Policies
Privacy policy.
Privacy policy
Effective 28 August 2026.
This policy covers the free hosted service at forms.shibumistack.dev. A self-hosted instance needs a privacy policy from its operator.
Who handles the data#
Shibumi Forms is operated by an independent project maintainer using the public name bitbonsai. Privacy questions and data requests can be sent to [email protected].
The project maintainer decides how account, authentication, security, and service-operation data is used. A site owner decides what a form asks for and why. Shibumi Forms processes submission content for that site owner.
If you submitted a form on someone else's site, contact that site owner first. The site owner can access, export, and delete submissions. Shibumi Forms may need the owner's help to identify your record.
What the hosted service stores#
Account records contain the account owner's email address, Terms version and acceptance time, and account timestamps. Form records contain the form name, registered page URL, allowed origin, success URL, and active state.
Magic-link records contain the account email, purpose, expiry, timestamps, and a SHA-256 hash of the token. Session records contain a SHA-256 token hash, expiry and activity timestamps, and a general device label derived from the account owner's user agent. Raw magic-link and session tokens are not stored.
Submission records contain the named fields sent by the form, submission time, and private notes added by the account owner. Shibumi Forms does not add the visitor's IP address or user agent to a submission record. A form can send either value as a named field.
Per-form request history contains timestamp, request ID, HTTP method, normalized Origin domain when supplied, response status, outcome, and duration. Account owners can read this history in their dashboard, including why requests to their known endpoints were rejected or failed. It contains no submission payload, URL path, IP address, user agent, email address, token, cookie, or secret.
Application output logs contain request IDs, route classes, status codes, and durations. They exclude email addresses, submission payloads, tokens, cookies, and secrets.
Why data is processed#
The service uses account and form data to receive submissions, show them in the private dashboard, and export CSV files. It uses account and request data for authentication, service limits, abuse prevention, recovery, and legal obligations.
The site owner is responsible for the legal basis for data collected through their form.
Where data is processed#
The live SQLite database is /data/shibumi-forms.sqlite on a persistent Hetzner Cloud volume in Falkenstein, Germany, data center fsn1-dc14, region eu-central. Hosted accounts share the database file. Every admin data query checks account ownership.
HTTPS protects data in transit. Submission payloads are not end-to-end encrypted. The service operator can access the server and database for operations, security work, or recovery.
Other providers process limited data for the service:
- Hetzner hosts the server and persistent storage in Germany.
- Cloudflare proxies traffic and provides the Turnstile abuse check. It receives network and browser data needed for those services.
- Resend receives an account owner's email address and one-time confirmation link to deliver sign-in and account-deletion emails.
Database location does not determine where Cloudflare or Resend process their data. Their handling follows their own privacy terms. Shibumi Forms has no advertising or tracking analytics and does not sell personal data.
Cookies and local storage#
The service uses an essential session cookie after sign-in. It is HttpOnly, Secure in production, and SameSite=Lax. A regular session lasts 24 hours. Choosing "Keep me signed in for 30 days on this device" extends it to 30 days.
The browser stores the light or dark theme choice locally. Cloudflare Turnstile may use browser storage for its abuse check.
Retention and deletion#
Forms, submissions, and per-form request history remain until the account owner deletes their parent record. Deleting one submission does not delete its corresponding request entry. Account records remain until account deletion.
Startup cleanup removes magic-link records more than 48 hours old and removes expired sessions. An expired link or session cannot authenticate while it awaits cleanup.
Deleting a submission removes its content from the live database while its payload-free request entry remains. Deleting a form removes its submissions and request history. Account deletion removes the account, forms, submissions, request history, and sessions. A magic-link delivery record can remain until startup cleanup.
The daily forms-backup.timer stores database backup files under /data/backups on the same persistent volume as the live database. The operator retains them for up to 30 days. Deleted records may remain in those files until they expire. The operator has not verified a separate encrypted off-host backup.
Account owners can export submissions as CSV and delete submissions, forms, or the account from the dashboard. Send other access, correction, or deletion requests to [email protected]. Form submitters should contact the site owner first.
Changes#
Policy updates will appear here with a new effective date.