How TypelessForm Handles Your Data

A
Alex IsaLead Maintainer · Webappski

TypelessForm processes voice in memory and stores no recordings on our infrastructure. Audio is transmitted over TLS 1.2+, transcribed by OpenAI's speech-to-text model, mapped to your form by GPT, and released as soon as the API returns the JSON. We are GDPR-compliant; SOC 2 is on our roadmap (not yet certified); HIPAA is out of scope. Operational logs are retained up to 30 days; billing records up to 5 years per Polish accounting law.

Who operates TypelessForm?

TypelessForm is operated by Webappski. For the full legal entity, billing entity and Data Processing Agreement, see our canonical DPA and Privacy Policy. All security, privacy and compliance enquiries: info@webappski.com.

What happens when a user speaks?

  1. The user grants microphone permission to the page hosting the widget. The browser captures audio locally.
  2. The browser streams audio over TLS 1.2+ to the TypelessForm API — a Google Cloud Function in the EU (region europe-central2).
  3. The API forwards the audio to OpenAI's speech-to-text model, then sends the resulting text and the descriptions of your form's fields to a GPT model that maps it to your HTML form fields. The values already in fields that are not marked data-ai-private go to our API with the request that fills the form; we do not store them and do not pass them to OpenAI.
  4. The API returns a structured JSON object containing the field values. The widget writes those values into the corresponding DOM inputs on your page.
  5. The API releases the memory holding the audio as soon as the JSON is returned. No persistent copy is written.

What data do we store?

Data classStored?Notes
Raw voice recordingsNoProcessed in memory, discarded as soon as the API returns the response.
Transcripts (text)No The transcript text lives in memory while the request runs, then goes to the language model for field mapping. Our application logs keep only metadata (audio duration, detected language, text length, field counts, timings), never the text. Those logs sit in Google Cloud Logging (location: global, no EU-only guarantee) with its default retention of 30 days, then are deleted. OpenAI's own 30-day copy of the requests and responses, which include the transcript, is described below.
Form field values (mapped output)No Returned to your page in the API response; never written to our database. OpenAI's own 30-day copy of the requests and responses, which include these values, is described below. Once they reach your form, those values fall under your own privacy policy.
API key + usage counters + registered domainsYes API keys are stored as one-way SHA-256 hashes; the plaintext value is shown to the operator only once at creation. Request counts, timestamps and the per-key allow-listed domains are kept for the lifetime of the API key to enforce plan limits and detect abuse. No request bodies are retained.
Account email + display name (for API key issuance)Yes Stored on the Webappski portal (the issuing system that operates TypelessForm) at webappski.com/en/portal. Used solely for authentication and service notices.
Billing & invoice recordsYes — 5 years Billing email, invoice data and subscription history are retained for 5 years per the Polish accounting and tax obligations (Ustawa o rachunkowości). Separate from operational logs.
Consent receiptsYes — up to 24 months Pseudonymous UUID, timestamp and a daily-rotating SHA-256(IP + date) hash — never raw IP — for GDPR Art. 7(1) proof of consent. Auto-deleted after 24 months.
Infrastructure security logsYes — 30 days Timestamps, HTTP status codes, request duration, User-Agent and infrastructure IPs (logged by Google Cloud) for network security and abuse detection. Webappski acts as an independent Controller for this scope under GDPR Art. 6(1)(f) (legitimate interests). Auto-deleted after 30 days.

Which fields does the widget refuse to fill by voice?

High-risk form fields are detected and are not filled by voice. Digits a person says aloud are not removed from the audio, which goes to our API and on to OpenAI for transcription, so card numbers and other secrets must be typed. The descriptions of the form's fields (name, type, label, placeholder and section headings; at fill time also the option values of select, radio and checkbox-group fields) also go to OpenAI. A value already in a field that is not marked data-ai-private goes to our API with the request that fills the form (see the opt-out attribute below). The widget refuses voice filling for the following fields, even when explicitly invoked:

  • Passwords (type="password")
  • Credit-card numbers (PAN and CVV)
  • Social-security numbers (SSN, NIN and equivalent national IDs)
  • One-time passwords (OTP, 2FA codes)
  • IBANs, passport numbers, driver-licence numbers and tax IDs
  • Hidden form fields (type="hidden")
  • File uploads (type="file")
  • CAPTCHA challenges
  • Special-category labels under GDPR Article 9 (medical records, health insurance, religious belief, political affiliation, trade-union membership) — flagged by a classifier model and a guardrail rule set, not by a list on your device; the classifier reads the field descriptions, so they go to OpenAI first. A field the classifier flags is not filled by voice. This detection materially reduces but does not eliminate Art. 9 risk; Controllers must mark domain-specific sensitive fields with the opt-out attribute below and obtain explicit Art. 9(2)(a) consent where applicable (per DPA §4.4).

