Skip to main content

Privacy Policy

Last updated 21 July 2026

Fillo is operated by Jafu ApS in Denmark. This policy explains how Fillo handles personal data when you build forms, render them inside your product, and collect responses. You can contact us at hello@fillo.so.

Two roles

For your account (you, the person who signs up and builds forms) we are the data controller. For the responses your forms collect from your end users, we act as a data processor on your behalf — you are the controller of that data. Our processor commitments are set out in the Data Processing Agreement.

What we collect about account holders

  • Account details: your name, email address, and a hashed password (passwords are never stored in plain text).
  • Workspace data: organisation name, members, and the forms you create.
  • If you sign in with Google: your Google account identifier, email, basic profile details such as your name, and the sign-in tokens the authentication provider needs (scopes openid, email, and profile).
  • Operational logs needed to run and secure the service (e.g. request timestamps, IP address, error logs).

Slack connection data

When a workspace manager connects Slack, Fillo stores the Slack workspace identifier and name, the bot user identifier, an encrypted bot access token, and a cache of channel identifiers and names used by the channel picker. Private channels enter that cache only after the Fillo bot has joined them. Fillo does not request or read Slack message history.

For each form using Slack, Fillo stores the selected workspace and channel identifiers and whether the channel was private. When a response is accepted or updated, Fillo sends Slack the form name, event time, a link to the response, an optional verified respondent name or email, and up to three answer fields explicitly selected by a form manager. Uploaded file contents and every unselected answer stay out of Slack.

What we process on your behalf

  • Form responses: the answers your end users submit, plus metadata such as the source route, timestamps, and review status.
  • Email addresses your forms collect, if any.
  • Uploaded files: files are stored in your connected storage (Google Drive, Box, or an S3-compatible bucket). Uploads go browser-direct; for Drive and Box, authenticated downloads may stream through Fillo so workspace members can access them. We store file metadata and a reference to where the file lives, not a long-term copy of the file contents.
  • Saved progress (optional, per form): when you turn on Save and resume, we store your end users’ in-progress answers before they submit, so they can pick up where they left off. A draft is readable with a one-time token held in the respondent’s browser — and, if you additionally turn on the in-progress content view for a form, by members of your workspace, so you can help someone finish. If you turn on resume emails, we use an address the respondent entered (or their verified account email) to send them a single link back to their draft. Drafts are deleted when the response is submitted, when the respondent starts over, or automatically 7 days after the last change.
  • Respondent identity (optional): if your app passes account context with identify(), we store the identifier you send (your own user id) and any email, name, or attributes you include, and attach it to the responses that person submits. You decide whether to send it, and you can require it to be cryptographically signed by your server before we record it.

Product and documentation usage

Fillo records coarse server-side product and documentation events to understand reliability and improve the service. Documentation search text stays in your browser. A search event can include the page path, a coarse query-length range, a coarse word-count range, the result count, and whether it returned zero results. We do not send or store the search text, a hash of it, or another query fingerprint. Other documentation events can include an up or down feedback vote, a guide topic filter, and actions such as copying a page or opening its machine-readable version.

These events do not include form answers and use a shared service identifier instead of an analytics cookie or visitor profile. They are not used for advertising, individual visitor tracking, or cross-site tracking. They are not guaranteed to be anonymous: ordinary request handling, security, and rate-limiting infrastructure may still process an IP address and other request metadata.

Why we process data, and our legal bases

  • To provide the service you signed up for (performance of a contract).
  • To keep the service secure and prevent abuse — rate limiting, spam protection, logs (legitimate interests).
  • To understand coarse product and documentation usage and improve reliability, navigation, and support content (legitimate interests).
  • Optional features you switch on, such as email notifications and AI form drafting (consent / contract).

Who we share data with

We do not sell personal data, use it for cross-context advertising, or send form answers to analytics tools. We share data only with the providers that help us run Fillo: EU hosting, transactional email, optional AI drafting, and diagnostics and coarse product or documentation usage measurement for reliability and improvement. The full list, with legal entities, purpose, location, and safeguards, is on our Sub-processors page.

If you enable customer-connected destinations — such as webhooks, Google Sheets, Notion, Slack, or Zapier — we send the relevant response data to those destinations on your instructions. Those accounts and endpoints are controlled by you, not by Fillo.

Where data is stored, and international transfers

Fillo runs on servers in the European Union, and the responses your forms collect are stored there too. Uploaded files go to the storage you connect, such as Google Drive, Box, or an S3-compatible bucket; Fillo keeps the response itself, the file’s metadata, and a reference to where the file lives. Limited data may leave the EEA only when a feature needs it — for example, sending an email through Resend or drafting a form with Anthropic — and those transfers use Standard Contractual Clauses and the providers’ data-processing terms.

How long we keep it

  • Account and workspace data: for as long as your account is active. Account and workspace deletion has a 21-day grace period before permanent deletion.
  • Slack connection token and channel cache: until a workspace manager disconnects Slack or the workspace is deleted. A form's selected Slack channel remains until the destination or form is removed; delivery telemetry is covered by the logging period below.
  • Responses: until you delete them or close the workspace. You can export and delete responses at any time.
  • Saved-progress drafts: deleted when the response is submitted, when the respondent starts over, or automatically 7 days after the last change — whichever comes first.
  • Respondent identity and profiles: kept while the person has responses in the workspace; you can erase a person (their profile, drafts, and identity, and optionally their responses and files) at any time.
  • Logs, delivery telemetry, and coarse product or documentation usage events: kept only as long as needed for security, debugging, reliability, and service improvement; structured telemetry rows are generally kept up to 90 days.

How we protect it

  • Encryption in transit (TLS) on every request, and encryption at rest for the database.
  • App-used provider credentials, such as S3 keys and connected Drive, Box, and Notion tokens, are encrypted at rest with AES-256-GCM.
  • Every form, response, file reference, storage connection, and integration is scoped to a workspace and checked server-side.
  • Public submission endpoints validate the form schema, cap request size, rate-limit abuse, and use honeypot protection.
  • Uploaded file references must belong to the expected form before they can be attached to a response.
  • Webhooks are signed, and customer-connected destinations are used only on your instructions.
  • When you delete a response or erase a respondent, Fillo removes linked records and attempts to remove managed file references; if connected storage is unreachable, the delete fails closed so it can be retried instead of silently orphaning data.

Your rights

Under the GDPR you can request access, correction, deletion, a portable copy, or restriction of your personal data, and you can object to certain processing. Email hello@fillo.so and we’ll respond within the legal time limits. You can also complain to your local supervisory authority; for Jafu ApS this is the Danish Data Protection Agency (Datatilsynet). For responses your forms collected, contact the business that ran the form — they are the controller of that data.

US privacy

We do not sell personal data or share it for cross-context behavioural advertising. If a US state privacy law gives you rights such as access, deletion, correction, or appeal, you can use the same contact email above.

Cookies and browser storage

We use only the essential cookies needed to keep you signed in and protect sessions. We do not use advertising or analytics cookies. Documentation usage events are sent to a same-origin server endpoint without a browser analytics identifier. Fillo embeds may also use browser localStorage for product state, such as remembering that a browser already submitted a form, caching code-form sync status, or storing a saved-progress draft reference. Draft answers themselves are stored on Fillo only when the form owner enables Save and resume.

Contact

Jafu ApS. Privacy questions: hello@fillo.so.

Changes

If we change this policy we’ll update the date above and, for material changes, let account holders know before the change takes effect.