form, use the assistant or help chat, or connect through the API, CLI, or MCP.

If you only submit someone else's form, that form owner is the controller of your answers. We process those answers for that owner. Ask that owner about their privacy notice. We can help the owner delete answers that we store.

## Roles

We are the controller of account data, organization data, billing records for the Request Forms plan, site analytics, help-chat transcripts, security logs, and similar records we need to run the service.

You are the controller of respondent data. That includes answers, signatures, file uploads, payment metadata tied to a form submit, and any personal data in questions, hidden fields, or webhook payloads. We are the processor of that respondent data. We process it to host the form, store responses, send notify email, export, and deliver webhooks that you configure.

If you need a written data processing addendum, email support@requestforms.io from the owner account. This policy already states the processor terms: we act on your instructions in the product, we keep respondent data confidential, we use subprocessors listed here, and we delete or return stored answers when you delete them or close the account, subject to backups and legal holds.

## Account and workspace data

We store the account you create: email, password hash when you use a password, optional name, optional avatar, email verification state, and linked Google login when you use Google.

We store organizations, members, roles, invites, plan status, custom domain settings, API keys, webhook URLs, and OAuth client records for MCP. We store the forms you save, including questions, logic, theme, CSS, logos, banners, and publish settings.

We store assistant threads for forms you edit, including prompts and drafts. Guests can start an assistant thread before sign-in. Sign-in is required to save, publish, or save a template.

## Form answers and respondent data

Published forms collect the answers you choose to request. Public form pages are reachable without an account. Do not put secrets in a published form. Do not ask for data you are not allowed to collect.

Answers can include text, choices, numbers, email, phone, country, links, dates, ratings, rankings, signatures, calculated values, hidden fields, and similar blocks. File uploads go to our file storage. Payment fields send money to the organization's Stripe account. We do not sell form answers as a data product.

You can search and export answers in the response inbox, download CSV, or export a one-time Google Sheet snapshot. That sheet lives in Google under the Google account that completes the export. It does not stay in sync.

## File uploads

Form file uploads, avatars, logos, and banners go through our API. Secure upload is on by default for form files. Those files use short-lived signed download links after we check access. If you turn Secure upload off, the file can use a public file URL. Webhooks include a public file URL only when Secure upload is off.

You control what respondents upload. Scan files you download. We can remove malware or abusive files when we find them.

## Payments

Paid Request Forms plans bill through Stripe per organization. Stripe processes that card or payment-method data. We store plan status and related billing identifiers we need to run the plan.

Payment fields on a form use Stripe Connect. Money goes to the organization's Stripe account. Stripe processes card data for those charges. Those charges are not Request Forms fees. See /terms for refunds.

## Embeds, hosted forms, and custom domains

You can publish a hosted link on requestforms.io. You can embed the form with a web component or an embed page on your site. Answers still come to Request Forms. The host page can send theme values such as font and color. Visible-field prefill can come from the URL or embed attributes.

Paid organizations can serve hosted forms on a verified custom domain. Search engines can index those forms through that host. Embed pages stay out of search results. The form still runs on our service.

If you import a theme from a website URL, we fetch that public HTTPS page to read colors, fonts, and similar brand signals.

## Cookies and similar storage

We use cookies that the product needs.

rf_session is an HTTP-only session cookie. It keeps you signed in on the website. It lasts 7 days or until you sign out. Password reset and logout end old sessions.

rf_last_login_method stores the last sign-in method (password or Google) so the login page can highlight it. Logout does not clear it. It is a long-lived cookie.

rf_agent_visitor keeps a guest assistant thread before sign-in. rf_help_visitor keeps a help-chat thread for visitors. Those visitor cookies can last up to one year.

Stripe sets cookies on Stripe Checkout and Stripe Connect flows that Stripe controls. Google may set cookies for Google sign-in, Google Sheets export, and reCAPTCHA when you use those features.

The public footer links to the Atributi public analytics dashboard. This site does not load the Atributi tracker. See atribusi.com for that product's own notice.

## Assistant, help chat, and models

The form builder agent and the help chat send prompts, form drafts, and relevant product docs to language model providers so they can reply. They read the form you are editing and our public docs. They are not a public training set of respondent answers in this product.