These fields must be typed.

Free-text health fields (symptoms, conditions, medications) are not flagged by the classifier: mark them data-ai-private.

Controller opt-out attribute: add data-ai-private to any additional form field to keep it out of voice filling. A field marked data-ai-private is not filled by voice and is cut out of the request that fills the form. When the form is first read, the name, type, label, placeholder and section headings of every visible field (never a value a person has entered) still go to our API and to OpenAI to classify the form's fields; at fill time also the option values of select, radio and checkbox-group fields that are not marked data-ai-private (per DPA §4.3). Digits a person says aloud still stay in the audio. The value of any field of the same form that is not marked data-ai-private, the card or SSN field itself included, goes to our API with the request that fills the form, however it got there (typed, pasted or filled in by the browser); we do not store it and do not pass it to OpenAI (password fields and fields marked data-private="true" are cut out as well; hidden inputs are not read). Mark card-number and SSN fields data-ai-private to cut them out of that request.

How is data encrypted?

  • In transit: TLS 1.2+ on both legs — browser → TypelessForm API, and API → OpenAI. HSTS is enabled on typelessform.com; the API backend runs on Google Cloud Functions, which is HTTPS-only.
  • At rest: operational logs and account records are stored on managed infrastructure with disk-level encryption (Google Cloud Logging uses AES-256).
  • Audio at rest: not applicable — audio is not persisted.

Who are our sub-processors?

Sub-processors are third-party services Webappski uses to deliver TypelessForm. Google Cloud and Firebase work under Google's own data-processing terms (the Cloud Data Processing Addendum and the Firebase Data Processing and Security Terms, which Google incorporates into its service agreements); OpenAI and Stripe under their data-processing agreements. The contractual list, including Formspree, lives in our Data Processing Agreement; this table lists the services that handle data for TypelessForm, including the Firebase Hosting edge that serves the widget file.

Sub-processorPurposeData handledRegion — transfer mechanism
OpenAISpeech-to-text (gpt-4o-mini-transcribe) and field mapping (GPT) Voice audio (not kept by OpenAI), transcripts, form-field descriptions and filled values (requests and responses kept for up to 30 days for abuse monitoring) United States — EU→US transfer covered by Standard Contractual Clauses (SCCs)
Google Cloud PlatformWidget infrastructure (Cloud Functions, Cloud Logging, Firestore) Application logs (metadata only — no transcript text), infrastructure logs (IP, timestamps, error codes), client configs, consent receipts Cloud Functions and Firestore: European Union (europe-central2). Cloud Logging: Google's global location — no EU-only guarantee
Firebase Hosting (Google)The widget script file, the widget's fonts, and typelessform.com itself The visitor's IP address and User-Agent, processed at the serving edge of Google's global CDN Global edge network — no EU-only guarantee
Stripe, Inc.Subscription billing for site operatorsPayment method tokens, billing email, invoice dataEU / United States — SCCs + PCI DSS Level 1
FormspreeContact form processing on webappski.comName, email, message content submitted via the contact formUnited States — SCCs

OpenAI 30-day retention: audio is dropped from our infrastructure after the response is returned, and OpenAI does not keep it either: its published data-controls table lists no abuse-monitoring retention for the speech-to-text endpoint we use. The calls to its language model are different: OpenAI holds the text of their requests and responses for up to 30 days for its own abuse monitoring under their API policy (see OpenAI's data-controls guide). That text is the transcript, the descriptions of the form's fields and the filled values. We cannot have it deleted sooner. We do not store the audio, the transcripts or the filled values ourselves. OpenAI notes that it can keep this abuse-monitoring copy longer where the law requires it, or where that is reasonably necessary to protect its services or any third party from harm. Calls through our OpenAI client are sent with store: false, so OpenAI does not keep the call as application data. That does not switch off the 30-day abuse-monitoring copy of the requests and responses. Input and output sharing with OpenAI is disabled — your data is not used to train their models. That is not the same as Zero Data Retention (ZDR): ZDR is a separate status OpenAI grants on approval, and we do not hold it today. If an enterprise contract requires ZDR, we will file the application with OpenAI — the decision is theirs, not ours.

