Privacy Policy

Last updated: December 13, 2025

VeilForms is built on a simple principle: we cannot read your data, so we cannot misuse it.

This privacy policy explains what data we collect, how we use it, and why our zero-knowledge architecture means we know less about you than traditional form services.

The Short Version

Who We Are

VeilForms is operated by ZTAS.io, a privacy-focused software company.

Contact:

What Data We Collect

1. Account Information

When you create an account, we collect:

2. Encrypted Form Submissions

When users submit forms:

Critical detail: Form data is encrypted client-side with your public key. We receive only ciphertext. We mathematically cannot decrypt it.

3. Usage Data

We collect minimal analytics:

What we DON’T collect:

4. Technical Data

Standard server logs:

Logs are used solely for security, debugging, and preventing abuse.

How We Use Your Data

Account Management

Service Operation

We do NOT:

Zero-Knowledge Architecture

VeilForms is designed so we cannot access your form data:

  1. You generate keypairs on your device (public + private key)
  2. You keep the private key (we never see it)
  3. Users encrypt submissions in their browser with your public key
  4. We store ciphertext that we cannot decrypt
  5. You decrypt locally or on your server using your private key

This means:

Data Sharing

We share data only in these limited circumstances:

Service Providers

All providers are GDPR-compliant and operate under strict data processing agreements.

We may disclose data if required by law, but:

We’ll share data if you explicitly authorize it (e.g., support requests).

We will NEVER:

Data Retention

Data Deletion

You can delete data anytime:

When you delete:

Your Privacy Rights

Depending on your location, you may have these rights:

GDPR (EU/UK)

CCPA (California)

Other Jurisdictions

We respect privacy rights globally and will honor requests to the extent legally possible.

To exercise rights: Email privacy@veilforms.com with your request. We’ll respond within 30 days.

Cookies and Tracking

VeilForms uses minimal cookies:

Essential Cookies

These are necessary for the service to function. No consent required.

No Tracking Cookies

We do NOT use:

We respect Do Not Track (DNT) signals as standard practice.

Children’s Privacy

VeilForms is not intended for users under 16. We don’t knowingly collect data from children.

If you believe a child has created an account, contact privacy@veilforms.com and we’ll delete it immediately.

International Data Transfers

VeilForms is hosted on Netlify’s global edge network (primary: US-East). If you’re outside this region:

Security Measures

We protect your data with:

Even with a server breach, encrypted submissions remain unreadable without your private key.

Changes to This Policy

We may update this policy as we add features or comply with new regulations.

We’ll notify you of material changes:

Continued use after changes constitutes acceptance.

Version history:

VeilForms may link to external sites. We’re not responsible for their privacy practices. Read their policies before sharing data.

Contact Us

Questions about this policy or your data?

We are a small team operating remotely. For EU/UK data protection inquiries, contact privacy@veilforms.com.


Summary Table

Data TypeWhat We CollectHow We Use ItCan We Read It?
Form submissionsEncrypted blobStore and deliver to youNO - Encrypted
Email addressYour account emailLogin, notificationsYes
Payment infoStripe tokenBillingNo (Stripe handles)
Usage analyticsView counts, error ratesImprove serviceYes (anonymized)
IP addressesServer logsAbuse preventionYes (7-day retention)
Private keysNever collectedN/ANever have access

The key difference: Traditional form services see all your submissions in plaintext. We see only encrypted ciphertext.


This policy is effective as of December 13, 2025.