Formwork
Menu
Get started free Log in

What we store about respondents

The data a Formwork form records when someone fills it in, how IP addresses are handled, which cookies are set, and what third-party services a form contacts.

This page describes what the software stores. It is not legal advice. What you must tell respondents, and whether you need their consent, depends on the questions you ask and the laws that apply to you.

What is recorded with a response

  • Their answers, for every question they saw and answered, stored against the version of the form they filled in.
  • Uploaded files and signatures, stored on the server outside the public web folder.
  • An email address, only if you switched on Collect email, or if a respondent asked for a "continue later" link, in which case the address is used to send that one email.
  • Timing: when they started, when they last saved and when they submitted, plus how long it took.
  • Coarse device details: whether it was a desktop, mobile or tablet, the browser name, the operating system, and the language the browser asks for, such as "en".
  • Where they came from: the website that linked to the form (host name only), the utm_source, utm_medium and utm_campaign tags in the link, and any hidden field values you set up.
  • Quiz results: points, score and whether it was graded.
  • Your own notes: tags and a private note that you add, visible to your team only.
  • If the form requires sign-in, the Formwork account that answered.

You decide what to ask, so collect only what you need.

IP addresses

Formwork does not store respondents' IP addresses with their responses. It stores a short hash of the address, mixed with a secret key and the date. Because the date is part of it, the same person produces a different hash tomorrow, so it cannot be used to follow someone over time. It is used for rate limits and for abuse controls, such as capping how much one visitor can upload in an hour. The web server that hosts Formwork may keep its own access logs, which are outside the application and are managed by whoever runs the server.

For the form's funnel numbers (views, starts, submissions) Formwork uses a similar anonymous visitor id built from the address and the browser's user-agent text and the date. It is not stored in a cookie and it changes every day. Events that belong to a response are deleted along with it.

Cookies and browser storage

Public forms do not start a session and do not set a session cookie, unless the form requires sign-in. They can set these cookies, all marked HttpOnly and SameSite=Lax, and Secure on HTTPS:

CookieWhenHow long
fw_r_<form link>A draft is saved or a response submitted. Holds the key to that response, so the person can resume or edit it30 days
fw_pw_<form link>A password-protected form was unlocked12 hours
fw_done_<form link>Only for forms set to one response per device1 year

While filling a form, a copy of the answers is also kept in the browser's local storage for up to 30 days, so a refresh does not lose work. It stays on the respondent's device.

Third parties

A published form is served from your Formwork address. Its scripts, styles, icons and fonts all come from the same address, and Formwork adds no analytics or advertising scripts to it. Two things can reach out:

  • Cloudflare Turnstile, a spam check, only if the person running your Formwork installation has switched it on.
  • YouTube or Vimeo, only if you put a video block in the form. YouTube links use the youtube-nocookie.com address.

The "Made with Formwork" badge shown on some plans is an ordinary link and loads nothing from elsewhere.

Where the data can travel

Data leaves a form when you send it on:

  • notification emails to your team include the first answers;
  • receipts go to respondents who gave an email address, if you enabled them;
  • webhooks send full answers to the addresses you add;
  • exports and the API give access to everything to people who have the right role or key.

Review these when you decide who should have access, and see Roles and permissions.

Removing data

See Retention and deleting responses.

Updated Sep 30, 2026