Sub-processor changes: 30 days' prior notice to B2B customers, with a 14-day objection window per DPA §5.4. Request the signed DPA at info@webappski.com, or read it directly at webappski.com/en/legal/dpa.

What compliance certifications does TypelessForm hold?

Current status:

  • GDPR: compliant. The widget is designed around data minimisation; voice is processed transiently, no recordings are stored on our infrastructure (OpenAI's own 30-day abuse-monitoring copy of the requests and responses is described above), and deletion and access controls are documented below.
  • Personal-data breach notification: we send B2B customers (Controllers) a preliminary notice within 24 hours of becoming aware of a confirmed personal-data breach, followed by detailed incident information within 48 hours (per DPA §5.6). Under GDPR Article 33, the Controller (you) is responsible for notifying the relevant supervisory authority within 72 hours; we provide the technical details required for that filing.
  • SOC 2: not yet certified. SOC 2 is on our roadmap; certification timing depends on audit-readiness milestones. Request our current security questionnaire at info@webappski.com. The report will be linked from this page when issued.
  • HIPAA: not in scope. TypelessForm is not marketed for protected-health-information (PHI) use cases and is not configured as a HIPAA Business Associate.
  • PCI DSS: not in scope if the card field sits in the frame of your payment provider. The widget is a script on your payment page: list it in your own script inventory (PCI DSS v4.0.1, requirements 6.4.3 and 11.6.1). The widget does not fill card fields and does not remove digits spoken aloud: card numbers are typed, never said aloud (see the fields above). The value of a card field marked data-ai-private is not sent: it is cut out of the request that fills the form. The value of any field of the same form that is not marked data-ai-private, the card-number field itself included, goes to our API with the request that fills the form, however it got there; we do not store it and do not pass it to OpenAI (password fields and fields marked data-private="true" are cut out as well; hidden inputs are not read). Put card fields in the frame of your payment provider, or mark them data-ai-private.

How do users and operators delete data?

  • End users: if you submitted form data to a site that uses TypelessForm and want it deleted, contact the operator of that site. We do not retain the form values; they live with the site that runs the widget.
  • Site operators: account, API-key and operational-log deletion can be requested from info@webappski.com. We complete deletion requests within 30 days.
  • Data Subject Access Request (DSAR): a DSAR lets data subjects request access to or deletion of personal data we hold. Portal account holders email info@webappski.com; we respond within the GDPR Art. 12(3) 30-day window. For DSARs forwarded by B2B Controllers, we provide processor assistance within 7 business days per DPA §5.5.

How do I report a security vulnerability?

Responsible disclosure is welcome. Email info@webappski.com with a clear reproduction path. We acknowledge within 7 business days (matching our DPA §5.5 inquiry response window) and will not pursue good-faith research that follows the OWASP Vulnerability Disclosure Cheat Sheet .

Frequently asked questions

Does TypelessForm store raw voice recordings?

On Webappski infrastructure: No. Audio exists only in memory while the transcription request runs and is never written to disk or logs. On OpenAI (our speech-to-text sub-processor): the audio is not kept, but the requests and responses of its language-model calls (the transcript, the descriptions of the form fields and the filled values) are held for up to 30 days (longer where the law requires it or to protect OpenAI’s services or any third party from harm) for abuse monitoring per OpenAI API policy, and we cannot have it deleted sooner. Calls through our OpenAI client are sent with store: false, so OpenAI does not keep the call as application data; that does not switch off the 30-day abuse-monitoring copy of the requests and responses described above. Input/output sharing is disabled, so your data does not train their models. Zero Data Retention is a separate status OpenAI grants on approval and we do not hold it today; if an enterprise contract requires it, we will file the application and OpenAI decides.

