Help center
Go to home
Go to templates
Go to settings
Go to help center

Cookie notice

The cookies and browser storage this install sets, what each entry is for, and the outside scripts a published form can load.

Tinyform sets very little in your browser, and nothing it sets is used to follow you around the web. This page lists every entry the software itself writes, what it is for, and how long it stays. Anything a form owner adds to their own pages is theirs and is covered at the end.

Who sets them

The operator of this install: [name and contact]. The software runs on their server, so every entry below is a first-party one set by that server or by the page it served.

Cookies

Signing in sets one cookie that identifies your session to the server. It is what keeps you signed in between pages and between visits, it cannot be read by scripts on the page, it is sent only to this site, and it lasts seven days unless you sign out first, which removes it.

Three others exist only for a moment during signing in, and each disappears as soon as the step it belongs to is finished: one that remembers you chose not to stay signed in, one that carries you between the password step and the two-factor step, and one that guards the round trip to Google where the operator has enabled Google sign-in.

That is the whole list, and none of it is set for a visitor who only fills in a form. A respondent is never given a cookie by this product.

Browser storage

Beyond the cookies above the product uses your browser's local storage, which stays on your device and is never sent to the server. These are the entries.

EntryWho gets itWhat it holdsHow long
app-sidebar-collapsedA signed-in userWhether you folded the sidebarUntil you clear it
app-folded-orgsA signed-in userWhich workspaces you folded in the sidebarUntil you clear it
dashboard-foldedA signed-in userWhich dashboard sections you foldedUntil you clear it
fe:insights-chart-mode: followed by a question keyA signed-in userWhich chart type you chose on an Insights cardCleared when you sign out
form-editor:draft: followed by the form's idA respondent, on a form whose owner turned on Save answers for laterThe answers you typed but did not submitRemoved when you submit. After thirty days it is ignored and never restored, though the entry itself stays until it is overwritten or you clear it
fp_ followed by the form's idA respondent, on a password-protected formA token proving you entered the password, so you are not asked againUntil the form's password changes, or you clear it
tinyform.respondent-idA respondent, only on a form whose owner set Prevent duplicate submissions to compare on this browserA random identifier with nothing in it about you, so the form can tell it has already been filled in from hereUntil you clear it
tinyform:shown: and tinyform:submitted:, each followed by a form's idA visitor to somebody else's page carrying an embedded popup, written on that page's own siteThat the popup has been shown, and that it has been submittedUntil you clear it

Two of those deserve a sentence rather than a table cell. The respondent identifier is the only lasting value this product writes into a form-filler's browser, and it is written lazily: a form whose owner did not turn that setting on never creates one. A draft never leaves your device — the form's owner cannot see an unsubmitted answer through it; Partial submissions is the separate, server-side feature an owner turns on to receive answers in progress.

Analytics without cookies

The Insights tab is counted without storing anything in your browser. A visitor is told apart from another by a hash of their address, their browser and the current date, taken under a secret only this install holds; because the date is mixed in, the value changes daily and the count cannot be used to recognise you tomorrow. Because no identifier is stored on your device, no consent banner is drawn for it.

Views and completed submissions are recorded by the server from the request itself. Starts and answers are gathered by the page and sent to this same server in a small batch, which is a first-party request that carries the question reached and nothing you typed.

Third-party scripts

The product's own pages load no advertising, marketing or third-party analytics script — not the builder, not a published form, not this help centre.

A published form can load outside code in three ways, and each of them is switched on by a choice somebody made:

  • Google reCAPTCHA, when the operator has configured it and the form's owner has added the reCAPTCHA block. Google's script runs under Google's own privacy policy; reCAPTCHA describes when the block is drawn.
  • Stripe, on a form with a Payment block. Stripe's script draws the card fields itself, in frames of its own, and sets Stripe's cookies under Stripe's privacy policy. Payment forms covers the block.
  • Google Fonts, when the form's owner picked a typeface from Google's catalogue in the Customize panel. Your browser then fetches that font from Google as the page draws, which discloses your address to Google. No script runs, and a form left on the default typeface fetches nothing — it is served by this install.

Content a form owner embeds in their form, such as a video or a map, loads from the provider that hosts it and may set that provider's cookies. A form owner who connected a custom domain can also inject their own code onto its pages; what that code sets is the owner's responsibility, not the operator's.

Controlling them

Your browser lets you view, block and delete cookies and local storage for this site. Deleting the session cookie signs you out; deleting local storage forgets a saved draft and asks you for a form's password again. Blocking storage entirely still lets you fill in and submit a form.

Contact

Questions about this notice go to the operator at [email address]. The operator should record the date of the last change here: [date].