Skip to content
← Back to home

Privacy Policy

Last updated: May 15, 2026

1. Who we are

DodoForm ("we," "us," "our") is an AI-powered form builder operated at dodoform.com. This policy explains how we collect, use, store, and protect personal data when you use our website, dashboard, APIs, and public forms.

2. Data we collect

Account data

When you sign up we store your email address, name (if provided via Google OAuth), and a hashed authentication token. We do not store your Google password.

Form content

Form schemas, field labels, logic rules, themes, and version history you create in the editor.

Submission data

Responses submitted by visitors to your published forms, including structured field values, optional file uploads, and metadata (timestamp, anonymized IP hash, user agent).

Usage analytics

Anonymous field-level interaction events (focus, blur, completion) used to power the drop-off heatmap and friction analysis. These are keyed by a random session token, not by any personally identifiable information.

This applies to published forms on the web. Our Android app contains no analytics or crash-reporting SDK of any kind and records no usage events.

AI processing

When you use AI form generation or messy-input extraction, the text, audio, image or PDF you provide is sent to a third-party model provider for processing. We use several, and which one handles a given request depends on availability: Google (Gemini), Amazon Web Services (Bedrock, which serves Amazon Nova and Anthropic Claude models), Groq, OpenRouter and SambaNova.

We log the model name, token counts, latency and a one-way SHA-256 hash of the prompt and response for billing and debugging. We do not store the prompt or response text in those logs.

Files you attach to the extractor (images, audio, PDFs) are passed to the model and are not stored by us — we keep the extracted values, the file name and a confidence score. Text you paste is stored, because it is the record the extraction was made from and what you review it against.

We do not use your data to train our own models. We do not control the retention or training practices of the providers above; each is governed by its own API terms.

Payment data

Billing is handled by our payment processor. We store your subscription status and customer ID but never see or store your credit card number.

3. How we use your data

  • Provide, maintain, and improve the DodoForm service.
  • Generate forms and extract structured data from messy input via AI.
  • Compute analytics, lead scores, and sentiment insights for form owners.
  • Send transactional emails (submission notifications, password resets).
  • Enforce rate limits, prevent abuse, and maintain security.
  • Process payments and manage subscriptions.
  • Respond to support requests.

4. Data sharing

We do not sell your data. We share data only with:

  • Infrastructure providers — Supabase (database, auth, storage), Vercel (hosting), Upstash (rate limiting; your IP address and, on sign-in attempts, your email address are held briefly as rate-limit keys), Cloudflare Turnstile (bot protection on public forms, which receives your IP address). These process data on our behalf under their own privacy policies.
  • AI providers— Google (Gemini), Amazon Web Services (Bedrock), Groq, OpenRouter and SambaNova, for form generation and data extraction. See “AI processing” above for what is sent and what we log.
  • Push notifications — OneSignal, which receives your DodoForm user ID, your plan and trial status, and the text of each notification we send you.
  • Mobile purchases — RevenueCat, which receives your DodoForm user ID and the purchase receipt from Google Play. It never receives your email or name.
  • Email delivery — Resend, which receives the recipient address and message content for transactional email and for the email integration.
  • Payment processor — for subscription billing.
  • Form owner integrations — when a form owner configures webhooks, Zapier, or other integrations, submission data is forwarded to those endpoints as configured by the owner.
  • Law enforcement — only when required by valid legal process.

5. Data retention

Account data is retained while your account is active. Submission data is retained until the form owner deletes it or deletes their account. AI prompt audit logs — which record the model, token counts, latency and a one-way hash, never the prompt or response text — are retained for 90 days. Partial submission drafts are retained for 90 days then automatically purged.

When you delete your account, forms, responses and uploaded files go immediately. The two exceptions are set out under “Your rights” below: records you contributed to other customers' workspaces are reassigned rather than deleted, and prompt audit logs age out on the 90-day schedule above. Where this policy and our Terms differ on retention, this policy governs.

6. Security

All data is encrypted in transit (TLS) and at rest. Database access is governed by row-level security policies. AI queries execute under a read-only role with constrained query plans — no raw SQL reaches the database.

Payloads sent to our registered webhook endpoints are signed with HMAC-SHA256 so you can verify they came from us. Payloads sent to a destination you configure as a form integration — a URL, Slack or Discord webhook — are not signed, because there is no shared secret between us and that endpoint to sign with. Treat data arriving there as unauthenticated.

7. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data. You can:

  • Export all submissions as CSV/Excel from the dashboard.
  • Delete individual forms and their submissions from the dashboard.
  • Delete your entire account from Settings, on the web or in the Android app. This is irreversible. Three things are worth knowing before you do:
    • If you own a workspace that other people are still members of, deletion is refused rather than performed. Deleting it would take their forms and responses with it. Remove the members first, or ask them to leave.
    • Records you contributed to other people's workspaces — corrections you made, extraction jobs you ran, API keys you created — are reassigned to that workspace's owner, not deleted. Removing them would destroy another customer's audit trail and could break a live integration belonging to someone else.
    • Deleting your account does not cancel a paid subscription. Cancel it in Google Play or on your billing page first, or you will continue to be charged.
  • Contact us at privacy@dodoform.com for any data request we don't cover in the UI.

8. Cookies

We use essential cookies for authentication (Supabase session) and workspace selection. We do not use advertising or third-party tracking cookies. Form owners may optionally enable Facebook Pixel or Google Tag Manager on their public forms — those are governed by the form owner's own privacy policy, not ours.

9. Children

DodoForm is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or a dashboard notification. Continued use of the service after changes constitutes acceptance.

11. Contact

Questions about this policy? Email privacy@dodoform.com.