Skip to content

Privacy policy

Last updated: October 10, 2026

PostCatch ("we", "us") is a form backend service operated by millisecond.studio in Montreal, Canada. This policy explains what data we handle and why, for the two kinds of people who interact with PostCatch: form owners, who create forms and receive submissions, and form submitters, the visitors who fill out a form on a site that uses PostCatch.

Data we collect from form owners

  • Account details. Your email address. There is no password: we email you a one-time login link, and your forms only start delivering once you have used one.
  • Form configuration. The form's name, allowed domains and spam filtering settings. Submissions are delivered to your account's email address.

What happens to a form submission

When a visitor submits a form that points at PostCatch:

  • We store the submitted fields in our database, attached to the form, along with a delivery status (delivered, blocked as spam, or held until the owner verifies their email). The form owner can review them in their dashboard.
  • We email the submission to the form owner at their account's email address. If the submission includes an email field, it is set as the reply-to address so the owner can respond directly.
  • File attachments are emailed, not stored. Files uploaded through a form are forwarded to the form owner as email attachments only. We keep a record of the file names, never the file contents.
  • Hidden control fields (names starting with _, such as the _next redirect) only steer behavior; they are neither stored nor emailed.

Stored submissions exist so form owners can review what was delivered and what was blocked. We do not read, mine, or use submission contents for anything else.

Spam filtering

Submissions pass through layered spam checks:

  • Request analysis. We inspect the request's user agent to reject known bots outright.
  • Honeypot field (optional). A hidden field only automated form fillers complete; its value is never stored.
  • AI content classification (optional, per form). The submitted field contents are sent to an AI provider (currently Cloudflare Workers AI) which returns a single spam category and nothing else. The content is processed under the provider's commercial API terms, solely to produce that classification.

Submissions blocked as spam are stored with the reason so form owners can spot false positives. The checks fail open: if a check errors out, the submission is delivered rather than lost.

Data collected automatically

Standard server logs (IP address, user agent, timestamps) are kept for security, debugging, and abuse prevention. We do not build visitor profiles and we do not use any data for advertising.

Cookies, storage and analytics

The site sets no cookies and runs no analytics or advertising. Logging into the dashboard stores a session token in your browser's local storage, strictly to keep you logged in. That's it.

Service providers

We share data only with the providers needed to run the service: email delivery (submission notifications and account emails) and AI spam classification when enabled (submission contents only). We do not sell, rent, or trade personal data. We may disclose data when required by law.

Data retention and deletion

  • Stored submissions remain until the form owner deletes the form or their account; both permanently delete the form's submissions.
  • Deleting your account permanently deletes your forms and all of their stored submissions.
  • If you submitted a form on someone else's site and want that data removed, contact the owner of that site, or email us and we will help.

Data security

We use commercially reasonable measures to protect the data we hold, but no method of transmission or storage is 100% secure.

Changes to this policy

We may update this policy from time to time. Changes are posted on this page with an updated date above.

Contact us

Questions about this policy? Email [email protected].