Information We Collect
We collect information you provide when creating forms, configuring destinations, contacting support, or submitting a form hosted by or routed through Webtzm.
- Account and contact details such as name, email address, and support messages.
- Form configuration details, field labels, output rules, quota settings, and destination metadata.
- Submission content sent by visitors, including text fields and file metadata. File uploads are routed to the configured Google Drive destination when enabled.
- Technical records such as request time, delivery status, usage counts, errors, and security checks needed to operate the service. When a submission is refused because its site is not on the allowed list, Webtzm keeps only that site's hostname, in a short list capped per form, so the owner can allow it — never any value from the refused submission.
Google Data
When you connect Google, Webtzm uses the permissions you grant only to provide the features you select. The core connection can append rows to Sheets, create Docs, write JSON or PDF files, and upload files to Drive. It uses narrow, incremental permissions and can access only files Webtzm creates or files you explicitly select — including a Sheet chosen through Google's own file picker, loaded from Google and run inside your own Google session, which grants nothing wider than this same drive.file scope.
Gmail sending is a separate, optional connection. If enabled, Webtzm uses the gmail.send permission to send transactional owner alerts, submitter receipts, and an optional full-record email output from your connected Gmail account. The full-record output is sent only to the recipient explicitly configured by the workspace owner and may contain the submitted form answers. Owner alerts and submitter receipts do not repeat submitted answers.
Webtzm does not use Gmail permission to read, list, modify, or delete messages. It cannot inspect your inbox or sent-mail history.
Google user data is not sold, used for advertising, or used to train general-purpose AI models. OAuth refresh tokens are encrypted and isolated to the connected workspace. You can disconnect Gmail sending independently from the core Google connection.
Webtzm's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI Assistants You Connect
You can connect an AI assistant, such as Claude, ChatGPT, or another client that supports the Model Context Protocol, to one workspace. You connect it either by signing in to Webtzm and approving it on a Webtzm page, or by creating an assistant key in Account › AI assistants and pasting it into the assistant.
A connected assistant can read the workspace’s forms and their settings, the embed code for each form, delivery status, and plan usage. If you choose “View and make changes”, it can also create forms, change their settings, and pause or resume them. It cannot read the contents of submissions, delete or archive forms, change billing, or connect or disconnect Google.
Webtzm stores the connection itself: the assistant’s name as it identified itself (or the name you gave a key), its access level, the workspace, and when it was created and last used. Tokens and keys are stored only as one-way hashes, so Webtzm cannot show one again. An access token expires after one hour, a sign-in connection ends after 30 days without use, and a key works until you revoke it. You can disconnect an assistant or revoke a key at any time in Account › AI assistants. Removing you from the workspace, deleting the workspace, or deleting your account also ends the assistant’s access.
Your assistant is run by another company. What you ask it, and what it receives from Webtzm, is processed by that company under its own terms and privacy policy. Webtzm sends your data to that company only as the answer to requests your assistant makes.
How We Protect Data
Webtzm maintains technical and organizational security procedures designed to protect the confidentiality and integrity of sensitive data, including Google user data and public form submissions.
- HTTPS encryption protects data while it travels between your browser, Webtzm, and Google APIs.
- Google OAuth refresh tokens are encrypted at rest with authenticated AES-GCM encryption. Encryption keys are stored separately from the token records, and short-lived Google access tokens are not persisted by default.
- Workspace membership and role checks restrict access to workspace data. Forms, submissions, Google connections, delivery records, and usage records are isolated by workspace.
- Webtzm requests Google permissions incrementally and uses the least-privilege permission needed for each selected feature. Gmail sending can be disconnected without disconnecting the core Google connection.
- Application logs and stored error messages are designed to exclude OAuth tokens, raw form answers, upload session URLs, and confidential Google response bodies.
No online service can eliminate every security risk. Webtzm reviews access controls and data-handling procedures as the service changes and updates this policy when its handling of Google user data materially changes.
Payments
Paid plan checkout and billing may be handled by Stripe. Webtzm does not store full card numbers. Stripe may process payment, billing, fraud prevention, tax, and compliance information according to its own services and policies.
Sharing
Webtzm sends Google user data to Google APIs only to create the outputs or Gmail messages selected by the workspace owner. Cloudflare hosts and protects the service and processes workspace data needed to deliver submissions. Stripe may process account and billing information for paid plans, but Webtzm does not send form submissions or Google user data to Stripe.
A workspace owner may enable Record Fetch on a workflow whose Sheet Webtzm created. When enabled, Webtzm reads that Sheet and returns only the columns the owner selected, to whoever presents a key the owner created. Webtzm does not decide who that is: a server key is held by the owner’s own systems, and a browser key is readable by every visitor of the page carrying it, which the console states before such a key can be created. Record Fetch is off by default, shares no column until one is selected, reads only Sheets Webtzm created, and never writes.
We do not share Google user data with advertisers or data brokers. We may disclose limited information when required by law, to investigate abuse or security incidents, or as part of a business transfer subject to appropriate confidentiality and data-protection safeguards.
Retention And Deletion
On the Free plan, Webtzm keeps submitted field values while delivery is pending or retrying, then redacts them when delivery succeeds or reaches a terminal failure. Pro workspace owners select a 7-, 30-, or 90-day retention period; the Pro default is 30 days. Webtzm clears Pro submitted values after that period, once delivery has finished or finally failed. Non-sensitive delivery, usage, and audit records may be retained to document service operation, enforce limits, investigate abuse, and meet legal obligations.
Webtzm does not store uploaded file bytes in its databases. Enabled uploads are sent to the Google Drive destination selected by the workspace owner, who controls the file's sharing and deletion in Google Drive.
Disconnecting a Google connection erases its saved token material from the workspace and stops future use. A signed-in user can request account deletion from the dashboard. The request immediately pauses owned workspaces and public form routes, revokes other sessions, and starts a 30-day recovery period. Recovering during that period restores the saved workspace and route states. Owner and manager-console accounts cannot use self-service deletion while they hold those protected operational roles.
After the recovery period, Webtzm deletes the account, memberships, owned workspaces, workspace forms, submissions, Google connection material, and delivery records. Stripe subscription renewal is stopped and the Stripe Customer is deleted when the request is made. Webtzm retains only a one-way hash of the Google account’s stable identifier to prevent repeat trials and founding offers; it contains neither the Google identifier nor the email address. Limited non-sensitive records may also be retained where required for legal, security, fraud-prevention, or settled-payment obligations.
Contact
Questions about this policy can be sent to support@webtzm.com.