Last updated: July 20, 2026
This Privacy Policy explains how this Openform instance (the "Service") collects, uses, and shares information. Openform is open-source, self-hostable form-builder software that lets people create forms and surveys, share public links, and collect responses.
Because Openform is self-hosted, this instance is run by an independent instance operator. That operator, not the authors of the Openform software, decides how the instance is configured and is the party responsible for the personal data processed through it. In data-protection terms, the instance operator is the data controller for account-holder data and for the platform-level processing described here. This policy describes the data handling that the software makes possible; the operator's specific practices, retention periods, and configuration may vary.
There are two distinct roles to keep in mind:
If you are a respondent and have questions about how your response is used, the account holder who created the form is typically your first point of contact, alongside the instance operator.
When you create an account, the Service stores the information needed to identify and authenticate you, such as your chosen identifier or email and authentication credentials, along with basic account and workspace membership records.
When account holders build forms, the Service stores the form definitions, including their pages, fields, settings, and any sign-in or access requirements configured for a form, as well as workspace records describing who has access.
When someone responds to a form, the Service stores the answers they submit, together with metadata such as timestamps. The content of a response is determined by the questions the account holder chose to ask, which may include personal data if the form requests it.
If a form or the instance requires signing in through a third-party identity provider (such as Discord or Roblox), the Service receives identity information from that provider. This can include a username, a unique user identifier, and, where applicable, group or guild role memberships associated with your account at that provider. This information may be stored with the account or attached to a response so that the account holder can see who responded and, where configured, apply access rules based on role membership.
The Service may process IP addresses for operational and security purposes, in particular to apply rate limiting that protects the Service against abuse and automated attacks.
The Service uses a small number of cookies that are necessary for it to function:
These cookies are used to operate the Service rather than for advertising. Depending on how the instance is configured or deployed, additional strictly necessary cookies may be present.
The Service uses the information it collects to:
Where data-protection law requires a legal basis for processing, the instance operator generally relies on one or more of the following:
Account holders who collect responses are responsible for having their own valid legal basis for the personal data they gather from respondents and for making any disclosures their own use requires.
When you sign in through a third-party provider such as Discord or Roblox, that provider processes your data under its own privacy policy. The Service only receives the identity information described above and does not receive your password or credentials at that provider. The instance operator does not control these providers and is not responsible for their practices. You should review the privacy policy of any provider you use to sign in.
The Service retains information for as long as it is needed to provide the Service and for the purposes described in this policy, unless a longer period is required or permitted by law. Because the instance is self-hosted, the specific retention periods, backup schedules, and deletion practices are determined by the instance operator and may differ from one instance to another.
Account information is generally retained while an account is active. Form definitions and responses are retained until the account holder deletes them or the instance operator removes them. Operational data such as rate-limiting records is typically short-lived. When data is deleted, copies may persist in backups for a limited time before being overwritten.
This policy distinguishes between two categories of personal data:
If you are a respondent seeking to access, correct, or delete a response you submitted, the account holder who created the form is usually best placed to act on that request, since they control that content; the instance operator can assist as the party operating the platform.
The instance operator takes measures intended to protect information against unauthorized access, alteration, disclosure, and loss. These may include authentication controls, access restrictions within workspaces, rate limiting, and standard operational safeguards. However, no method of transmission or storage is completely secure, and the specific security posture of any instance depends on how the operator has deployed and configured it. No absolute guarantee of security can be given.
Depending on where you live, you may have rights over your personal data, which can include the right to access the data held about you, to correct inaccurate data, to request deletion, to restrict or object to certain processing, and to obtain a copy of your data in a portable form.
Account holders can exercise many of these rights directly through the Service by viewing, editing, or deleting their accounts, forms, and responses. Where a right cannot be exercised directly, or where you are a respondent, requests can be directed to the relevant account holder or to the instance operator, who will respond as required by applicable law. The operator may need to verify your identity before acting on a request.
The Service is not directed at children, and accounts are not intended to be created by anyone below the minimum age required by applicable law. The instance operator does not knowingly collect personal data from children through account registration. Account holders who choose to collect responses from children through their own forms are responsible for obtaining any parental consent and meeting any additional legal requirements that apply to them. If you believe a child has provided personal data through this instance in a way that requires attention, contact the instance operator.
The instance operator may update this Privacy Policy from time to time. When it does, the "Last updated" date above will be revised, and material changes may be communicated through the Service where practicable. Your continued use of the Service after an updated policy takes effect constitutes acceptance of the update.
Questions about this Privacy Policy or about how your data is handled can be directed to the instance operator through the contact channel that operator makes available.