Openform

Privacy Policy

Last updated: July 20, 2026

Introduction

This Privacy Policy explains how this Openform instance (the "Service") collects, uses, and shares information. Openform is open-source, self-hostable form-builder software that lets people create forms and surveys, share public links, and collect responses.

Because Openform is self-hosted, this instance is run by an independent instance operator. That operator, not the authors of the Openform software, decides how the instance is configured and is the party responsible for the personal data processed through it. In data-protection terms, the instance operator is the data controller for account-holder data and for the platform-level processing described here. This policy describes the data handling that the software makes possible; the operator's specific practices, retention periods, and configuration may vary.

Who is responsible for your data

There are two distinct roles to keep in mind:

  • The instance operator runs this Service and is responsible for account-holder data and the operation of the platform.
  • Account holders create forms and collect responses. For the responses submitted to their forms, the account holder is the party responsible toward their respondents and decides why and how those responses are used. The operator processes that response data on the account holder's behalf as part of running the Service.

If you are a respondent and have questions about how your response is used, the account holder who created the form is typically your first point of contact, alongside the instance operator.

Information We Collect

Account information

When you create an account, the Service stores the information needed to identify and authenticate you, such as your chosen identifier or email and authentication credentials, along with basic account and workspace membership records.

Form definitions and workspace content

When account holders build forms, the Service stores the form definitions, including their pages, fields, settings, and any sign-in or access requirements configured for a form, as well as workspace records describing who has access.

Respondent submissions

When someone responds to a form, the Service stores the answers they submit, together with metadata such as timestamps. The content of a response is determined by the questions the account holder chose to ask, which may include personal data if the form requests it.

OAuth-derived identity

If a form or the instance requires signing in through a third-party identity provider (such as Discord or Roblox), the Service receives identity information from that provider. This can include a username, a unique user identifier, and, where applicable, group or guild role memberships associated with your account at that provider. This information may be stored with the account or attached to a response so that the account holder can see who responded and, where configured, apply access rules based on role membership.

IP addresses

The Service may process IP addresses for operational and security purposes, in particular to apply rate limiting that protects the Service against abuse and automated attacks.

Cookies

The Service uses a small number of cookies that are necessary for it to function:

  • An authentication session cookie that keeps account holders signed in.
  • A gate sign-in cookie used when a respondent signs in through a third-party provider to answer a form that requires it, so that the sign-in persists across the submission flow.

These cookies are used to operate the Service rather than for advertising. Depending on how the instance is configured or deployed, additional strictly necessary cookies may be present.

How We Use Information

The Service uses the information it collects to:

  • Provide, operate, and maintain the Service, including creating and managing accounts, forms, workspaces, and responses.
  • Authenticate account holders and, where required, respondents.
  • Deliver forms to respondents and record their submissions for the account holder who owns the form.
  • Apply access rules, such as restricting who may respond based on identity or role membership captured from a third-party provider.
  • Protect the Service, including through rate limiting and other measures that detect and prevent abuse, fraud, and security incidents.
  • Comply with legal obligations that apply to the instance operator.

Legal Basis and Consent

Where data-protection law requires a legal basis for processing, the instance operator generally relies on one or more of the following:

  • Performance of a contract or provision of the Service, to give account holders the functionality they sign up for.
  • Legitimate interests, such as keeping the Service secure and preventing abuse, balanced against your rights.
  • Consent, where it is required, for example when a respondent chooses to submit a form or to sign in through a third-party provider. Where processing relies on consent, you may withdraw that consent, though doing so may prevent you from completing an action such as submitting a response.
  • Compliance with legal obligations that apply to the operator.

Account holders who collect responses are responsible for having their own valid legal basis for the personal data they gather from respondents and for making any disclosures their own use requires.

Third-Party Identity Providers

When you sign in through a third-party provider such as Discord or Roblox, that provider processes your data under its own privacy policy. The Service only receives the identity information described above and does not receive your password or credentials at that provider. The instance operator does not control these providers and is not responsible for their practices. You should review the privacy policy of any provider you use to sign in.

Data Retention

The Service retains information for as long as it is needed to provide the Service and for the purposes described in this policy, unless a longer period is required or permitted by law. Because the instance is self-hosted, the specific retention periods, backup schedules, and deletion practices are determined by the instance operator and may differ from one instance to another.

Account information is generally retained while an account is active. Form definitions and responses are retained until the account holder deletes them or the instance operator removes them. Operational data such as rate-limiting records is typically short-lived. When data is deleted, copies may persist in backups for a limited time before being overwritten.

Respondent Data vs. Account-Holder Data

This policy distinguishes between two categories of personal data:

  • Account-holder data is processed by the instance operator so that people can use the Service to build and manage forms.
  • Respondent data is the content of form submissions and any identity information captured during submission. This data belongs to the context of the form it was submitted to, and the account holder who owns that form determines how it is used. The operator stores and processes it on the account holder's behalf as part of running the Service.

If you are a respondent seeking to access, correct, or delete a response you submitted, the account holder who created the form is usually best placed to act on that request, since they control that content; the instance operator can assist as the party operating the platform.

Security

The instance operator takes measures intended to protect information against unauthorized access, alteration, disclosure, and loss. These may include authentication controls, access restrictions within workspaces, rate limiting, and standard operational safeguards. However, no method of transmission or storage is completely secure, and the specific security posture of any instance depends on how the operator has deployed and configured it. No absolute guarantee of security can be given.

Your Rights

Depending on where you live, you may have rights over your personal data, which can include the right to access the data held about you, to correct inaccurate data, to request deletion, to restrict or object to certain processing, and to obtain a copy of your data in a portable form.

Account holders can exercise many of these rights directly through the Service by viewing, editing, or deleting their accounts, forms, and responses. Where a right cannot be exercised directly, or where you are a respondent, requests can be directed to the relevant account holder or to the instance operator, who will respond as required by applicable law. The operator may need to verify your identity before acting on a request.

Children's Privacy

The Service is not directed at children, and accounts are not intended to be created by anyone below the minimum age required by applicable law. The instance operator does not knowingly collect personal data from children through account registration. Account holders who choose to collect responses from children through their own forms are responsible for obtaining any parental consent and meeting any additional legal requirements that apply to them. If you believe a child has provided personal data through this instance in a way that requires attention, contact the instance operator.

Changes to This Policy

The instance operator may update this Privacy Policy from time to time. When it does, the "Last updated" date above will be revised, and material changes may be communicated through the Service where practicable. Your continued use of the Service after an updated policy takes effect constitutes acceptance of the update.

Contact

Questions about this Privacy Policy or about how your data is handled can be directed to the instance operator through the contact channel that operator makes available.