Skip to content

Privacy and data retention

Promptless Forms stores what visitors submit, plus a few details about the submission itself. It connects to WordPress’s own privacy tools so you can export or erase one person’s submissions, and it keeps entries until you delete them.

  • Answering a request from someone to see or delete their data.
  • Writing your privacy policy.
  • Setting how long submissions are kept.

Each entry holds the answers, uploaded files, the date, the visitor’s IP address, their browser’s user agent and, if they were logged in, their WordPress user. See Entries.

Depending on how a form is set up, submissions also go to:

  • the notification email recipients, with uploaded files attached;
  • a webhook destination such as Google Sheets, Zapier or Make, with links to uploaded files;
  • Google, when a visitor types in an address field;
  • Twilio, for the text-back feature.

While a visitor fills in a form, their answers are kept in the browser tab (session storage), so a reload does not lose them. They are cleared when the submission succeeds or the tab is closed.

Forms adds suggested text to Settings → Privacy → Policy Guide, under Promptless Forms. It describes the stored data and the external services a form may use. Copy what applies into your policy.

Forms registers with WordPress’s personal data tools as Promptless Forms — Form Submissions.

  1. Go to Tools → Export Personal Data or Tools → Erase Personal Data.
  2. Add a request for the person’s email address and confirm it as usual.
  3. When the request runs, Forms finds every entry whose email-type field holds that address, ignoring case.

An export lists each entry’s form, date, answers, uploaded file names, IP address and user agent. An erase deletes those entries entirely, with their uploaded files.

Forms does not delete entries on its own; they stay until you remove them. To delete them automatically:

  • With FlowMint Workflows, create a scheduled workflow that finds old entries with the fre_list_entries step (it takes form_id and older_than_days) and removes them with fre_delete_entries.
  • By hand, filter Form Entries by form, tick the old entries and use Bulk actions → Delete. Export them first if you need a record.

The webhook delivery log, which holds each webhook’s response, is cleared of records older than 30 days every day.

  • Deleting the plugin keeps entries unless Remove all data when Promptless Forms is deleted is ticked under Settings; then entries, forms and uploaded files are removed permanently. Up to version 1.10.0, deleting the plugin always removed every entry and form.
  • Copies elsewhere are not erased. Emails, spreadsheets and records in other services keep their copies; delete them there.
  • File links stay valid while the file exists. Anyone with a link from an email or webhook can open the file until the entry is deleted.