Legal

Cookie Policy

Last updated: 9 August 2026

Cookies and storage we use

Cookies and browser storage used by HelloForms, with purpose, category and duration
NamePurposeCategoryDuration
Authentication session tokenKeeps you signed in to your HelloForms account and lets the app refresh your session without asking for your password again.Strictly necessaryUntil sign-out, or 30 days of inactivity
Workspace interface preferencesRemembers sort order, expanded template categories, sidebar state and similar view choices so the workspace looks the same next visit.Functional (local storage)Until you clear browser storage
Builder editing sessionHolds short-lived editor state such as undo/redo history for logic fixes while you stay in the same builder session.Functional (session storage)Cleared when the tab closes
Draft form claim tokenLets someone who started a form before signing up claim that draft once they create an account.Strictly necessaryUp to 7 days
Abuse and rate-limit signalsShort-lived values used to detect submission floods and repeated failed sign-ins, protecting your forms from spam.SecurityMinutes to hours

1. What this covers

This policy explains the cookies, local storage and session storage that HelloForms sets on helloforms.net and inside the signed-in application. It sits alongside our Privacy Policy, which describes how we handle personal data more broadly.

2. We do not run advertising trackers

HelloForms sets no advertising, retargeting or cross-site profiling cookies. We do not embed third-party ad networks or social pixels, and we do not sell or share browsing data.

3. Published forms and your respondents

A form you publish does not set marketing or tracking cookies on the people who fill it in. Respondents may receive strictly necessary values needed to submit the form safely, such as an anti-abuse token or partial-response key when you enable save-and-resume.

4. The No-Spying guarantee for embedded forms

When one of your forms is embedded on another website — through our iframe embed, our JavaScript tag or a direct form link — the form is rendered in an isolated context that deliberately omits every marketing and analytics script we use on our own marketing site. No tag manager container, no advertising or conversion tags, no retargeting pixels and no third-party ad or social scripts are loaded inside the form. Only the code needed to render the form, validate answers and submit them securely is served. The embed also never reads or writes cookies belonging to the host page, and it never reports the host page's visitor data back to us for advertising purposes. If you add your own tracking to the page around the embed, that is your responsibility and must be disclosed in your own notices.

5. Managing cookies

You can clear or block cookies and site storage in your browser settings at any time. Blocking strictly necessary items will sign you out and can stop the builder from saving your work; functional preferences will simply reset to their defaults.

6. Changes and contact

If we add or remove a cookie we will update the table above and revise the date below. Questions about this policy: hello@helloforms.net.

See also our Privacy Policy and Data Processing Agreement.