Last updated: 3 June 2026
Privacy Policy
TakumiForm is a layer that sits on top of Google Forms™. We care a lot about what we touch, because most of the data flowing through us is owned by you and lives in your Google account. This page explains exactly what we do with it.
The short version
- Your form responses live in your Google Sheet. That's the source of truth.
- We keep a copy in our database so the in-product analytics are fast.
- We never sell your data and we don't show ads.
- You can export or delete everything we have on you. Email us and we'll do it inside 30 days.
What we collect
Account information
When you sign in with Google, we receive your email address, name, and profile picture. We store these so we know who you are when you come back.
Form structure
Once you connect a Google Form, the TakumiForm add-on inside Google Forms sends us its structure (questions, options, logic) for the single form you have open, and we store a cached copy in our database. This is what lets us render your form on your own website instead of inside an iframe. The takumiform.com website itself holds no Google scope that can read your forms — the structure only ever reaches us through the add-on you install.
Form responses
Submissions made through a TakumiForm embed are written to two places: the Google Sheet linked to your Form (so nothing changes from Google's perspective), and our own database (so we can show you analytics, search, and the response inbox quickly). If you cancel your subscription, your Sheet still has every response — you are never locked out of your own data.
File uploads
Files uploaded through your forms are stored securely with our cloud storage provider. The download link is written into the matching cell of your Sheet so you can retrieve files even without logging into TakumiForm.
Payment information
If you take payments, the card details are handled by Stripe directly. We never see or store card numbers — only the transaction reference and amount.
Usage data
Standard web server logs: IP address, user agent, requested URL, timestamp. We keep these for 30 days for debugging and abuse prevention.
How we use it
- To run the product (sign you in, render your form, store responses).
- To show analytics and reports inside the dashboard.
- To send you product emails about your account (billing, security, downtime). We will not send you marketing emails without your consent.
- To investigate abuse and protect the service.
Who we share it with
The third parties that handle your data because they're part of how the product works:
- Google — sign-in only. The takumiform.com website asks for your name and email (standard OIDC scopes) and nothing else. The structure of your form reaches us only through the TakumiForm add-on you install inside Google Forms, which has access to the single form you have open (per-document scope) and no other forms, files, or Sheets.
- Our cloud hosting and storage providers — run the application and store data, file uploads, and backups on our behalf.
- Stripe — payment processing, only if you take payments.
- Microsoft Clarity — heatmaps and session replay on the marketing website (not inside the app). Uses cookies. You can opt out by blocking
clarity.msin your browser.
We don't sell your data, share it with advertisers, or use it to train machine-learning models.
How we protect your data
We treat the data you trust us with — including any sensitive data such as Google user data, form responses, and uploaded files — as something to guard, not just store. The mechanisms in place:
- Encryption in transit. All traffic to and from TakumiForm runs over HTTPS/TLS.
- Encryption at rest. Sensitive data such as access tokens and other secrets is encrypted at rest using strong, industry-standard encryption, and our backups are encrypted at rest as well.
- Access controls. Access to production systems and data is restricted to the people who operate the service, each authenticated individually. We do not browse your form responses; access happens only when you ask us for support or when we're investigating a specific abuse or reliability issue.
- Least privilege on Google data. The takumiform.com website signs you in with the minimum OpenID Connect scopes (name and email) and holds no scopes that can read your Forms, Drive, or Sheets. Your form structure reaches us only through the add-on you install inside Google Forms, which is limited to the single document you have open. We request the narrowest access that makes the product work.
- Isolation and retention limits. Each customer's forms and responses are scoped to their account, and we delete data on the schedule described below rather than keeping it indefinitely.
No system is perfectly secure, but if we ever discover a breach affecting your data, we'll notify affected account holders and the relevant authorities as required by law.
Google user data & Limited Use
TakumiForm's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, the Google user data we access is used only to provide and improve the features you've asked for, is never sold, is never used for advertising, and is never used to train generalized AI or machine-learning models. Humans don't read your Google user data except where you give explicit consent, where it's needed for security or to comply with the law, or where the data has been aggregated and anonymized.
How long we keep it
- Account data — as long as you have an account, plus 30 days after deletion.
- Form responses — as long as you keep the form connected, plus 30 days. The Google Sheet copy is governed by your own Google account settings.
- File uploads — same as responses.
- Server logs — 30 days.
- Backups — retained for up to 90 days, then rotated out.
Your rights
Whichever country you're in, you can:
- Ask us what data we hold on you.
- Ask us to correct it.
- Ask us to delete it (we'll honour this unless we have a legal reason to keep it, like billing records).
- Ask for a copy of it in a portable format.
- Withdraw any consent you've given.
EU/UK residents — these are your GDPR rights. California residents — these are your CCPA rights. To exercise any of them, email [email protected]. We'll respond within 30 days.
Cookies
We use cookies for two things: keeping you signed in (essential, can't be turned off without breaking the app), and Microsoft Clarity on the marketing site (analytics, opt-out described above). We do not use advertising cookies.
Children
TakumiForm is not aimed at children under 13. If you believe a child has created an account, email us and we'll remove it.
Changes
If we update this policy, we'll change the date at the top and tell account holders by email at least 7 days before material changes take effect.
Contact
Privacy questions, deletion requests, or anything else: [email protected].