Security at PulseFormCreator
Last updated: 17 September 2026
PulseFormCreator stores form and survey content and respondent answers on your behalf. This page explains how we protect that data and what we do not claim.
§1 Encryption
Data is encrypted in transit and at rest. In transit: TLS 1.2 or higher on every endpoint. At rest: AES-256 encryption by our infrastructure providers (PulseFormCreator's managed Supabase Postgres database for survey and response data; Cloudflare R2 for uploaded files).
§2 Access control
Access to production data is scoped per-account via row-level security (RLS) in Postgres. Only the survey owner can read their own surveys and responses. PulseFormCreator staff access is logged and only used to investigate reported incidents.
§3 Authentication
Magic-link email authentication via Supabase Auth. No password to leak. No third-party social login at launch.
§4 Backups
Daily automated database backups retained for 7 days. Point-in-time recovery available for 24 hours. Disaster recovery testing reviewed quarterly.
§5 Hosting and data residency
App servers: Vercel, in Vercel's Sydney region. Survey and response data: PulseFormCreator's managed Supabase (Postgres) database. Uploaded files: Cloudflare R2. All of it is encrypted in transit and at rest. Some processors may store data outside Australia, for example in the US or EU. See privacy policy §8.
§6 Respondent IP addresses
Raw respondent IPs are not stored. We store a one-way hashed IP for abuse and duplicate detection only. When a survey has anonymous responses turned on, not even the hash is stored, and neither is the respondent's browser or device information.
§7 Third-party processors
We use Supabase (database), Vercel (hosting), Cloudflare R2 (file storage), SendGrid (email), OpenAI (AI builder only, see the AI data policy), and Stripe (billing for paid plans). Each has its own security posture, all under contractual data-processing agreements.
§8 Responsible disclosure
If you believe you've found a security issue, please report it via the in-product feedback channel marked SECURITY. We aim to acknowledge reports within 5 business days. We will not pursue legal action against good-faith researchers who follow standard responsible-disclosure practice.
§9 What we don't claim
PulseFormCreator is not SOC 2, ISO 27001, HIPAA or PCI-DSS certified. If your use case requires one of those certifications, PulseFormCreator is not the right product for it.