Cookie notice

What cookies and similar technologies we use on the marketing site and in the FormTo app, and how you can control them.

Last updated: April 6, 2026

What are cookies?

Cookies are small text files stored on your device by a website you visit. We also use similar technologies (such as localStorage or session storage) where described below. This notice should be read together with our Privacy policy.

Marketing website (this site)

Our public marketing pages may set strictly necessary cookies required for basic functionality (for example preferences you choose on the site, or load balancing where used by our host). We may add analytics cookies to understand aggregate traffic; if we do, we will update the table below and, where required, ask for your consent before non-essential cookies run.

FormTo dashboard (app)

When you sign in to the dashboard, our authentication provider (Clerk) and our application set cookies (or use equivalent storage) needed to keep you logged in, protect against abuse, and maintain session security. These are generally strictly necessary for the product to work.

Specific cookies we use

The table below lists the specific cookies and storage keys currently in use. Cookie names and lifetimes can change with platform updates; use your browser's developer tools to inspect the current state.

NameTypeProviderDurationPurposeCategory
__clerk_db_jwt1st partyClerkSessionAuthentication session token for the FormTo dashboardStrictly necessary
__session1st partyClerk / FormToSessionMaintains the logged-in session across page navigationsStrictly necessary
__client_uat1st partyClerk1 yearCross-tab authentication synchronizationStrictly necessary
_vercel_no_cookie1st partyVercel1 yearDeployment routing signal used by our hosting providerStrictly necessary
formto_pref1st partyFormTo1 yearStores UI preferences (e.g. theme or layout choices, if used)Functional
Analytics cookie3rd partyTBDTBDAggregate traffic analysis — not yet activeAnalytics (not yet active)

Consent mechanism

For users in the EEA and UK, non-essential cookies (Functional and Analytics categories) require your consent before being set, in accordance with the ePrivacy Directive and GDPR.

Currently, FormTo only sets strictly necessary cookies, which do not require prior consent. When we activate analytics or other non-essential cookies, a consent banner will appear on first visit for EEA/UK users. Your consent choice will be stored in a localStorage key named formto_cookie_consent (containing the consent timestamp, accepted categories, and notice version). This record is stored locally in your browser and is not transmitted to our servers.

You may withdraw or modify your consent at any time by clearing your browser's site data for our domain, or by using the cookie preferences link (to be added to the footer when non-essential cookies are activated). If the Cookie Notice is materially updated, you will be re-prompted on your next visit.

Your choices and opt-out instructions

Strictly necessary cookies

These cookies cannot be disabled without breaking core functionality of the FormTo dashboard (such as logging in and maintaining your session). If you block these cookies via your browser settings, the app will not function correctly.

Functional cookies

To remove functional cookies, go to your browser settings, navigate to site data or cookies, and clear data for formto.dev. Note that doing so will reset any saved UI preferences.

Analytics cookies (when active)

When analytics is activated, you will be able to opt out via the consent banner displayed on your first visit. You may also opt out at any time by clicking the cookie preferences link in the footer. Additionally, FormTo respects the Do Not Track (DNT) browser signal — when DNT is enabled, no analytics cookies will be set, even after analytics is activated.

Clerk session cookies

Logging out of the FormTo dashboard removes active session cookies set by Clerk. For more information on how Clerk uses cookies, see Clerk's privacy policy at clerk.com/privacy.

Do Not Track

FormTo respects the Do Not Track (DNT) browser signal as a best-effort commitment: when your browser sends a DNT: 1 header, we will not set analytics or tracking cookies on your device, even if you have previously consented or if analytics is later activated. Strictly necessary and functional cookies are not affected by DNT as they are required for service operation.

Third-party cookie policies

Some cookies are set by third-party providers whose own privacy and cookie policies govern how they use that data. Relevant policies:

  • Clerk — authentication cookies: clerk.com/privacy
  • Stripe — billing and fraud-prevention cookies: stripe.com/privacy
  • Vercel — hosting infrastructure cookies: vercel.com/legal/privacy-policy

How consent is recorded

When you interact with a consent banner (once introduced), FormTo records the following in your browser's localStorage under the key formto_cookie_consent:

  • The timestamp of consent (ISO 8601 format)
  • The categories accepted (e.g. ["necessary", "functional"])
  • The version of the Cookie Notice in effect at the time of consent

This record is stored solely in your browser and is not transmitted to FormTo's servers. If the Cookie Notice version changes materially (i.e. we add new cookie categories), the stored version will be compared to the current version on your next visit and you will be re-prompted if there is a mismatch.

Contact

Questions about this notice: contact@formto.dev.

Privacy · Terms · Home