Privacy
What we collect, where it goes, and when it's deleted
Who we are
Missed Form Alert is run by Rohan Kulkarni, an individual trading as 9th House. There is no company behind it yet. If that changes, this page will say so and name the company.
Contact for anything on this page: rohan@9thhouse.io.
Two kinds of data, two roles
- Messages people send through a website's contact form. The website owner decides to use Missed Form Alert, so the owner (or the agency running the site for them) is the controller. We handle those messages only on their instructions, as a processor.
- Our own customers' details: the site URL, the email address alerts go to, and anything you send us on the early-access form. For these we are the controller.
What stays on the website
Once installed, the plugin records every Contact Form 7 and WPForms submission in a table in the site's own WordPress database, along with how it ended: delivered, blocked by a spam filter or honeypot, stopped before the form plugin ran, or its notification email failed.
- Password, payment card and file-upload fields are never recorded. Nor are captcha tokens or anything that looks like a card number.
- For honeypot fields (hidden fields only bots fill in), we keep only whether it was filled, never what was typed.
- Submissions made by a logged-in site administrator are not recorded.
- The message text in this table, and the spam filter's reason, are cleared after 7 days by a daily job on the site. The row itself (date, form, outcome) stays so the site can count what happened.
- Delivered submissions never leave the site. They are only counted.
- Deleting the plugin removes the table, its settings and its scheduled jobs.
What leaves the website
Nothing leaves until a site administrator enters a site key and ticks the consent box in the plugin's settings. After that, only these submissions are sent to our checking service:
- blocked by the spam filter or a honeypot,
- stopped before the form plugin ran, or
- accepted by the form, but the notification email to the owner failed to send.
For each one we receive: a random ID, the site's URL, which form plugin and form it came from, how it ended, the spam filter's reason if it gave one, whether a honeypot was filled, and the form fields as the visitor typed them (minus the excluded fields above). That includes the sender's name, email address and phone number if the form asked for them. We need those so the alert can show the owner the whole message and they can reply. Each one also carries the plugin's "Alert email" setting, and alerts go to the latest one we received.
The plugin sends this after the visitor has already seen their "thank you" page, so visitors never wait on us.
Where it goes
| Who | What they get | Where | Why |
|---|---|---|---|
| Cloudflare, Inc. | Everything listed under "What leaves the website" | Stored in a Cloudflare D1 database set to EU jurisdiction. The code that receives each request runs on Cloudflare's network, which can be outside the EU. | Hosts our checking service and its database |
| TypeSafe AI, Inc. (the Jev classifier) | The form fields only, after we replace email addresses, phone numbers, and any field labelled as a name (such as "Name" or "First name") with placeholders. A name the sender types inside the message itself, and web links, are kept. TypeSafe does not get the site URL. | United States | Rates each message as a real enquiry, a sales pitch or spam |
| An email delivery provider (to be named before alerts go live) | The alert: the recipient's address and the message it's about | To be confirmed when named | Delivers alert and weekly summary emails |
Right now alerts are written and stored but not emailed, because no email provider is connected. This page will name the provider before any alert email is sent.
About TypeSafe
The verdict on each message comes from an AI model. It can be wrong. That's why every alert includes the message itself.
TypeSafe's terms say it will not train its models on what we send. They also give TypeSafe a permanent right to keep technical logs, statistics and "classifications ... and learnings" derived from it, and to use those to improve its services. TypeSafe does not publish how many days it keeps the requests themselves. We don't know that number. We have not asked TypeSafe yet. When we have an answer we'll put it here.
Data sent to TypeSafe in the US is covered by the EU Standard Contractual Clauses and the UK Addendum in TypeSafe's data processing agreement.
How long we keep it
| What | How long |
|---|---|
| Message text on the website | 7 days, then cleared |
| Message text on our service, including the spam filter's reason and the copy inside a stored alert | 7 days, then cleared by a daily job |
| The verdict and its scores, the form, the outcome, the alert type and subject line, and the timestamps | Kept, so weekly summaries and accuracy checks still work. The alert subject contains the site URL, not message text. |
| Weekly summaries (counts per site) | Kept |
| Site details: URL, alert email addresses, and a one-way hash of the site key | While the site is registered. On request we delete the site and everything kept for it: its checks, verdicts, alerts, counters and weekly summaries. An agency's combined weekly summary that lists the site is not changed. |
| Early-access sign-ups: email and agency name | 12 months, then deleted automatically by a daily job. Sooner if you ask. |
| Our service logs | They hold IDs, verdicts and error codes, never message text or email addresses. Cloudflare keeps them for its standard log period. |
| Anything sent to TypeSafe | Unknown. See above. |
Sites that must not switch sending on
TypeSafe's terms do not cover special-category data such as health information. So sites for clinics, therapists, doctors, lawyers, or anything aimed at children, must not tick the consent box. If you install the plugin on such a site, leave sending off. It still records locally and does nothing else.
If you tell us a site is in one of these areas, we also mark it on our side. For a marked site we never store message text or the filter's reason, and nothing is passed to TypeSafe: we keep only how each submission ended and when. If a message's notification email failed, we still send an alert, with the message withheld. This is only a backstop, so please still leave sending off.
What we don't do
- We don't sell or rent any of this data.
- We don't use it to train any AI model.
- We don't use it for advertising, and we don't contact the people who filled in the forms.
- The plugin sets no cookies on visitors.
- Our own website uses PostHog (hosted in the United States) to count visits, see which pages people come from, and count sign-ups. It runs without cookies and without building personal profiles. If you sign up, we store only the email address you give us.
- Our website also uses Cloudflare Web Analytics, which counts page views without cookies and without identifying individual visitors.
With a design partner's written agreement, and their client's consent, we may use blocked messages to measure how accurate the checks are. Those messages are anonymised first and are never shared outside Missed Form Alert.
Your rights
If you filled in a form on someone's website, that website's owner is in charge of your message. Ask them first. They can export or erase what the plugin holds on their site from WordPress (Tools, then Export or Erase Personal Data), searched by your email address. For the copy on our service, they can ask us, or you can email us directly and we will delete it. We can also delete a whole site and everything kept for it.
If you're our customer or signed up for early access, you can ask us to see, correct, export or delete your details, or object to how we use them.
Email rohan@9thhouse.io. We'll answer within one month. If you're in the EU or UK and unhappy with our answer, you can complain to your data protection authority.
Changes
If we change what we collect or who we send it to, we'll update this page and email registered site owners before the change applies. We will give at least 14 days' notice.