NisuformDocs

Privacy and data

What Nisuform stores with each submission, how to limit it, how long data is kept and how deletion works.

You decide what your forms collect. Nisuform stores the answers your form sends and a few details about each request, and gives you settings to collect less.

What is stored with a submission

DataStoredWhy
The answers your form sendsAlwaysThis is the submission.
Uploaded filesWhen uploads are onStored privately, see File uploads.
Page the form was sent fromAlwaysShows where submissions come from.
Browser and device typeAlwaysHelps spot bots and shows devices in analytics.
CountryAlwaysDerived from the request, used for analytics and blocked countries.
IP addressUnless turned offLets you block abusive senders.

Special fields like _gotcha, _elapsed and the Turnstile token are never stored. Submissions dropped as bots or blocked are not stored at all.

Stop storing IP addresses

Turn off Store IP addresses in the form's Settings, Spam protection. New submissions are stored without an IP address. Rate limits and IP blocking keep working, because they check the address while the request is handled without saving it.

Collect only what you need

  • Ask only for the fields you use. Every field you add is data you are responsible for.
  • Link to your privacy policy from the form, and add a Checkbox field for consent where the law requires one.
  • Don't collect passwords, card numbers or other highly sensitive data through forms.

Security

  • Data is encrypted in transit and at rest.
  • Uploaded files are checked by their contents, stored privately and only shared through links that expire after 15 minutes.
  • Webhooks are signed, so your server can reject anything that didn't come from Nisuform.
  • Form keys only allow sending submissions. They can't read data.

Retention and deletion

Submissions are kept until you delete them. There is no automatic expiry.

You deleteWhat is removed
A submissionThe submission and its files.
A formThe form, all of its submissions and files, and its integrations.
A teamAll of its forms, submissions and files.
Your accountYour profile and every team you own.

Deleted data is removed within 30 days and purged from encrypted backups within a further 90 days. Export anything you want to keep first.

Data Processing Agreement

If you collect personal data from people in the EU or UK, Nisuform processes it on your behalf. The Data Processing Agreement is included with every account. It lists our subprocessors and security measures. See also the Privacy Policy.

Requests from the people who filled in your form

When someone asks you to see or delete their data, find their submissions in the inbox or in a CSV export, then send them a copy or delete them. Contact support@nisuform.com if you need help.