Skip to content

Privacy Policy for LucidForms

Last Updated: September 11, 2026

Effective Date: September 11, 2026

Website:https://lucidforms.co

Contact Email:[email protected] (or [email protected])


1. Introduction & Scope

Welcome to LucidForms ("we," "our," or "us"). LucidForms provides form backend infrastructure, submission processing, spam filtering, file handling, and automated integration services for developers, website owners, and businesses ("Customers" or "Account Holders").

This Privacy Policy explains how we collect, process, disclose, and safeguard information when:

  1. You visit or use our platform at lucidforms.co and its associated subdomains, web applications, and APIs (as an Account Holder / User).
  2. You submit data through a form endpoint operated by LucidForms on behalf of one of our Customers (as an End-User / Form Respondent).

Please read this Privacy Policy carefully. By creating an account, accessing our services, or submitting data to a LucidForms endpoint, you acknowledge that you have read and understood this policy.


2. Roles Under Privacy Laws (GDPR, UK GDPR, CCPA/CPRA)

To understand how your data is handled, it is critical to distinguish between two data protection roles:

  • LucidForms as Data Controller:We act as a Data Controller for the personal data of our direct Customers (account holders, billing contacts, dashboard visitors). We determine why and how this information is collected and processed.
  • LucidForms as Data Processor / Service Provider:When end-users submit data to a form endpoint created by our Customers,the Customer is the Data Controller, and LucidForms acts as a Data Processor (or "Service Provider"). We process form submission payloads and uploaded files strictly in accordance with our Customer’s instructions, form configurations, and our Terms of Service.

3. Information We Collect

A. Information We Collect from Account Holders (Customers)

  • Account & Authentication Information:
    • Email address, display name, and avatar/profile picture.
    • Authentication details (OAuth tokens from Google Sign-In, or time-based one-time password / magic link verification records).
  • Billing & Subscription Details:
    • Plan tier (Free, Pro), subscription status, transaction IDs, add-on quota purchases.
    • Note: All payment and card transactions are processed securely through our payment provider (Dodo Payments). LucidForms does not collect or store credit card numbers, CVVs, or full banking details on our servers.
  • Service Configurations & Settings:
    • Form configurations (form names, honeypot settings, spam thresholds, allowed domains, notification emails, redirect URLs, custom auto-responder templates).
    • Connected third-party OAuth tokens (e.g., Google Sheets, Notion workspace authorizations).
  • Usage & Telemetry Data:
    • Monthly submission counts, storage usage (in bytes), spam block metrics, browser type, IP address, and platform log records.

B. Information We Collect from Form Respondents (End-Users)

When an end-user submits a web form powered by LucidForms:

  • Form Submission Payloads: All form fields supplied by the user (e.g., names, emails, phone numbers, free-text messages, customized business data).
  • File Uploads: Any files (images, documents, PDFs) uploaded through supported forms, stored securely on cloud storage.
  • Technical & Anti-Spam Metadata:
    • Client IP address and User-Agent string (used strictly for bot mitigation, rate-limiting, geo-routing, and security checks).
    • Referrer header and origin domain (to enforce whitelist settings configured by the form owner).
    • Captcha tokens (Turnstile, hCaptcha, or Google reCAPTCHA v2) submitted alongside the form.
    • Timestamps of submission.

4. How We Use the Collected Information

We process personal data for the following legitimate business and operational purposes:

PurposeCategory of DataLegal Basis (GDPR Art. 6)
Provide Core ServicesAccount data, form configurations, submissions, file uploadsPerformance of Contract (Art. 6(1)(b))
Submission Routing & NotificationsRespondent data, notification emails, webhook URLsPerformance of Contract / Processor Instructions
Spam & Abuse ProtectionIP, User-Agent, honeypot fields, submission text, CaptchaLegitimate Interests (Art. 6(1)(f))
Billing & Quota ManagementDodo customer IDs, submission volumes, file storage bytesPerformance of Contract / Legal Obligation
Automated RespondersRespondent email and submitted fieldsPerformance of Contract / Legitimate Interests
Inactivity & Usage AlertsCustomer email, submission timestampsPerformance of Contract / Legitimate Interests
Platform Security & AuditingServer logs, error traces, webhook verification logsLegitimate Interests (Art. 6(1)(f))

5. Automated Processing & AI Spam Filtering

LucidForms provides optional and configurable spam protection features to safeguard forms:

  • Rule-Based & Honeypot Checks: Evaluation of hidden honeypot fields, banned keyword lists, and domain whitelists.
  • Third-Party Captcha Verification: Forwarding client tokens to Google reCAPTCHA, Cloudflare Turnstile, or hCaptcha.
  • AI-Assisted Spam Classification (Google Gemini):

    If enabled by the form owner, submission text is analyzed by our automated spam classifier powered by Google GenAI (Gemini) against categories such as profanity, fraud, deceptive phishing, malware/drugs/crypto-spam, and automated mass-solicitation.

    Data Privacy in AI: Submission data analyzed for spam filtering is transmitted via API solely for real-time classification and scoring. It is not used by LucidForms to train public foundation models.


