Privacy
Last updated 18 September 2026
This instance is operated by Krypta. This page describes what it stores about you, what it is unable to read, and how to ask for something to be changed or removed.
The short version: form titles, questions, answers and uploaded files are encrypted in your browser before they are sent. We hold ciphertext and no key that opens it. That is not a policy commitment that could be revised later, it is a property of how the software is built, and it means a database dump, a stolen backup, a compromised host or a legal demand made to us yields ciphertext.
What we hold about your account
- Your email address. It identifies the account, receives the six-digit code that verifies it, and receives collaboration invitations and response notifications.
- A hash of a verifier derived from your password. Your password is not sent to the server and is not stored here in any form: the browser derives a key from it and sends a one-way verifier, which the server then hashes again with Argon2id.
- Wrapped copies of your account key, one for each way you unlock it. These are ciphertext that only your password, your vault recovery code or your passkey can open.
- If you enrol two-factor authentication, the TOTP secret, which has to be readable to check your codes, and hashes of your TOTP recovery codes. If you enrol a passkey, the credential it registered.
- Session records, which hold a hash of the session token rather than the token. Sessions expire after 30 days of not being used, and 90 days after they were created whatever happens.
What we hold about your forms
Some metadata is unavoidable if the service is to work at all, and pretending otherwise would be dishonest.
- Ciphertext for form titles, questions and responses, and the encrypted bytes of uploaded files. None of it can be read by this instance, its operator, its host or anyone served a copy of its database.
- The size of each uploaded file, because storage limits are counted against it. Ciphertext lengths for titles, questions and responses are padded, so those sizes say close to nothing about their contents.
- Timestamps, counts, and whether a form is accepting responses, along with its close date and response cap. A limit the server cannot read is a limit it cannot enforce.
- Who collaborates on which form and in what role, and the email address an invitation was sent to.
What we hold to run the service
- IP addresses, used to count requests against rate limits. These counters are short-lived, they are not written to a request log for this purpose, and the login limiter counts against a hash of the address you typed rather than the address itself.
- Pending signups, held for 15 minutes so a verification code can be checked, and discarded whether or not it is used.
- If you subscribe to a paid plan, the customer and subscription identifiers issued by our payment processor, your plan, its status, and how many responses your account has received this month. Card details are handled by the payment processor and never reach this instance.
What we do not do
There is no analytics, no advertising, no profiling and no third-party tracking on this site. We do not sell or share personal data. Fonts are served from this origin rather than a font network, so opening a form does not hand your address to anyone else, and the pages load no third-party scripts.
The only cookies are the ones that sign you in: a session cookie, and a short-lived cookie that carries a collaboration invitation while you accept it. Both are restricted to this site and neither is used to follow you anywhere.
If you are answering someone's form
You do not need an account and we do not ask who you are. Your answers are encrypted in your browser and sealed to the form, so only the people running that form can read them. We cannot read your answers, and we cannot find them for you: to us they are ciphertext with no name on it.
That has a consequence worth stating plainly. The person who made the form decides what they collect and what they do with it, so a request to see, correct or delete your answers has to go to them rather than to us. We are not in a position to act on it, whatever we might wish.
While you are part-way through a form, your answers are kept in your own browser so that closing the tab does not lose them. They stay on your device, are never sent to us in that form, are removed after 30 days, and the form gives you a control that removes them immediately. On a shared computer, use it.
Who else processes this data
We use service providers to run the instance: a hosting provider for the servers, an object storage provider for encrypted file uploads, an email provider to deliver verification codes, invitations and notifications, and a payment processor for paid plans. They receive only what their job requires, and the encrypted material stays encrypted in their hands too.
Notification emails carry a count and a link, never the title of a form or anything from a response, because those are encrypted and we could not put them in an email if we wanted to.
How long we keep it
Your forms, responses and uploads stay until you delete them. You can delete a response or a whole form from the dashboard, and deleting a form deletes the responses and files attached to it.
Encrypted database backups are kept for a short period so the service can be restored after a failure, and a deletion works through to those backups as they age out. Rate-limit counters and pending signups are transient and measured in minutes to hours. Sessions expire as described above.
To close your account, write to us at support@getkrypta.com. There is no self-service button for this yet, so it is a request we carry out by hand rather than one you can complete on your own, and we say so rather than implying otherwise. Deleting an account deletes the encrypted material only that account holds.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Write to support@getkrypta.com and we will answer within one month.
Two honest limits apply. Anything encrypted can be exported by you from inside the app, where the keys are, and the export you make there is more useful than anything we could assemble, since ours would be ciphertext. And we cannot correct or delete something we cannot identify: answers submitted to a form someone else runs are theirs to act on.
If you think we have handled your data badly, please tell us first, and know that you can also complain to the data protection authority where you live.
Changes and contact
If this policy changes in a way that matters, the date at the top changes with it and we will say so to account holders before it takes effect. Questions, requests and complaints go to support@getkrypta.com.