Privacy

FormShield processes the message text, sender name and email supplied by the website using the service. When TypeSafe is configured, these inputs are sent to TypeSafe for classification. Rule fallback and the public rules demo do not call TypeSafe.

The application does not intentionally store submission bodies. Infrastructure providers may process connection metadata and operational logs. Account contact email, credential hashes, subscription identifiers and usage counters are stored in PostgreSQL. Creem processes payments; FormShield does not receive full card numbers.

Sign-in uses a secure, HttpOnly session cookie. Google provides basic profile information and a verified email when you choose Google sign-in. Resend processes your email address and verification code to deliver sign-in messages. Authentication records, session metadata and hashed verification codes are stored in PostgreSQL. Old browsers may retain legacy credentials until you link your key. Sign out on shared devices. Website operators must disclose the service to their visitors and determine an appropriate basis for processing.

This page describes the implementation and is not a certification of compliance. Data retention and operator identity must be finalized before public launch.

Contact: leileid6@gmail.com