Is TypelessForm GDPR compliant?

Yes. TypelessForm is designed around GDPR data minimisation: voice is processed transiently on Webappski infrastructure (no recordings stored), DSAR access and deletion controls are provided, and infrastructure logs are kept 30 days. For personal-data breaches we send B2B Controllers a preliminary notice within 24 hours and detailed incident information within 48 hours (per DPA §5.6). Under GDPR Article 33, the Controller is responsible for notifying the supervisory authority within 72 hours; we provide the technical details required.

What encryption does TypelessForm use?

TLS 1.2+ on both legs: browser → TypelessForm API, and API → OpenAI. HSTS is enabled on typelessform.com; the API backend runs on Google Cloud Functions (EU, europe-central2), which is HTTPS-only. Operational logs and account records use disk-level encryption at rest (Google Cloud Logging uses AES-256). API keys are stored as one-way SHA-256 hashes.

Is TypelessForm SOC 2 certified?

Not yet. SOC 2 is on our roadmap; certification timing depends on audit-readiness milestones. Request our current security questionnaire at info@webappski.com. The report will be linked from this page when issued.

Can TypelessForm be used for HIPAA or protected-health-information workloads?

No. TypelessForm is not marketed for PHI use cases and is not configured as a HIPAA Business Associate.

Which fields does the TypelessForm widget refuse to fill by voice?

Passwords, credit-card numbers (PAN and CVV), social-security numbers and equivalent national IDs, one-time passwords and 2FA codes, IBANs, passport numbers, driver-licence numbers, tax IDs, hidden form fields, file uploads, CAPTCHA challenges, and GDPR Article 9 special-category labels (medical records, health insurance, religious belief, political affiliation, trade-union membership). The Article 9 detection (a classifier model and a guardrail rule set, which reads the field descriptions at OpenAI) is not exhaustive; Controllers can mark any additional field with the data-ai-private HTML attribute to keep it out of voice filling. A field the classifier flags is not filled by voice. A field marked data-ai-private is not filled by voice and is cut out of the request that fills the form; when the form is first read, the name, type, label, placeholder and section headings of every visible field (never a value a person has entered) still go to our API and to OpenAI to classify the form fields; at fill time also the option values of select, radio and checkbox-group fields that are not marked data-ai-private (per DPA §4.3). Free-text health fields (symptoms, conditions, medications) are not flagged by the classifier: mark them data-ai-private. Digits a person says aloud are not removed from the audio, which goes to our API and on to OpenAI for transcription, so card numbers and other secrets must be typed. The value of any field of the same form that is not marked data-ai-private, the card or SSN field itself included, goes to our API with the request that fills the form, however it got there (typed, pasted or filled in by the browser); we do not store it and do not pass it to OpenAI. Mark card-number and SSN fields data-ai-private to cut them out of that request.

Who are TypelessForm sub-processors?

OpenAI (speech-to-text on the gpt-4o-mini-transcribe model and GPT field mapping; US, EU→US transfer covered by Standard Contractual Clauses); Google Cloud Platform (Cloud Functions and Firestore in the EU region europe-central2; Cloud Logging in the global location of Google, with no EU-only guarantee); Firebase Hosting (Google; serves the widget script file, the fonts of the widget and typelessform.com itself; the IP address and User-Agent of the visitor are processed at the serving edge of the global Google CDN, with no EU-only guarantee); Stripe, Inc. (subscription billing; EU/US, SCCs and PCI DSS Level 1); Formspree (contact form on webappski.com; US, SCCs). Fonts are served from our own host, so the page makes no request to Google Fonts. Canonical list at https://webappski.com/en/legal/dpa.

How do I request data deletion from TypelessForm?

Portal account holders email info@webappski.com from the address tied to their API key; we respond within the GDPR Art. 12(3) 30-day window. For DSARs forwarded by B2B Controllers, we provide processor assistance within 7 business days per DPA §5.5. Billing/invoice records may be retained 5 years per Polish accounting law (separate from operational logs).

How do I report a security vulnerability in TypelessForm?

Email info@webappski.com with a clear reproduction path. We acknowledge within 7 business days (matching our DPA §5.5 inquiry response window) and follow the OWASP Vulnerability Disclosure Cheat Sheet.

Last reviewed: .