Privacy policy
Last updated 24 September 2026.
There are three different things here — this website, the free plugin running on your site, and Formsafe Pro — and they handle data very differently. Each has its own section.
1 · This website
- No cookies of ours, no analytics, no tracking. The site is static pages served by Cloudflare Pages, whose servers see your IP address the way any web host does.
- The tools on the guide pages run in your browser. Email headers, form templates and Contact Form 7 markup you paste into them are processed on your own device and are not sent anywhere.
- Buying Pro: pressing a buy button loads Paddle's checkout from cdn.paddle.com. Paddle is the merchant of record and processes your name, email address, billing address and payment details under its own privacy notice. We receive your email address, the country and the purchase — never your card details.
- After buying: the thank-you page sends the purchase's transaction id to our licence service to fetch your download link.
- Lost your download: that page sends the email address you type, and the product name, to our licence service. If the address matches a purchase, the service emails a fresh link to it.
- Emails you send us are kept so we can answer them and deal with follow-ups.
2 · The licence service
Our licence service runs on Cloudflare Workers. For each purchase it keeps the email address you paid with, the licence, the subscription's status from Paddle, and the installation ids of the sites that have used the licence. It uses them to send your download link, to deliver updates, and to answer your support questions. Records are kept while the subscription is active and for as long afterwards as accounting law requires.
3 · The free plugin, on your site
Formsafe Contact Form sends nothing to us — no usage data, no telemetry, no licence check.
- Entries stay in your site's database, in two tables of the plugin's own: what visitors typed, the page they sent it from, the time, and the mail status. You, as the site owner, are the controller of that data.
- IP addresses are not stored by default. The limit of five messages per address per ten minutes works on a hashed value that expires on its own.
- Notification emails go through your own site's mail setup,
wp_mail(), to the recipients you choose. - CAPTCHA — only if you switch one on. Cloudflare Turnstile, hCaptcha and Google reCAPTCHA v3 are all off by default. When one is on, visitors' browsers load its script from the provider (challenges.cloudflare.com, js.hcaptcha.com or www.google.com), and when a form is sent your server passes the visitor's answer, their IP address and your secret key to that provider to be checked. Those providers' own privacy terms then apply.
- Deleting: WordPress' own export and erase tools find entries by email address, and entries can delete themselves after a retention period you set. Deleting the plugin removes its data only if you've ticked the setting that says so.
4 · Formsafe Pro, on your site
To us, Pro sends only what licensing and updates need, from your server and never while a visitor loads a page. Every request carries, in its User-Agent header, the plugin's version and your site's address:
- when a licence is first used on a site: the licence key, the product name, the word wordpress as a label, and an installation id (a hash of a random value stored on your site);
- a licence check, at most once a week, during an admin page load: the licence key and the activation id;
- an update check, when WordPress looks for plugin updates: the product name, the installed version, the licence key and the installation id;
- the download of a new version, when you update;
- if you use the plugin's “Send the link” form on its License tab: the email address you type and the product name, so a fresh download link can be emailed to the address the licence was bought with.
Your entries never come to us. To the services you connect — Mailchimp, Brevo, Kit, MailerLite, ActiveCampaign, HubSpot or a webhook address you enter — Pro sends, from your server and with your own API key, the fields you've mapped for that form, or the whole entry for a webhook: after each entry, when a failed delivery is retried, and when you test the connection. What those services do with it is governed by your agreement with them. Alert emails about a broken connection go through your site's own mail setup to the address you choose.
5 · Your rights
You can ask what we hold about you, have it corrected or deleted, or object to how we use it, by emailing us. Where we're required to keep something — records of a sale, for example — we'll say so and why. You can also complain to your data protection authority; in Denmark that is Datatilsynet.
6 · Who is responsible
The controller for the data in sections 1, 2 and 4 is Lasse Feddersen, a sole trader. Contact: email us.