Privacy Policy
Last updated September 17, 2026
This Privacy Policy explains how information is handled when people use Chimera Forms accounts, create or collaborate on forms, visit hosted forms, or submit responses. Chimera Forms is a standalone form, survey, registration, scheduling, and workflow platform.
In this policy, operator means the person or organization making this Chimera Forms service available. A form owner is the user or organization responsible for a form. A respondent is a person who submits information through a form.
1. Information associated with an account
Chimera Forms may store information needed to create and manage user accounts, such as a person's name, email address, password hash, account status, role, invitation status, profile settings, and security-related timestamps.
Passwords are not stored in plain text. Passwords are processed using a modern password-hashing algorithm so the original password is not recoverable from the stored hash.
2. Forms and form settings
Chimera Forms stores the information users create while building and managing forms. This can include questions, instructions, page structure, display logic, scheduling rules, quotas, capacity settings, styling, email triggers, collaborator permissions, hosted-page branding, published revisions, and related configuration.
3. Form responses
When someone submits a form, Chimera Forms stores the answers accepted by that form along with information needed to process and manage the submission. The exact content of a response depends on the questions and settings chosen by the form owner.
Form owners are responsible for deciding what their forms ask and why that information is being collected. If you are responding to a form, questions about the purpose of the form, the requested information, or how the organization plans to use your answers should generally be directed to the person or organization that published the form.
4. Form analytics
When a form owner enables Chimera Forms analytics, the platform may record anonymous form-usage information such as a form view, first interaction, pages reached or completed, questions reached or interacted with, validation errors, successful completion, published revision, hosted-versus-embedded presentation, coarse device and browser family, referrer domain, embedding origin, and UTM campaign values.
Core Chimera Forms analytics does not create a cross-site visitor profile, does not use an analytics cookie, and does not store a raw IP address in the analytics visit record. A random visit identifier exists only to connect events within one form visit. Form owners can pause collection, choose a retention period, or clear analytics history for their forms.
5. Technical and security information
Chimera Forms may process technical information needed to operate and protect the platform, such as timestamps, browser or user-agent information, request origins, rate-limit records, audit events, session information, and security-related identifiers or hashes.
This information is used for purposes such as authentication, abuse prevention, troubleshooting, audit history, protecting public submission endpoints, and maintaining the reliability of the service.
6. Cookies and browser storage
Chimera Forms uses session cookies to keep signed-in users authenticated and to support security controls. The browser may also store interface preferences, such as light or dark mode, so the application can remember how a user prefers to view it.
The core platform does not require third-party advertising cookies to provide its form-building and response-management features.
7. How information is used
Information handled by Chimera Forms may be used to:
- create and manage user accounts;
- build, publish, display, and process forms;
- store and present responses to authorized users;
- apply display logic, validation, scheduling, quotas, and capacity rules;
- send configured notifications, confirmations, and invitations;
- support collaboration and permissions;
- generate exports requested by authorized users;
- prevent abuse, investigate security events, and maintain audit records;
- maintain, troubleshoot, and improve the service.
8. Who can access information
Account and form information is available only to users whose roles and permissions allow that access. Form owners can grant collaborators different levels of access and are responsible for choosing appropriate permissions.
Response data may be visible to form owners and authorized collaborators. Administrators may have broader access when necessary to operate, secure, support, or maintain the service.
9. Sharing and disclosure
Chimera Forms does not sell form response data or use form responses for third-party targeted advertising.
Information may be disclosed when necessary to provide a feature requested by an authorized user, such as sending an email notification, or when disclosure is reasonably necessary to comply with law, protect the service, investigate abuse, enforce applicable terms, or protect the rights and safety of users or others.
If the operator connects Chimera Forms to third-party email, storage, analytics, authentication, or other services, those providers may process information according to their own agreements and privacy practices.
10. Email notifications and invitations
Chimera Forms may send messages related to account invitations, collaborator invitations, account activation, form submissions, confirmations, or other triggers configured by authorized users. These messages may contain form information or response data when a form owner intentionally configures them to do so.
Recipients should take care when forwarding messages that contain response information.
11. Hosted and embedded forms
A form may be presented on a Chimera Forms hosted page, shared through a QR code or direct link, or embedded on another website. The form owner controls the questions and much of the content and branding presented with the form.
When a form is embedded on another website, that website may have its own cookies, analytics, privacy policy, and data practices that are separate from Chimera Forms.
12. Exports
Authorized users can export response data in supported formats. Once an export is downloaded, emailed, copied, uploaded elsewhere, or otherwise removed from Chimera Forms, the person or organization handling that copy becomes responsible for protecting it.
13. Data retention
Retention needs vary by form, organization, and legal requirement. Form owners and administrators are responsible for establishing appropriate retention practices for the information they collect and control.
Some technical, security, audit, backup, or invitation records may be retained for a reasonable period when needed for service integrity, troubleshooting, abuse prevention, or recovery.
14. Security
Chimera Forms uses technical and organizational safeguards intended to reduce the risk of unauthorized access, alteration, disclosure, or loss. These safeguards include account authentication, role-based permissions, server-side validation, CSRF protection, session controls, rate limiting, audit records, and other protections appropriate to the feature being used.
No system can guarantee absolute security. Users should protect their credentials, assign collaborators carefully, avoid collecting unnecessary sensitive information, and report suspected security problems promptly.
15. Your account information
Signed-in users can update supported profile information through the Account area. If an organization manages your account or access, additional changes may need to be handled by an administrator.
16. Requests concerning form responses
If you want to ask about, correct, or request deletion of information you submitted through a particular form, contact the person or organization that published that form. The form owner is normally in the best position to understand why the information was collected and what retention obligations apply.
Requests involving your Chimera Forms account or operation of the platform itself should be directed to the operator of this service.
17. Children and younger users
Chimera Forms can be used by schools, educational programs, families, and organizations that may serve younger people. Form owners are responsible for determining whether they need parental consent, guardian permission, institutional approval, or other safeguards before collecting information from minors.
18. Changes to this policy
This policy may be updated as Chimera Forms gains features or as legal, security, or operational requirements change. The date at the top of this page will be updated when material revisions are made.
19. Privacy questions
Questions about a specific form or response should generally be directed to the person or organization that published the form. Questions about a Chimera Forms account or this service should be directed to the operator.