Privacy
Last updated 8 September 2026
In short: we store the forms you build and the answers people give them, so we can show them back to you. There is no analytics, no tracking and no advertising anywhere on this site, and we do not sell anything to anyone. Deleting a form deletes its responses with it.
This policy covers two different people, and it is worth being clear which one you are. If you have signed in and built a form, the first half applies to you. If you have been sent a link and filled something in, the second half does — and the person who built that form, not Seagit, decides what it asks and what happens to your answers.
There is no tracking on this site
Worth saying first because it removes most of what a privacy policy usually has to explain. Seagit Forms carries:
- no analytics of any kind — no Google Analytics, no alternatives
- no advertising, and no advertising identifiers
- no third-party trackers, pixels or social embeds
- no cross-site profiling, and nothing sold or shared for marketing
There is no cookie banner because there is nothing to consent to. The only cookie we set is the one that keeps you signed in.
If you build forms
Your account
You sign in with Google or GitHub. We receive your email address, your display name and a user ID from whichever you chose. We never see your password for either service.
Your forms
The questions you write, your field IDs, your settings and your appearance choices are stored so the form can be served and edited. Your form password, if you set one, is stored only as a salted scrypt hash — it cannot be read back, by you or by us, and it is never returned by any part of the API.
What we store, and why
| Data | Why | Kept |
|---|---|---|
| Email, name, provider user ID | To sign you in and show your forms to you and nobody else | Until you ask us to delete the account |
| Your forms and their settings | To serve, edit and export them | Until you delete the form |
| Responses to your forms | To show and export the answers you collected | Until you delete the response or the form |
Cookies and local storage
One cookie, access_token, holds your sign-in token so the API knows it is you. It is SameSite=Lax, short-lived, and cleared when you sign out. Your browser also remembers two preferences locally — your light or dark choice, and whether the editor's field panel is open. Those never leave your device.
If you are filling in a form
You do not need an account and we do not create one for you. Your answers belong to the person who built the form; they can read, export and delete them, and they chose any other destination the answers are sent to.
What is recorded with your answers
- the answers themselves, and when you submitted them
- your email address and name, but only if that form asks for them
- your browser's user agent, the referring page, and the page you submitted from — the same request details any website receives
If the form has a file field, the file you choose is stored as part of your response, up to 200 KB.
Please do not send passwords or payment details
A Seagit form is not the right place for credentials, card numbers or government identifiers, and no legitimate organisation should ask for them this way. If a form does, do not fill it in — see the terms, which forbid it.
Who else sees any of this
A small number of providers, each doing one job, and none of them receiving anything for their own purposes:
| Who | What they handle |
|---|---|
| Google Firebase | Sign-in for form builders |
| Amazon Web Services | Storage of forms and responses |
| Vercel | Hosting and serving the site |
Beyond those, responses go wherever the form's owner has told them to: their own webhook endpoint, a Telegram chat, a Slack, Discord, Microsoft Teams or Google Chat message, an Airtable record, a Notion page, a Google Sheet row, or an email to an address they chose. Those destinations are the owner's choice and the owner's responsibility — once a response reaches one, that service's privacy policy governs it, not ours. Each guide says exactly what is sent to that destination; webhooks is the one to read first, because it shows the raw shape.
If you connect a Google Sheet
Sending responses to Google Sheets is optional and off until you connect it. When you do, you grant us access through Google's own consent screen, and this is exactly what that grant covers.
We ask for one scope: drive.file. It is Google's narrowest Drive scope. It permits access only to files this app created, or that you explicitly picked for it in Google's own file picker. It does not grant access to the rest of your Drive, and we never request a broader scope — not in testing, not for support.
What we store for the connection, and nothing else:
- a refresh token, so delivery keeps working without asking you to sign in again
- the email address of the Google account you connected, shown back to you so you can tell a live connection from a stale one
- the scope granted, and when you connected
These live in their own table, keyed to your account, and are deliberately never written into the form itself — so they are not exposed by anything that reads a form, and a form shared or duplicated carries no credential with it.
What we do with it, and what we deliberately do not:
- append one row per response to the sheet you created through us or picked, and read that sheet's header row so answers land in the right columns
- never overwrite anything already in the sheet — rows are inserted, so data below the table is not destroyed. Delivery never changes the sheet's structure. The one action that does is “Create missing columns”, which adds a column for questions that lack one and runs only when you press it
- never let an answer act as a formula. Values are written literally, so text that looks like a spreadsheet formula is stored as text rather than executed
- never read, list or open any other file in your Drive — the scope does not permit it and we do not attempt it
- never use this data for advertising, never sell it, and never transfer it to anyone except as needed to deliver your responses
Disconnecting removes it. Remove the Google Sheets destination, or use Reconnect to replace the account, and the stored token is deleted. You can also revoke the grant from your Google Account permissions page at any time, which stops delivery immediately. The sheet and everything already written to it stay yours and are untouched — they are in your Drive, not ours.
Cloudflare Turnstile: bot protection
Every public form is checked by Cloudflare Turnstile before a submission is stored. We operate forms.seagit.com and the embed frame the widget runs inside, so we are the one place this can be disclosed — the widget itself carries no privacy notice of its own, and on the invisible option it shows the respondent nothing at all: no checkbox, no Cloudflare branding, no terms.
To run that check, Turnstile processes:
- the respondent's IP address
- a TLS fingerprint and their browser's User-Agent
- the sitekey the widget was issued under, together with the origin it ran on
It sets no tracking cookies and is not used for advertising. Cloudflare's own Turnstile Privacy Policy covers exactly this processing.
If you embed a Seagit form on your own site, your visitors go through this same check on your page. That is processing we do not control your disclosure of — you may need to say so in your own privacy policy, particularly if the form you embed uses the invisible option. See spam protection for what each option means for your respondents.
Deleting things
Deleting a form deletes its responses. That is deliberate: answers should not outlive the form that collected them. It cannot be undone, so export first if you need them.
If you responded to someone's form and want your answer removed, ask the person who runs that form — they can delete it directly and they are the ones who decided to collect it. If you cannot reach them, write to us and we will help.
To delete your own account and everything in it, or to ask what is held about you, email privacy@seagit.com.
Changes to this policy
If this policy changes in a way that affects what we collect or who sees it, the date at the top changes with it. We will not quietly broaden what we do with data you have already given us.