Security & data privacy
How JellyForm protects your data, plus answers to the security questions teams ask most.
Anonymous feedback only works if both sides trust the platform holding it. This article covers how JellyForm protects your organization's data, at the level most teams need to evaluate it. For the full legal detail, see our Privacy Policy and Terms of Service.
Encryption
- In transit: all communication with JellyForm uses TLS encryption.
- At rest: sensitive data is encrypted in storage. Optional respondent emails get an extra layer: each is encrypted and hidden from the box owner; only the system can decrypt it to send reply notifications.
What we collect — and don't
For registered users (your team), JellyForm stores the account basics: email, name, and your company's settings. For anonymous feedback givers, JellyForm stores only the submission content and conversation thread. IP addresses are not tracked or stored for anonymous submissions, and the submission form sets no identifying cookies. See How anonymity works for the full picture.
Your data stays yours
- We never sell or share customer data. Data is shared only with the service providers needed to run the product, as listed in the Privacy Policy.
- It's exportable. You can export your conversations at any time — see Export conversations to CSV.
- Deletion is real. If you cancel, your data is retained for 30 days in case you reactivate, then permanently deleted. Details in Cancel your subscription & what happens to your data.
Compliance questions
For organizations with formal requirements, a BAA/DPA is available on the Enterprise plan, along with custom data retention — contact sales@jellyform.com. If your security team has questions this page doesn't answer, reach out to support@jellyform.com and we'll answer them directly.
Related reading
Was this article helpful?
Related articles
Still need help?
Our team is happy to help you get the most out of JellyForm.
