Privacy policy

Last updated: 13 August 2026. Applies to the hosted service at https://formroost.shovelware.ai. If you self-host Formroost, none of this leaves your server.

What we process, and why

DataWhyKept
Your email address (form owner)To send your access key, sign-in links, and submission notificationsUntil you delete your account
Form submission contentsRelayed to your inbox. Not stored by default.Relay-only unless you turn on history
Stored submissions & uploads (opt-in history)So you can browse and export them in the dashboard30 days; deleted immediately if you turn history off
Submitter IP address & user agentRate limiting and spam filtering onlyTransiently, in rate-limit counters

What we don't do

Analytics & session recording

We use a self-hosted instance of Umami (running on our own infrastructure — no third-party analytics processor) to understand how the site is used. It is cookieless and collects no personal information beyond the page interactions described here.

We record user sessions on this site. A recording captures your clicks, scrolling, and the pages you view. Everything you type into an input field is masked before the recording leaves your browser, and regions of the dashboard that display form-submission contents are excluded from recording entirely. Recordings are kept for 30 days, then deleted.

Opting out: enable "Do Not Track" in your browser and no analytics or recording data is sent at all — we honour it.

Your submitters' data

If you point a form at Formroost, you are responsible for telling your visitors where their submission goes. We act as a relay on your behalf: by default a submission is emailed to you and not stored. If you enable history, submissions are stored for you and deleted when you disable it or after 30 days.

Contact

Questions or deletion requests: hello@formroost.com. Security reports: see our security policy.