Privacy policy
Effective September 29, 2026. Doorman (“we”, “us”).
The short version
- We screen form submissions for our customers and forward the real ones. For those submissions, the website owner is in charge and we act on their instructions.
- Each submission is sent to Jev (TypeSafe) only to be judged. We don't use submissions to train models, and we don't sell personal data.
- We keep submissions for 30 days on Free, 180 days on Pro and 365 days on Business, then delete them automatically.
- You can export or delete your account and everything in it from Settings at any time.
1. Who is responsible for what
Account data. When you sign up, we decide how your account information is used, so we are the controller of it.
Form submissions. When a visitor submits a form on a customer's website that uses Doorman, the customer decides why that data is collected. The customer is the controller; we are their processor (service provider) and handle submissions only to provide the service. If you submitted a form on someone else's website, please contact that website's owner about your data; we will help them respond.
2. What we collect
From customers
- Account: email address, a hashed password, your plan, and billing identifiers from Stripe (we never see or store full card numbers).
- Configuration: your forms' names, business descriptions, destinations (emails, Slack and webhook URLs), thresholds and allow/block lists.
- API keys and sessions: stored only as hashes.
- Usage and events: monthly check counts and product events such as sign-ups, logins, plan changes and labels, used to run and improve the service.
From form submissions (on behalf of customers)
- The fields the form sent (for example name, email, message and other fields), clipped to fixed lengths. File uploads are ignored and not stored.
- The sender's IP address and, where our network provider supplies it, their country.
- Signals such as time on page, whether JavaScript ran and whether a hidden honeypot field was filled; for checkout forms, the order and payment signals the customer chooses to send.
- Doorman's decision (route, probability, reason and evidence sentence), any label a person gives it, and the delivery log.
From visitors to this website
- Standard server logs (IP address, pages requested, browser) kept for security and debugging for up to 30 days.
- Text you type into the “try it” box on the home page is sent to Jev to be judged and is not stored.
3. How we use it
- To provide the service: judge submissions, forward them to the destinations you set, show them in your dashboard and let you rescue or label them.
- To send service emails: welcome and “set a password” links, password resets, usage warnings and forwarded submissions.
- To bill you through Stripe and handle plan changes.
- To keep the service secure and working: rate limiting, abuse prevention, debugging and alerting.
Legal bases (where GDPR/UK GDPR applies): performance of our contract with you for account data; our legitimate interests in securing and improving the service; and, for submissions, the customer's instructions under our data processing terms.
No training, no selling. Submissions are sent to Jev only to be judged. We don't use them to train or fine-tune models, and we don't sell or rent personal data or use it for advertising.
Automated decisions. Doorman makes automated recommendations about whether a submission is genuine. Customers can review every held and dropped submission and deliver it with one click. These are recommendations to the customer, not decisions about you: the customer who runs the form decides what happens to each submission and can deliver any held or dropped one. If you think a message of yours was wrongly kept out, contact the website's owner.
4. Who we share it with
We use a small number of subprocessors to run Doorman. Each receives only what it needs.
| Subprocessor | Purpose | Data |
|---|---|---|
| TypeSafe (Jev) | Judging each submission | Submission text, signals and the form's business description |
| Resend | Sending email | Recipient address and email content, including forwarded submissions |
| Stripe | Billing | Account email, plan and payment details (entered directly with Stripe) |
| Fly.io | Servers, database and network | All service data, stored in the United States (San Jose, California) |
| Migadu | Our own mailbox | Emails you send to hello@withdoorman.com and our replies |
| Google Fonts | Serving fonts on this website | Visitors' IP address and browser details |
Submissions also go wherever the customer points them (their email, Slack workspace or webhook). We may disclose data if required by law, or to protect the rights and safety of users and the service. If Doorman is acquired or merged, data may transfer to the new owner under this policy. We will give customers 30 days' notice of new subprocessors by email and on this page.
5. How long we keep it
| Data | Kept for |
|---|---|
| Submissions, Free plan | 30 days |
| Submissions, Pro plan | 180 days |
| Submissions, Business plan | 365 days |
| Account, forms and keys | Until you delete the account |
| Login sessions | 30 days |
| Password reset links | 1 hour (7 days for the first “set a password” link) |
| Product event logs | About 400 days |
| Backups | Up to 14 days |
| Billing records | As long as tax law requires, up to 7 years |
Submissions older than the plan's period are deleted automatically. Moving to a plan with a shorter period deletes older submissions. Deleting your account removes its forms, keys and all submissions immediately (backups roll off within 14 days).
6. Cookies and local storage
dm_session: an HttpOnly cookie that keeps you logged in to the dashboard (30 days). Strictly necessary.doorman-theme: your light/dark preference, kept in your browser's local storage. Never sent to us.
We don't use advertising or third-party analytics cookies. The optional form script (d.js) sets no cookies; it adds a page-load timestamp and a hidden honeypot field to the form.
7. Security
Passwords are hashed with scrypt; API keys and session tokens are stored only as hashes. Traffic is encrypted in transit with HTTPS. Webhooks are signed so you can verify they came from us. Access to production data is limited to the people who run Doorman. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay and within 72 hours where required.
8. International transfers
We and our subprocessors process data in the United States. Where data leaves the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the UK Addendum.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, export or restrict the use of your personal data, and to object to some uses. Customers can export everything we hold about their account as JSON, and delete the account, from Settings in the dashboard. For anything else, email hello@withdoorman.com. You can also complain to your local data protection authority.
If you submitted a form on a website that uses Doorman, contact that website's owner first: they control that data. We will forward requests we receive to them.
10. Children
Doorman is a business tool and isn't directed at children under 16. We don't knowingly collect their data as a controller.
11. Changes
We will post changes here and update the effective date. For material changes we will email account holders at least 30 days in advance.
12. Contact
Doorman. Email: hello@withdoorman.com.