Cookie Policy

This page explains which cookies SimplyForms uses, why we use them, and how you can manage them.

Effective date: May 28, 2026

Last updated: June 25, 2026

1. Introduction

Cookies are small text files stored on your device when you visit a website. SimplyForms uses cookies in a narrow, developer-friendly way: to keep the Service secure, maintain your authenticated session, and remember which team and workspace you are working in.

This policy describes cookies set when you visit simplyforms.dev. Our separate staff admin application runs on a different host, is not accessible to customers, and is covered by an internal staff notice — its cookies are never set on customer browsers.

We do not use advertising, marketing, or session-replay cookies. Our site analytics is cookieless and writes nothing to your device (see section 6). If we ever introduce a tool that sets a non-essential cookie or similar storage, we will introduce consent gating before it is set.

2. Our PECR Basis

Under the UK Privacy and Electronic Communications Regulations 2003 (PECR) and equivalent EU rules, cookies and similar storage that are strictly necessary to provide a service the user has requested do not require opt-in consent. We organise our storage into two groups:

  • Strictly necessary cookies— authentication, password-recovery, step-up reauth, active-team and active-workspace context, billing fraud prevention (Stripe), and bot protection (Cloudflare Turnstile). Without these the signed-in Service cannot function.
  • Preferences and similar storage— a small number of user-initiated preference flags (such as dismissing the cookie-notice banner or the welcome banner, and remembering your chosen column layout for the submissions table). Each of these is set only after a direct user action(clicking the dismiss button, or changing a column setting). That action is your choice to enable the preference, and serves as your consent for that storage. These items are minimal, do not perform tracking or profiling, and are not shared with third parties. You can reverse the choice at any time by clearing browser storage as described in section 7; if you contact us at the address in section 9 we will help you identify how to clear or avoid the relevant preference storage in your browser.

We do not rely on “legitimate interests” for any cookie — PECR does not recognise that as a basis for cookies.

3. Strictly Necessary Cookies

NameProviderPurposeDuration
sb-<project-ref>-auth-tokenSupabaseKeeps you signed in and allows authenticated dashboard requests to succeed. Without this cookie you cannot use the Service while signed in. May be split into multiple chunks for large sessions.Up to 400 days from the latest refresh
sf-stateSimplyFormsPublic hint (out / partial / full) read before page paint so the auth-aware navigation renders correctly on first load. Required to avoid a flash of signed-out chrome for signed-in users.30 days
sf-authSimplyFormsLegacy auth-state hint, retained read-only as a fallback for cookies issued before the sf-state migration. We no longer set this cookie; any remaining values expire naturally within 30 days of their last write.30 days (legacy)
sf-recent-authSimplyFormsHMAC-signed token issued after you re-enter your password. Authorises sensitive account actions (password change, email change, MFA disable) within a short window so you do not have to re-enter your password for every step.15 minutes
sf_pwd_recoverySimplyFormsSignals that a password-recovery flow is in progress so the UI guides you to set a new password.15 minutes
pending_invite_tokenSimplyFormsCarries a team-invitation token across the sign-up step so you land in the right team after creating an account.30 minutes
active_team_idSimplyFormsRemembers the team you are working in across dashboard requests. The multi-team dashboard you have signed in to use cannot function without this state — switching teams is part of the Service you have requested.365 days
active_workspace_idSimplyFormsRemembers the workspace you are working in across dashboard requests. Same essential role as the active team cookie.365 days

4. Preferences & Similar Storage

These items remember preference choices you have actively made. They sit on your device, do not track you across sites, and are not used for analytics, advertising, or profiling. We list browser storage alongside the one preference cookie because the ICO treats “cookies and similar technologies” together.

NameProviderPurposeDuration
sf_cookie_noticeSimplyFormsCookie. Remembers that you dismissed the cookie-notice banner so it stops appearing on every visit.365 days
sf-welcome-dismissedSimplyFormslocalStorage. Remembers that you dismissed the first-run welcome banner on the dashboard. Device-local; not transmitted to our servers.Until you clear browser storage
Form submissions table column preferencesSimplyFormslocalStorage. Remembers your chosen column layout for the form submissions table. Device-local; not transmitted to our servers.Until you clear browser storage

Clearing your browser storage will reset these preferences. We also use a short sessionStorage entry to rate-limit feedback submissions within a single tab session; it is discarded when the tab closes.

5. Third-Party Cookies

Some essential cookie activity is handled by third-party providers we use to operate SimplyForms:

NameProviderPurposeDuration
__stripe_midStripePersistent fraud-prevention identifier set by Stripe during embedded checkout to detect fraudulent payment activity.1 year
__stripe_sidStripeSession-scoped fraud-prevention identifier set by Stripe during embedded checkout.30 minutes
Cloudflare Turnstile challenge stateCloudflareHelps distinguish legitimate visitors from bots on protected auth, recovery, and form flows. Identifiers may vary based on Cloudflare risk checks.Session / varies

A note on customer forms.SimplyForms customers can choose a CAPTCHA provider — Cloudflare Turnstile, Google reCAPTCHA, hCaptcha, or Friendly Captcha — for forms they embed on their ownwebsites. Google reCAPTCHA and hCaptcha may set their own cookies on the customer’s site (not on simplyforms.dev); the customer is responsible for disclosing those on their site. Friendly Captcha is cookieless. On SimplyForms-hosted form pages (at simplyforms.dev/f/…) the only CAPTCHA used is Cloudflare Turnstile, already covered in the table above — no other CAPTCHA provider runs on simplyforms.dev.

6. Privacy-Focused Analytics

On our public marketing site we use Umami, a privacy-focused, cookieless analytics tool. Umami helps us understand how the marketing site is used — which pages are visited, where visitors arrive from, and roughly which browsers and devices are common — so we can fix broken navigation and decide what to improve.

It does not write anything to your device.Umami sets no cookies and uses no localStorage or sessionStorage, so there is no persistent identifier and no way to track you. It collects only aggregate measurements: page views, referring URLs, anonymised browser, operating system and device type, and the country your request comes from (derived from your IP address at the moment of the request and then discarded — we do not store your IP address for analytics). It performs no cross-site tracking, builds no profiles of individuals, and is never used for advertising.

Analytics runs on our public marketing pages only. We do not load it inside the signed-in application.

Why we do not ask for consent:PECR requires consent to store information on, or read information from, your device. Because Umami stores nothing on your device and reads nothing from it — which we have verified — the consent requirement for cookies and similar storage does not apply. We describe it here for transparency. We continue to use no advertising cookies, marketing pixels, fingerprinting, or session replay, and if we ever add a tool that does set non-essential storage, we will introduce category-based consent before it loads.

7. How to Manage Cookies

Most browsers let you view, block, or delete cookies through their privacy or security settings. You can usually find these options in your browser’s settings menu under labels such as Cookies, Site Data, or Privacy.

If you block strictly necessary cookies, parts of SimplyForms may stop working as expected, including signing in, staying signed in, switching workspaces, and completing protected forms.

8. Updates to This Policy

We may update this Cookie Policy from time to time to reflect changes in our Service, legal requirements, or the third-party services we use. Updates are posted here with a revised “Last updated” date. For changes that introduce non-essential cookies, consent will be requested before the cookie is set.

9. Contact

Questions about this Cookie Policy? privacy@simplyforms.dev for privacy questions, or support@simplyforms.dev for general support. The full sub-processor list is published at /legal/subprocessors.