Security & privacy

Security and data practices

This page is written for the person doing the vendor review. It sets out where your data lives, how it's protected, how long we keep it, and the certifications behind the infrastructure we run on.

Last reviewed: September 3, 2026

How we protect your data

Data residency

Form definitions and form responses are stored at rest in the European Union. We don't move customer form data outside the EU for storage.

Hosting

Fomr runs on infrastructure hosted in SOC 2 compliant data centers, with redundant infrastructure behind it.

Encryption

HTTPS/TLS for everything in transit, including every published form, and encryption at rest for stored data. On every plan, including the free one.

Access control

Data is scoped to your organization. Your own admins manage who joins and who leaves, using Admin and Member roles.

Authentication

Email addresses must be verified before an invite can be accepted. Credentials are handled by our authentication provider, never stored in plain text.

Availability

Redundant infrastructure behind a public status page, so you can check uptime yourself rather than take our word for it.

Certifications and compliance

SOC 2 Hosting infrastructure
Fomr runs on infrastructure hosted in SOC 2-compliant data centers. The certification covers the data centers our infrastructure runs in.
GDPR Aligned
We follow data protection protocols aligned with GDPR requirements, and we can sign a data processing agreement with you.
HIPAA Not suitable for PHI
We don't sign BAAs and haven't built the safeguards required for protected health information. Don't use Fomr for forms that collect PHI.
PCI DSS Handled by Stripe
Payments run through Stripe's hosted checkout, which is PCI DSS Level 1 certified. Card numbers and security codes never reach our servers, and we store only a Stripe customer identifier.

We conduct regular internal security audits. If your review needs detail beyond what's on this page, or a specific framework addressed, email us and we'll answer directly.

Your data, your control

You own your data

We don't claim ownership of the forms you build or the responses you collect. Our Terms of Use put that in writing.

Export whenever you want

Export responses to CSV from the Results tab at any time. No support ticket, no waiting period, no upgrade required.

Delete on request

Delete individual responses yourself. For access, correction, or full erasure of personal data, email us and we'll handle it under GDPR.

Never sold

We have not sold or shared personal data with third parties for commercial purposes, and we don't sell to advertisers, data brokers, or resellers.

How long we keep your data

While your account is active, your forms and responses stay available to you. We keep personal information only as long as it's needed for the purposes set out in our Privacy Policy, and no purpose in that notice requires keeping personal information longer than twelve months past the start of an account's idle period. After that we delete or anonymize it, or isolate it from further processing where deletion isn't immediately possible, such as in backup archives.

We don't currently offer automatic retention rules with scheduled deletion, so if your policy requires responses to be purged on a fixed schedule, that's a manual step on your side today. We'd rather flag it than let you assume otherwise.

Who else processes your data

Running Fomr means relying on a small number of third-party providers. Billing runs through Stripe, and our AI features use Anthropic and OpenAI, as described below. Some providers process data outside the European Economic Area, including in the United States. Where that happens we rely on appropriate transfer safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision covering the recipient country. Our Privacy Policy describes these relationships, and we'll provide a current subprocessor list on request.

AI features

Our AI form builder sends your prompt to our AI providers, currently Anthropic and OpenAI, purely to generate the form structure. Prompts are not stored by us for training and are not used to train their models.

Google Workspace API data is excluded from this entirely. We do not send raw, aggregated, anonymized, or derived Google Workspace API data to any third-party AI or machine-learning service.

Data you send elsewhere

If you connect an integration, data that leaves Fomr is governed by the receiving service and your agreement with them. With our Google Sheets integration, for example, responses written to your spreadsheet live in your own Google account. Disconnecting Fomr or deleting your Fomr account stops future writes but does not remove data already sent, which you manage in Google Sheets.

Reporting a vulnerability

If you believe you've found a security vulnerability, email [email protected] with enough detail to reproduce it. Please give us a reasonable window to investigate and ship a fix before disclosing it publicly. We don't run a paid bounty program, but we read every report and we'll keep you updated on what we find.

Further reading

Running a vendor review?

Send us your security questionnaire and we'll fill it in. We can also sign a data processing agreement, or answer questions from your security team directly.

[email protected]

Your next form could be the best-looking thing on your site.

Free forever. Unlimited responses. No signup to start.