Data processing
Last checked: 2026-09-25. This page explains where your visitors' form data goes when Formsieve checks a submission with a Formsieve key, who receives it, and what is kept. It summarises public terms we read on that date; providers can change their terms, so follow the links for the current versions. This is information, not legal advice.
Who does what
- You (the site owner) are the controller of your visitors' data. You decide to screen submissions and need a lawful basis for it; for most sites that is a legitimate interest in keeping spam out (Privacy kit).
- Thinking42, Inc. runs Formsieve's check service and is your processor, under the Formsieve Data Processing Agreement (https://formsieve.com/dpa/), which you accept in the set-up wizard. If you are an agency running a client's site, you are the processor and Thinking42 your sub-processor (standard contractual clauses Module 3).
- Thinking42's sub-processors carry the data on its behalf. The current list is at https://formsieve.com/subprocessors/, and we give 30 days' notice before adding one.
The path of a submission
Your WordPress site → Cloudflare, Inc. (network and encrypted tunnel; it decrypts HTTPS at its edge, so the data passes through it in plaintext) → Thinking42, Inc. on Amazon Web Services (EC2, us-east-1, Virginia) → OpenRouter, Inc. (AI gateway) → TypeSafe AI, Inc. (runs the Jev model). All of them are in the United States. No part of this path offers processing in the EU as of 2026-09-25.
Only submissions that pass the plugin's local filters take this path. The filters run on your server and send nothing.
What is sent, and what is never sent
Sent, after an administrator has entered a key and given consent: the ordinary text and choice fields of the submission with their labels (phone numbers redacted by default; each value capped), the domain of the sender's e-mail address (you can switch it off), your site name and address, the site and form descriptions you write, the site languages, and numeric signals such as the number of links and the seconds from page load to submit. The request also carries your Formsieve key and the plugin version.
Never sent: IP addresses, user agents, full e-mail addresses, passwords, payment and card fields, uploads, hidden, consent and CAPTCHA fields, and fields that look like health, ID or bank data. Details: How it works.
The site address goes to Thinking42 only, to count your sites. It is not sent to OpenRouter or TypeSafe.
What Thinking42 keeps
- The content of submissions: nothing. It is processed in memory for the one request and never written to a database, log, cache or disk.
- Request records, for 30 days: time, request ID, key and site identifiers, plugin and version, status, latency, the model version and cost reported by OpenRouter, and the spam band of the result. No field values, e-mail domains or descriptions.
- After 30 days: daily totals per key and site (checks, errors, latency), kept 25 months for billing questions and your account's usage charts.
- No sharing between customers: Thinking42 does not reuse one customer's results for another, and does not train AI models on submissions.
OpenRouter
- Company: OpenRouter, Inc., New York, USA. Hosting: Google Cloud Platform, US regions.
- What Formsieve's service asks for on every request: zero-data-retention endpoints only, no data collection, TypeSafe as the only provider, and no fallback to other models. Thinking42 keeps logging and "use of inputs" switched off on its OpenRouter account. Each request also carries a pseudonymous identifier of your Formsieve account (a keyed hash, never visitor data), so that a provider's action against one customer does not affect the others.
- Retention: OpenRouter's data processing agreement (last updated 2026-08-26) says it deletes inputs and outputs promptly after generating the output unless logging is switched on. OpenRouter lists TypeSafe's Jev endpoint as not retaining prompts and as zero-data-retention.
- Training: OpenRouter states it does not use inputs or outputs for training (unless a customer opts in to its discount programme; Thinking42 does not); TypeSafe's endpoint is marked as not training.
- Links: Terms https://openrouter.ai/terms · Privacy policy https://openrouter.ai/privacy · DPA https://openrouter.ai/data-processing-agreement
TypeSafe AI
- Company: TypeSafe AI, Inc., San Francisco, California, USA. Hosting: AWS (us-west-2), with GPU providers Modal, Nebius and CoreWeave, per its sub-processor list at https://trust.typesafe.ai/subprocessors.
- Retention: TypeSafe's customer agreement keeps customer data "as long as necessary" for its purpose, with no fixed period, and allows TypeSafe to derive technical telemetry and monitor abuse without a time limit. Zero data retention is offered to enterprise customers.
- Training: TypeSafe states that it does not train or fine-tune models on customer data without consent.
- Links: Terms https://typesafe.ai/legal/mca · Privacy policy https://typesafe.ai/legal/privacy-policy · DPA https://typesafe.ai/legal/data-processing
Transfers out of the EU, UK and Switzerland
All processing is in the United States. Thinking42 is not certified under the EU-U.S. Data Privacy Framework, so the Formsieve DPA includes the EU standard contractual clauses (Module 2, or Module 3 for agencies), the UK Addendum and the Swiss amendments. As of 2026-09-25, Cloudflare and Amazon (for AWS) were certified under the Data Privacy Framework; OpenRouter and TypeSafe were not found on its list.
What we do not claim
Formsieve gives you data minimisation, consent, a visitor notice, privacy-policy text, export and erasure, log retention and a DPA. It does not make a site "GDPR compliant" by itself, it does not keep data in the EU, and "zero data retention" does not describe the whole path: Thinking42 keeps request records without content for 30 days, and TypeSafe's own retention is described above.
What is known, and what is not
As of 2026-09-28, TypeSafe's and OpenRouter's public pages say:
- Training: TypeSafe states that it does not train or fine-tune models on customer data (its customer agreement §4.1 and its privacy policy). OpenRouter states that it does not use inputs or outputs for training.
- Retention on OpenRouter: OpenRouter lists TypeSafe's Jev endpoint as zero data retention and as not retaining prompts. This is TypeSafe's policy as TypeSafe represents it to OpenRouter; OpenRouter does not guarantee a provider's compliance (OpenRouter DPA §2.4(b)).
- Data Privacy Framework: neither TypeSafe nor OpenRouter is on the Data Privacy Framework list.
Not confirmed in writing: how long TypeSafe itself keeps API inputs (it publishes no fixed period), and what the technical telemetry it may derive from requests contains. This page will be updated, with the date, if either company publishes or confirms more.