Privacy Policy
Who we are
AutonomousForm is operated by MacroThread Software, Tel Aviv, Israel. For the purposes of data protection law, MacroThread Software is the controller of account-holder data and acts as a processor for the answers businesses collect through their own forms. You can reach us through our contact page.
Two kinds of people, two different roles
Account holders are businesses and creators who build forms here. For their account data, we decide what is collected and why.
Form respondents are the people who fill in someone's form. For those answers, the business that built the form decides what is asked and why — we only store and display it on their behalf. If you filled in a form and want your answers changed or removed, contact that business first. We will help them act on your request, but it is theirs to make.
What we store about account holders
Your name, email address, a hashed password, and the forms you build. We never store your password in readable form.
What we store about form respondents
The answers a person submits, the formatted message generated from them, the business number the message was addressed to, the time of submission, and the IP address the submission came from. We also record whether the person followed the link through to WhatsApp — which tells the form owner they got that far, not that the message was sent.
Answers saved before the form is finished. Some forms save answers step by step, before the form is submitted, so the business can follow up with someone who started an enquiry and dropped off. These partial entries include the answers given so far and the IP address they came from. They are kept separately, are shown to the form owner clearly marked as unfinished, and are deleted as soon as the form is completed, when the owner dismisses them, or after 30 days — whichever comes first. A form owner can switch this off per form in that form's settings.
Payment screenshots. If a form asks for proof of payment, the image attached is stored with the submission and is visible only to that form's owner. Do not attach anything you would not want that business to hold.
Bookings. If a form offers appointment times, we store the slot chosen and hold it briefly while the form is being filled in, so two people cannot book the same time.
What we never see
WhatsApp. We have no access to it. We cannot read chats, cannot see whether a message was delivered or read, and cannot send messages as you or as a respondent.
Payments. We do not process, receive, hold or verify any money. A form can show a total and link to the business's own Bit payment request, but the payment happens entirely between the respondent and that business, in Bit. We never see card numbers, bank details or payment credentials, and attaching a screenshot is not proof to us that anything was paid.
AI. AutonomousForm does not run, call or send anything to any AI model. The "build with AI" feature writes a prompt for you to copy into whichever assistant you already use; what you type there goes to that assistant under its own privacy policy, not ours. We only see the result if you choose to paste it back here.
Cookies
Almost every cookie here is one the service needs to work. The single exception is analytics, which only runs if you allow it — see Analytics below. There is no advertising.
- Sign-in — keeps an account holder logged in. If you start building a form before creating an account, this cookie is the only thing that connects you to what you've built.
- Language — remembers the language you chose.
- Security — a token on pages with forms, to prevent forged submissions.
- On public forms — where a form offers appointment times, a cookie identifies your session so the slot you picked is held for you; where a form saves answers before submission, a cookie links those answers to your browser so returning updates the same entry instead of creating another.
-
Analytics — only if you allow it — Google Analytics sets
_gacookies to tell visits apart. If you decline, none are set, and withdrawing consent removes them.
Analytics
With your permission, we use Google Analytics to understand how visitors find and use our website, so we can improve it. It runs only on our own marketing pages and on the sign-up and sign-in pages, only for visitors who are not signed in, and only after you choose to allow it. Until then nothing is loaded from Google.
It never runs on a business's public forms — the people filling those in are that business's customers, and we do not track them. It never runs inside an account, and never on the password-reset page.
What Google receives: the pages you visit (without anything after the ? in the address), roughly
where you are and what device and browser you use, and how you arrived. Never your form answers, and never
your name or email address. Advertising features and Google signals are switched off, and the data is not
used for advertising.
Google processes this data on our behalf and may transfer it outside your country, including to the United States, under Google's own safeguards. We keep analytics data for no longer than 14 months. You can change your choice at any time:
Where data is held
The service and its database run on Microsoft Azure. Data may be processed in the region that hosting is configured for, which may be outside your own country.
Who can see your data
Answers submitted through a form are visible to the account that owns the form. We do not sell personal data and do not share it for advertising.
Our staff. Administrators of this service can see account details and, for support and abuse handling, can sign in to an account to see what its owner sees. We limit this to people who need it.
Providers. Hosting is provided by Microsoft Azure. If email delivery is configured, transactional email such as password resets passes through our email provider. If you allow analytics, Google provides Google Analytics.
Retention and deletion
Submissions are kept until the form owner deletes them or deletes the form, which removes the associated answers and attachments too. Unfinished entries are removed automatically after 30 days.
You can start building a form before creating an account. What you build is then held against an anonymous guest session, identified only by the sign-in cookie, and is never published — publishing requires an account. If you create one, those forms become part of it. If you don't, guest work that nobody has returned to for 30 days is deleted automatically and cannot be recovered.
If a free account reaches the end of its free period, the data is not deleted: the owner keeps read-only access to the leads already collected and can still export them. Contact us to have an account and its data removed entirely.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to some processing. Account holders can contact us directly. Form respondents should contact the business that runs the form in the first instance, since that business decides what it collects and why.
Children
The service is not intended for children, and accounts are for businesses and creators. If a form you build is likely to be filled in by children, it is your responsibility to have whatever consent the law where you operate requires.
Changes to this policy
We may update this policy as the product changes. The date at the top shows the last revision; continuing to use the service after a change means you accept the updated policy.
Contact
Questions about privacy, or want your data removed? Contact MacroThread Software, Tel Aviv, Israel through our contact page.