Privacy policy
Last updated 2026-05-26.
1. Who we are
TruForms is operated by TruenoTech, India. We are the controller of data about TruForms account holders and the processor of data about the people who submit their forms — see our DPA for the processor side.
2. Data we collect about you (the account holder)
When you sign up: your name, email, hashed password (Argon2id with a server pepper), and any workspace details you enter. When you use the service: form configurations, integration settings, billing records (managed by Razorpay), and audit logs. When you contact support: the messages you send us.
3. Data we collect about your form submitters
Whatever fields you collect in your forms — we don't inspect or repurpose that content. We also record the submitter's IP address, user-agent, timestamp, and spam score, used solely for delivering the submission to you, scoring spam, and enforcing rate limits.
4. How we use it
To provide the service (deliver submissions, fan out to integrations, render dashboards), bill you, prevent abuse, debug incidents, and contact you about your account. We do not sell personal data and we do not use submission contents to train any model.
5. Sharing
Sub-processors: Razorpay (billing), Microsoft Graph (email delivery), Cloudflare R2 (object storage for uploads), and our hosting provider. Each handles a narrow slice of data under written agreement. We share with law enforcement only when compelled by valid legal process, and we will notify you unless legally prohibited.
6. International transfers
Default region is Mumbai (ap-south-1). EU-region hosting is available on Business plans. When data crosses borders, we rely on Standard Contractual Clauses (SCCs) and equivalent safeguards.
7. Security
See the Security page for details — encryption at rest (AES-256-GCM) and in transit (TLS 1.2+), Argon2id password hashing, opaque session tokens, HMAC-signed webhooks. Report vulnerabilities to [email protected].
8. Retention
Submissions are retained per your plan's retention window (Free: 30 days, Pro/Business: 365 days) and deleted automatically after that. Account records are kept while your account is active and for up to 90 days after closure, after which they are deleted or anonymised. Billing records are retained for the period required by applicable tax law.
9. Your rights
You can access, correct, export, and delete your account data at any time from the dashboard. EEA/UK and Indian DPDP rights (access, rectification, erasure, portability, objection, withdrawing consent) are honoured — email [email protected] and we will respond within 30 days. You can lodge a complaint with the data protection authority in your country.
10. Children
TruForms is not directed at children under 16. We do not knowingly accept accounts from them; if you believe a child has signed up, email [email protected] and we will delete the account.
11. Changes and contact
Material changes will be announced at least 14 days in advance to the workspace owner. Questions about this policy or to exercise your rights: [email protected].