6. Third-Party Sub-Processors & Service Providers

To operate our cloud-native infrastructure, LucidForms partners with industry-leading sub-processors. All providers are vetted to ensure standard contractual clauses (SCCs) and robust data security:

  • Convex (Convex Inc.): Real-time database, backend compute, scheduled jobs, and workflow orchestration.
  • Cloudflare (Cloudflare, Inc.):
    • Edge workers (Cloudflare Workers) handling initial intake, rate-limiting, and CORS preflight.
    • Cloudflare R2 object storage for securely hosting uploaded files and form attachments.
  • Dodo Payments: Merchant of record and payment processor for subscriptions, billing, and add-ons.
  • Amazon Web Services (AWS SES): Transactional email delivery (login OTPs, new submission alerts, quota warnings, automated respondent emails).
  • Google Cloud / Google GenAI: AI API used for form submission spam evaluation.
  • Google Workspace & Notion APIs: When explicitly connected by an Account Holder to route form entries to Google Sheets or Notion databases.

7. Data Retention & Deletion

We believe in strict data minimization. Data retention schedules depend on account tier and feature settings:

  1. Form Submissions & Database Records:
    • Free Tier Accounts: Submissions with storage enabled are automatically retained for 7 days, after which they are permanently deleted from database records.
    • Pro Tier Accounts: Form submissions are retained indefinitely until manually purged or exported by the Account Holder.
    • Spam Submissions Queue: Submissions classified as spam are held for review for 14 days and automatically deleted thereafter.
    • Quota Overflow Submissions (Pro): Submissions held in overflow status must be cleared within 30 days, following which they are purged.
  2. File Uploads (Cloudflare R2):

    Uploaded files remain stored as long as the parent submission or form exists. If a submission, file, or form is deleted by the user, the corresponding object is permanently purged from R2 storage.

  3. Account Deletion & Grace Period:

    When an Account Holder requests account deletion via account settings, the account is marked for deletion and subject to a 7-day soft-delete grace period during which the user can cancel the request.

    Upon expiration of the 7-day period, the user record, projects, forms, API configurations, stored submissions, integrations, and files are permanently and irreversibly deleted.


8. International Data Transfers

LucidForms uses globally distributed cloud infrastructure (including Cloudflare Edge, AWS, and Convex). Your personal data may be transferred to, stored, and processed in the United States and other jurisdictions outside your country of residence.

Where data is transferred out of the European Economic Area (EEA), the United Kingdom, or Switzerland to countries without an adequacy decision, we ensure adequate safeguards are in place through Standard Contractual Clauses (SCCs) adopted by the European Commission.


9. Security Safeguards

We implement modern, defense-in-depth technical and organizational measures to safeguard information:

  • Encryption in Transit: All traffic to lucidforms.co, worker endpoints, and backend APIs requires HTTPS (TLS 1.2 or TLS 1.3).
  • Encryption at Rest: All submission records, tokens, and file attachments are stored with AES-256 encryption at rest.
  • Access Isolation: Third-party OAuth tokens (Google, Notion) and API credentials are stored securely and isolated at the database level.
  • SSRF & Loop Protection: Outbound webhooks undergo domain validation, loop prevention, and private IP blocking to prevent unauthorized intranet scraping.

10. Your Rights & Choices (GDPR & CCPA/CPRA)

Depending on your location, you have statutory rights regarding your personal information:

  • Right to Access & Portability: Request a copy of the personal data we hold about you.
  • Right to Rectification: Update or correct incomplete or inaccurate personal data.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your account and related records.
  • Right to Restrict or Object to Processing: Object to specific processing activities based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent (e.g., OAuth integrations), you may disconnect or revoke permissions at any time.
  • Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

How to Exercise Your Rights:

  • Account Holders: You can access, export, or delete your data by emailing [email protected].
  • Form Respondents: Because LucidForms processes submissions on behalf of our Customers, please contact the website owner or organization that provided the form. If you contact us directly with a request regarding a specific form submission, we will forward your inquiry to the relevant form owner.

11. Cookies and Tracking Technologies

  • Essential Cookies / Session Storage: We use essential session and authentication tokens (e.g., authentication session cookies) to keep you logged into the application dashboard.
  • PostHog (Marketing Website Analytics): We partner with PostHog to capture how you use and interact with our public marketing website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. This tracking is strictly limited to our marketing website. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how PostHog collects and uses your data, visit thePostHog Privacy Policy.
  • Dashboard & Form Submission Endpoints: LucidForms does not track your behavior inside the application dashboard or on your form submission endpoints. We do not sell personal information, do not rent submission data, and do not deploy cross-site third-party advertising or analytics trackers (including PostHog) on the application dashboard or form submission endpoints.

12. Children’s Privacy

LucidForms is intended for developers, businesses, and general professional use. Our service is not directed to individuals under the age of 16 (or under 13 in the US). We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal information without parental consent, please notify us at [email protected].


13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our technology, regulatory requirements, or business operations. When updates occur, we will revise the "Last Updated" date at the top. For material changes, we will notify registered Account Holders via email or through a prominent notice on the dashboard.


14. Contact Us

If you have questions, feedback, or requests regarding this Privacy Policy or our data handling practices, please contact our privacy team at: