Skip to content
FormSubmit

Account

Security & privacy

How FormSubmit protects submissions, files, integration secrets and your Google account.

Accounts

  • Sign-in is Google only — no passwords to leak or reuse.
  • Sessions are HTTP-only cookies. Superadmin access for our own staff is restricted to an explicit allowlist, and every admin action is audit-logged.

Submissions

  • Stored in a managed Postgres database, encrypted at rest by the provider, and transmitted over TLS.
  • Submitter IP addresses are never stored — we keep a salted SHA-256 hash for rate limiting and abuse detection.
  • You choose retention per form, including not storing submissions at all.
  • Deleting a form or submission deletes its files too.

Files

  • Stored in private object storage — never publicly listed.
  • Accessible only from your signed-in dashboard or via signed links that expire after 7 days (used in emails and integrations).
  • Risky file types are always served as downloads, never rendered in the browser.

Integration secrets

API keys, webhook URLs, signing secrets and captcha secrets are encrypted with AES-256-GCM before they're stored and are only ever displayed masked.

Google permissions

We request the minimum:

  • Sign-in: openid, email, profile.
  • Google Sheets (only if you connect it): drive.file, which lets FormSubmit access only the spreadsheets it creates for you — not the rest of your Drive.

Outbound requests

Webhooks only go to public HTTPS URLs and are signed so your server can verify them. We never follow redirects from webhook endpoints.

Reporting a vulnerability

Email security@formsubmit.app. We appreciate responsible disclosure and respond quickly.

See also our privacy policy and DPA.