Aooform

Privacy Policy

How Aooform collects, uses, and protects your information.

1. Information we collect

When you use Aooform we collect:

  • Account data: email, name, and avatar from the Google account you sign in with.
  • Content you create: forms, questions, options, design settings, and any logos you upload.
  • Form responses: answers that respondents submit to your forms, including file attachments where applicable.
  • Technical data: hashed IP address, user agent, and cookies used for authentication and marketing analytics.

2. Use of Google user data

Aooform's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • We request the forms.body.readonly scope only to read the structure of Google Forms you choose to import (we do not read Google Form responses).
  • We use this data solely to create a new Aooform form that mirrors the structure of your original, at your explicit request.
  • We do not sell, transfer, or use Google user data for advertising.
  • We do not use Google user data to train AI or machine-learning models.
  • We store an access token and refresh token to reconnect on your behalf. You may revoke this access at any time at myaccount.google.com/permissions.

3. How we use information

  • Provide form-building and response-collection functionality.
  • Authenticate users and manage access permissions.
  • Send a thank-you email to respondents who submit their email address.
  • Forward marketing conversion events through Meta Pixel and the Conversions API when the form owner configures a Pixel ID. Email and phone are sent as SHA-256 hashes.
  • Investigate issues and improve the service.

4. Third-party services

We rely on the following providers:

  • Supabase — database and authentication (hosted in ap-south-1).
  • Vercel — website hosting.
  • Google OAuth — sign-in and Google Forms import.
  • Resend — sending thank-you emails.
  • Meta (Facebook) — conversion event reporting when configured by the form owner.

5. Retention

  • Forms and responses: retained until the form owner deletes them.
  • Files uploaded by respondents: automatically deleted 90 days after submission.
  • Google OAuth tokens: retained until you disconnect or revoke access.
  • User accounts: deleted when you close your account.

6. Your rights

You can:

  • Access, edit, or delete your personal data.
  • Export your forms and responses as CSV.
  • Revoke Google access from your Google account.
  • Close your Aooform account by contacting us.

7. Security

All connections use HTTPS. Data is stored in Supabase with Row-Level Security enforced on every request. Access tokens are stored encrypted at rest.

8. Changes to this policy

We may revise this policy from time to time. The updated date is shown at the bottom of this page. Continued use of the service after a change constitutes acceptance of the revised policy.

9. Contact

For any privacy-related questions or requests, contact us at support@aooform.com.

Last updated: 2026-05-18