Trial. HostMyForms is in a trial phase. Accounts, forms, and answers may be deleted before the full release. What this means · [email protected]

Privacy Policy

Version 2 · Effective 25 September 2026

HostMyForms is a service for building forms, collecting responses with consent, and analysing them. It is operated by Firoz Jaroli, an individual based in India ("we", "us"). This policy covers hostmyforms.com, the app at app.hostmyforms.com, the admin site, the API at api.hostmyforms.com, and the MCP endpoint at mcp.hostmyforms.com.

We wrote it to match how the service actually works. If something here is unclear, write to us at [email protected].

1. Who is responsible for your data

For people who create an account, and for visitors to our website, we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act): we decide why and how that data is processed.

For people who answer a form, the organisation or person that runs the form (the workspace) is the Data Fiduciary, and we process the answers on its behalf as its Data Processor. Each form shows its own privacy notice and consent request. Questions about a particular form, and requests about your answers, go first to that workspace; every submitted response also gets a private link that lets you see, withdraw consent for, or erase your answer yourself.

2. What we collect

About account holders:

  • Your email address, which you confirm with a one-time code, and your name.
  • Optional profile details: account type, business name, profile picture and language.
  • Your password, stored only as an Argon2 hash that cannot be turned back into the password. If you sign in with Google, we keep your Google account identifier, not your Google password.
  • Details a workspace keeps about its members, such as display name, designation, employee code and a work phone number.
  • Sign-in records: when you signed in, your browser's user agent, and a keyed hash of your IP address (not the address itself). Tokens are stored only as hashes.
  • A log of security-relevant actions, such as sign-ins, password changes, permission changes, consent and data exports, with a keyed hash of the IP address.
  • The forms, campaigns, files and settings you create.

About people who answer forms, on behalf of the workspace:

  • The answers and files submitted, including a location if the form asks for one.
  • If the form requires it, the email address or mobile number used to verify the respondent.
  • Consent records and signed receipts: which notice was accepted, for which purposes, and when.
  • Technical details of the submission: time taken, language, app or browser, and a keyed hash of the IP address.
  • For children, the name, relationship and email address of the parent or guardian who gave consent.
  • Where a field worker recorded the answers, who recorded them and the consent evidence they captured.

Our servers also keep short-lived technical request logs, which include IP addresses and browser details, to keep the service secure and to fix problems. They are rotated automatically and kept only for as long as that needs.

We do not use advertising, analytics or tracking scripts, and we do not sell personal data.

3. Why we use it

  • To create and run your account and workspaces, and to deliver the forms and responses you work with.
  • To confirm email addresses and send the messages the service needs: sign-in codes, password links, invitations, receipts for respondents, and privacy and account notices. We do not send marketing email.
  • To keep the service secure: rate limits, detecting abuse, refusing disposable email addresses, and investigating incidents.
  • To power search across forms and responses, when a workspace uses it.
  • To answer your requests and meet our legal obligations.

We process account data on the basis of the consent you give when you sign up, and, where the DPDP Act allows it, for legitimate uses such as meeting a legal obligation or responding to a security incident.

4. Who processes data for us

We use a small number of service providers, each only for the purpose listed:

  • Hostinger: the server that runs the service, its database and its file storage, in Mumbai, India.
  • Cloudflare: the network in front of our sites, which protects them and delivers pages. It sees traffic to our sites, including IP addresses.
  • Mailtrap: delivers the email we send. It receives the recipient address and the message.
  • Voyage AI (United States): turns text into search vectors when search is used. It receives the text of questions, answers and search queries, under zero-day retention; the resulting vectors are stored in our own database. Files, calculated fields and locations are not sent.
  • Google: only if you choose to sign in with Google.

When a form includes a map, the map images are loaded from OpenFreeMap, which sets no cookies. When a form includes a video, it is played by YouTube (in its privacy-enhanced mode) or Vimeo.

We may also disclose data when the law requires it, for example in response to a valid order from a court or authority in India.

5. Data outside India

Our server is in India. Some providers above process data elsewhere: Voyage AI in the United States, and Cloudflare and Mailtrap on their global networks. We transfer data only to countries the Government of India has not restricted under the DPDP Act.

6. Cookies and browser storage

The app sets one cookie, which keeps you signed in. It cannot be read by scripts and is sent only to our sign-in endpoints.

The app also stores a few things in your browser: your theme and layout choices, a random device identifier that lets you find files you uploaded to a form, and, if you ask a form to remember you, your details for that form. You can clear them at any time in your browser.

Our website sets no cookies; it only remembers your theme choice in your browser.

7. How long we keep it

HostMyForms is in a trial phase. Before its full release we may delete all accounts and the data in them, earlier than the periods below; we aim to email account holders first. Consent records and the security log may be kept as described below.

  • Your account: for as long as you keep it. When you delete it, it is removed after a 7-day window in which you can change your mind. Your name, email, password and sessions are erased; consent records, receipts and the security log are kept, no longer linked to your identity, as proof of what was agreed and done.
  • A deleted workspace: it can be restored for 30 days, after which its forms, responses, files and members are erased. The security log and consent records are kept.
  • Answers to forms: for as long as the workspace keeps them, or until the respondent withdraws consent or asks for erasure, when they are erased or anonymised as the form's notice states.
  • Sign-in codes, expired sessions and unused uploads: deleted automatically within minutes to a day.
  • Backups: a daily database backup, each kept for 14 days.

8. Your rights

Under the DPDP Act you can:

  • Get a summary of your personal data and how it is processed. Account holders can download a copy of their account data from their account settings.
  • Correct or update your data, most of it directly in your profile.
  • Erase your data by deleting your account, or, for a form answer, through its private link.
  • Withdraw consent at any time, as easily as you gave it. Withdrawing does not affect processing that already happened.
  • Nominate someone to use these rights for you if you die or become unable to.
  • Have a grievance about how we handle your data addressed.

To use a right that you cannot use in the app, or to raise a grievance, write to our Grievance Officer, Firoz Jaroli, at [email protected]. We reply as soon as we can, and within 90 days at the latest. If you are not satisfied with our reply, you may complain to the Data Protection Board of India.

9. Children

Accounts are for adults: you must be at least 18 to create one. Forms that may be answered by children can require verifiable consent from a parent or guardian before the child's answers are accepted.

10. Security

Traffic is encrypted with TLS. Passwords are hashed with Argon2, tokens and IP addresses are stored only as hashes, access to each workspace is checked on every request, and private files are served through links that expire after minutes. No system is perfectly secure; if a breach affects your personal data, we will inform you and the Data Protection Board as the law requires.

11. Changes to this policy

When we change this policy we publish a new version here with its effective date. If a change affects what you agreed to, we ask you to accept the new version the next time you sign in.

12. Contact

HostMyForms is operated by Firoz Jaroli, India. Write to [email protected] about anything in this policy.