Help chat can store a transcript, an optional visitor email, and admin replies. We use that to answer you and to review abuse. The widget is hidden on embed pages.

## API, CLI, MCP, and webhooks

API keys are organization secrets. A key can create and edit forms, list submissions, manage webhooks, and read analytics. You can revoke a key on the organization page.

Assistants connect through the hosted MCP server with OAuth. We store OAuth client records, consent grants, and hashed access and refresh tokens so we can revoke them.

Webhook URLs you configure receive submit payloads that you chose to send. You can set a webhook secret. You are responsible for that destination. Do not send secrets you do not want that host to receive.

## Google sign-in, Sheets, and reCAPTCHA

Google sign-in sends us the verified email and related profile data Google provides. Google Sheets export sends current answers to a new spreadsheet in the Google account that completes the OAuth flow.

You can add Google reCAPTCHA on a form. Google then receives respondent traffic for that check. Anonymous public submits also require a math captcha. A honeypot stays on our service.

## Email

We send verify, reset, invite, and similar account mail. Organization members can receive notify email on submit when that setting is on. Help chat can email a transcript when that tool runs.

Mail we cannot send still stays in our mail store so we can debug delivery. Stored bodies omit verify and reset URLs.

## How we use data

We use data to provide the product, authenticate you, bill paid plans, prevent abuse, debug faults, improve reliability, answer support, and meet law. We use public marketing pages to explain the product. We do not sell personal data.

## Sharing and subprocessors

We share data with providers that help us run the service, and only as needed for that work.

Stripe processes plan billing and Connect payments. Google provides sign-in, Sheets export, and reCAPTCHA when those features run. Language model providers run the assistant and help chat. We use hosted compute, a hosted database, file storage, and an email delivery path when SMTP is configured.

We share data when you instruct us to: webhooks, Google Sheet export, embeds on your site, and members you invite. We share data if law requires it, or to prevent harm or abuse.

We do not sell form answers. We do not rent account lists.

## International processing

We process data on systems we operate and on systems our providers operate. Those systems can be outside your country. If you use the product, you instruct us to process respondent data in those locations as needed to provide the service.

## Retention

We keep account, organization, form, and answer data until you delete that item or delete the account, unless we must keep a record for security, billing, or law.

Delete account is in Settings. It asks for your password. Google-only accounts must set a password first. Deletion removes the account and the forms and answers we store for it. Backups and logs can remain for a limited time, then they expire.

Revoked API keys and OAuth tokens stop working. Help-chat threads and security logs can remain as needed for abuse review. Stripe and Google keep records under their own rules.

## Your rights

You can access and update profile data in Settings. You can export answers you own. You can delete answers, forms, or the account. You can revoke API keys and MCP grants. You can disconnect Stripe Connect from the organization page.

To ask a question about stored account data, or to request deletion of an account you own, email support@requestforms.io from that account address. Password login must work, or you must complete the reset flow first.

If you are a respondent, contact the form owner. If you cannot reach them, email support@requestforms.io with the form link and we will route the request when we can identify the owner.

If you are in a region with extra privacy rights, email the same address. We will honor requests the law requires for data we control. We will point respondent requests to the controller when that is the lawful path.

## Children

The product is not directed at children under 13. Do not create an account for a child under 13. Do not use Request Forms to collect personal data from children under 13.

## Security

See /security for how we protect data in this product. No method is perfect. You must use a strong password, keep API keys private, and treat published forms as public.

## Changes

We can update this policy. The date at the top is the current version. Continued use after a change means you accept the new policy. For the terms of service, open /terms.

## Contact

Email support@requestforms.io. There is no phone line. For product questions, open /docs. For security reports, put security in the subject.

## Sitemap

- Home: https://requestforms.io/
- Website forms: https://requestforms.io/website-forms
- Pricing: https://requestforms.io/pricing
- Docs: https://requestforms.io/docs
- Blog: https://requestforms.io/blog
- Tools: https://requestforms.io/tools
- OpenAPI: https://requestforms.io/openapi.json
- llms.txt: https://requestforms.io/llms.txt
- XML sitemap: https://requestforms.io/sitemap.xml
