Start
Data storage.
Data storage
A hosted submission travels over HTTPS from the visitor's browser to forms.shibumistack.dev. It leaves the static site and is stored by Shibumi Forms. The service does not email submission contents to the account owner.
What the hosted service stores#
The SQLite database contains:
- account email, Terms version and acceptance time, and account timestamps
- magic-link and session records, including SHA-256 token hashes, expiry times, and a general device label for sessions
- each form's name, registered page URL, allowed origin, success URL, and active state
- submitted field names and values, submission time, and any private note added by the account owner
- per-form request timestamp, request ID, HTTP method, normalized Origin domain when supplied, response status, outcome, and duration
Request history includes rejection and failure reasons for known form endpoints. It does not store submission payloads, URL paths, IP addresses, user agents, email addresses, tokens, cookies, or secrets.
The database stores submission field names and values as JSON text. File uploads are rejected. Submission records contain no visitor IP address or user agent added by Shibumi Forms. A form can send those values as named fields, in which case they become part of the submission.
Where hosted data lives#
The database file is /data/shibumi-forms.sqlite inside the service container. /data is a persistent Hetzner Cloud volume in Falkenstein, Germany, in data center fsn1-dc14 and region eu-central. The volume stays in place across application restart, deploy, and rollback.
All hosted accounts share this SQLite file. Every admin data query checks the authenticated account's ownership before reading or changing forms, submissions, and request history.
HTTPS protects data in transit. Submission payloads are not end-to-end encrypted. The service operator can access the server and database for operations, security work, or recovery. Keep passwords, payment card details, health data, government identifiers, and other highly sensitive information out of hosted forms.
Cloudflare proxies service traffic and provides Turnstile. Resend receives account email addresses and one-time confirmation links for sign-in and account deletion. The Privacy policy describes their roles.
Retention, export, and deletion#
Forms, submissions, and per-form request history remain until the account owner deletes their parent record. Each hosted form can hold 10,000 submissions. A full form rejects new submissions until the owner deletes old records.
Account owners can export submissions as CSV, delete one submission, delete a form, or delete the account. Deleting a submission removes its content while its payload-free request entry remains. Deleting a form removes its submissions and request history. Account deletion removes the account, its forms, submissions, request history, and sessions. Magic-link delivery records can remain until startup cleanup removes records more than 48 hours old.
The daily forms-backup.timer runs bun run backup -- /data/backups. Backup files stay under /data/backups on the same persistent volume as the live database and are retained for up to 30 days. Deleted records may remain in those files until they expire.
The operator has not verified a separate encrypted off-host backup. Keep regular CSV exports if you need an independent copy of submission data.
Self-hosted service#
A self-hosted instance writes its SQLite database to DATABASE_PATH. The supplied Compose setup uses /data/shibumi-forms.sqlite inside the forms-data named volume. The self-hosting operator controls the host, volume, backups, retention, and access.
See Backup and restore for self-hosted commands and Security and data handling for authentication, logging, and query isolation.