Public policy
Privacy Policy
Effective and last updated: August 5, 2026
Qualyo Forms provides form-building, publishing, routing, response, analytics, billing, and optional AI features. This policy describes the data handled by the current product. It does not invent a legal entity name, postal address, fixed retention period, or jurisdiction that the service owner has not published.
Privacy questions and requests: support@qualyoforms.com.
1. Who provides the service
“Qualyo,” “Qualyo Forms,” “we,” and “us” refer to the operator of qualyoforms.com and the Qualyo application. The operating legal entity, postal address, and a universal governing jurisdiction have not been published in the product. Contact us before relying on Qualyo for a workflow that requires those details in a data-processing agreement.
2. The data we handle
- Account and workspace data: email address, authentication identifiers, profile and workspace settings, memberships, notification settings, and subscription status.
- Form and response data: form content, visual routes, publishing settings, respondent answers, uploaded documents or images, drawn-signature images, contact fields selected by the form owner, qualification output, summaries, and lead-management fields.
- Usage and diagnostic data: views, starts, submissions, completion and drop-off events, route outcomes, attribution parameters, security events, logs, device or request information, and product interactions.
- Billing data: Stripe customer, subscription, price, billing-status, and related identifiers. Qualyo does not store full payment-card numbers.
- Support and contact data: messages, email address, and context you submit when asking for help or a correction.
3. Form owners and respondents
A Qualyo customer decides what a form asks, who receives it, which routes and AI criteria apply, where a webhook sends data, and how responses are used. In many contexts, that customer determines the purpose of respondent-data processing and Qualyo processes the data to provide the service. Respondents should direct requests about a specific form to its owner when possible; we can help route a request when given the form URL and relevant details.
Published form wording and branding are intentionally public to anyone with the link or access to an embed. Respondent answers are not intended to be public.
4. How we use data
- Authenticate users and provide workspaces, forms, responses, routes, analytics, notifications, exports, billing, and support.
- Secure the service, prevent abuse, diagnose failures, and maintain operational records.
- Process optional AI wording, qualification, and summaries when the form owner enables those features.
- Deliver lifecycle and submission email, owner-configured webhooks, and billing operations.
- Measure product and form performance and improve the service.
- Comply with legal obligations and enforce service terms.
5. Optional AI processing
When an AI feature is invoked, the server sends the minimum relevant form instructions, earlier answers, and operating context needed to the configured AI provider. Providers may include OpenRouter and the model providers selected behind that service. Their separate terms and privacy notices may apply.
Qualyo’s usage ledger stores account, form, respondent-flow, billing-period, reservation, and settlement metadata used to count AI conversations; it is not designed to duplicate respondent answers. AI output can be incomplete or incorrect. Every Qualifier has a form-owner-selected automatic qualify or disqualify fallback for provider or allowance failures.
6. Service providers and disclosures
Qualyo uses service providers only as needed to operate the product. Current categories and providers include Supabase for authentication, database, and storage; Vercel for application hosting and custom-domain operations; Stripe for subscriptions and payment processing; configured OpenRouter/model providers for optional AI; Loops for lifecycle or submission email; and DataFast and PostHog for product analytics when configured. Data also goes to webhook destinations explicitly configured by a workspace owner.
We may disclose information when required by law, to protect the service or people, in connection with a business transaction, or with the relevant user’s direction. We do not sell personal information as a data-broker product.
7. Cookies, local storage, and analytics
Qualyo uses authentication storage and other browser storage needed to keep sessions, attribution, and product settings working. Product analytics may record page, signup, form, upgrade, and workflow events. Browser privacy settings can limit some storage; essential authentication and security behavior may still be required to use the application.
8. Retention and deletion
Qualyo has not published one fixed retention period for every data category. Data is retained while needed to provide and secure the service and for legitimate billing, fraud-prevention, dispute, backup, and legal records. Workspace owners can export available response data and may request account or personal-data deletion through support. A request may require identity verification and may not immediately remove records that must be retained for security, billing, or legal reasons.
9. Security
Qualyo uses encrypted transport, authenticated server operations, access controls, private storage for respondent uploads, and Supabase row-level security to separate workspace data. No online service can promise absolute security. Users are responsible for protecting credentials, limiting what they collect, and configuring forms, recipients, and webhooks appropriately.
10. International processing
The service and its providers may process data in countries other than the user’s or respondent’s country. A formal region-specific transfer statement or data-processing addendum is not currently published. Contact support before using Qualyo where your organization requires one.
11. Choices and rights
Subject to applicable law and verification, a person may request access, correction, export, restriction, objection, or deletion of relevant personal information. Some requests should be handled by the form owner because that owner selected the questions and purpose. Marketing or lifecycle email can be managed through available unsubscribe controls or by contacting support.
12. Children and sensitive data
Qualyo is a business form product and is not designed as a child-directed or clinical service. Form owners are responsible for establishing a lawful basis, obtaining required consent, publishing their own notice, and avoiding information they do not need. Do not treat Qualyo qualification as healthcare, credit, employment, housing, or another consequential decision without appropriate human review and legal assessment.
13. Changes and contact
We may update this policy as the product or legal requirements change. The effective date above will change when the public policy changes materially. Send privacy questions or requests to support@qualyoforms.com, or use the contact page.