On this page
- 1.Who we are
- 2.Data we collect from people who build forms
- 3.Data collected when someone answers a form
- 4.Data from visitors trying ask.ai
- 5.Why we use it
- 6.Who helps us run ask.ai
- 7.International transfers
- 8.Cookies and browser storage
- 9.How long we keep data
- 10.Security
- 11.Your rights
- 12.Children
- 13.Changes to this policy
- 14.Contact
The short version
- We collect what we need to run ask.ai: your account, the forms you build and the responses they receive.
- If you answer a form, the person who made it decides what to ask and what happens with your answers. Contact them first.
- We don't sell personal data and we don't show ads.
- A few trusted providers help us run the service, such as hosting, payments, email and AI form generation.
- You can ask us to access, correct, export or delete your data at any time.
1.Who we are
ask.ai (tryask.ai) is an online form builder run by ask.ai. In this policy, "we" means ask.ai and "you" means anyone who uses the website, builds forms, or answers a form made with it.
This policy covers two different situations, and our role is different in each:
- When you create an account and build forms, we decide how your account data is used. We are the controller of that data.
- When someone answers a form, the person or company that made the form decides what to ask and what to do with the answers. They are the controller of the responses, and we process them on their behalf.
2.Data we collect from people who build forms
- Account details: your email address and, if you sign in with Google, the basic profile Google shares (name and email). We sign you in with a one-time email link or with Google; we don't store passwords.
- Workspace details: your workspace name, the teammates you invite and their roles.
- Your content: the forms you create, their settings, any logo you upload, and the responses your forms receive.
- AI prompts: what you type when you ask ask.ai to write or change a form.
- Billing: your plan and payment status. Payments are handled by Stripe; we never see or store your full card number.
- Integrations you connect: for example webhook addresses, tracking IDs (Meta Pixel, Google Analytics, Google Tag Manager, TikTok Pixel) and HubSpot or Salesforce connections. Access tokens for HubSpot and Salesforce are stored encrypted.
- Usage needed to run your plan, such as how many forms, responses and AI generations you've used this month.
3.Data collected when someone answers a form
When you answer a form, we store your answers for the form's owner. Depending on the form and on the owner's plan, we also record:
- Technical details: browser and operating system, device type, the page that linked to the form, language, time zone, screen size and how long you took to finish.
- On forms made by Pro workspaces: your IP address (unless the owner turned this off), your approximate country and city derived from it, and campaign tags (UTM) in the link you followed.
- While you have the form open, a short-lived record that someone is on it (approximate location, device and how far you've got) so the owner can see live activity. It is removed when you leave or shortly after.
- If the form is part of an A/B test, a random visitor ID and a cookie so you keep seeing the same version.
- If the form includes a meeting booking step, the booking itself happens on the owner's Calendly, Cal.com or Google Calendar page, under that provider's terms. We only store whether the booking was made.
The form's owner may also add their own tracking (such as Meta Pixel, Google Analytics, Google Tag Manager or TikTok Pixel) or send responses to their own tools (webhooks, HubSpot, Salesforce). Those transfers happen on the owner's instructions. If you have questions about how your answers are used, contact the person or company that shared the form with you.
4.Data from visitors trying ask.ai
On our website you can describe a form and see a draft before creating an account. What you type is sent to our AI provider to generate the draft, and the draft is kept in your browser until you sign up. We use your IP address to limit how many free drafts can be made each day and to block abuse.
5.Why we use it
- To provide the service: sign you in, save and publish your forms, collect and show responses, and send responses to the tools you connect. (Performance of our contract with you.)
- To generate forms with AI when you ask us to. (Performance of contract.)
- To bill you and keep records we're required to keep. (Contract and legal obligations.)
- To keep ask.ai secure: prevent spam, bots and abuse, and investigate problems. (Our legitimate interest in running a safe service.)
- To send you service emails, such as sign-in links, invitations and important account notices. We don't send marketing emails without your consent.
6.Who helps us run ask.ai
We share data only with providers that help us run the service, under contracts that limit what they can do with it:
- Supabase: database, file storage, sign-in and real-time updates. Our database is hosted in the United States (North Virginia).
- Vercel: hosts the application, and works out a visitor's approximate country and city from their IP address.
- OpenAI: generates and edits forms from your prompts. Your prompt (and, when editing, the current form) is sent to OpenAI.
- Stripe: payments and subscriptions.
- Resend: sends our transactional emails.
- Cloudflare Turnstile: checks that form submissions and free drafts come from people, not bots.
- Upstash, when enabled: short-lived counters used for rate limiting.
Tools you connect yourself (webhooks, HubSpot, Salesforce, tracking pixels) receive data because you asked us to send it. Their own terms and privacy policies apply. We don't sell personal data to anyone.
7.International transfers
Our database and servers are in the United States, and so are providers such as OpenAI, Stripe and Resend, so your data may be processed outside your country. When that happens we rely on the safeguards the law requires, such as standard contractual clauses.
8.Cookies and browser storage
We use a small number of cookies and browser storage items, all needed for the service to work:
- Sign-in cookies that keep you logged in.
- Your language choice on our website, and the workspace you last opened.
- On forms in an A/B test, a cookie that keeps you on the same version.
- In your browser's local storage: your theme and, while you try ask.ai without an account, your draft form.
We don't use advertising cookies on our own website. Tracking pixels appear on a public form only if its owner added them.
9.How long we keep data
We keep account data and forms for as long as your account is active. Responses stay until the form's owner deletes them, deletes the form, or closes their account. When an account is closed we delete its data within 30 days, except records we must keep by law (such as invoices). Live-activity records last only while someone is on a form, and security logs are kept only as long as needed to protect the service.
10.Security
Data is encrypted in transit. Access to workspace data is limited to its members by database-level rules, integration tokens are encrypted at rest, and only a small number of people can access production systems. No system is perfectly secure, so if we learn of a breach that affects you, we'll tell you and the authorities as the law requires.
11.Your rights
Depending on where you live, including under Brazil's LGPD and the EU and UK GDPR, you can ask us to:
- confirm whether we process your data, and give you a copy of it;
- correct data that is wrong or incomplete;
- delete it, or anonymise it when deletion isn't possible;
- export it in a portable format;
- stop or limit certain uses, and withdraw consent you've given;
- explain who we share it with.
Email privacy@tryask.ai and we'll reply within 15 days. If your data came from answering someone's form, we'll pass your request to that form's owner, who decides how to handle it. You can also complain to your data protection authority, such as the ANPD in Brazil.
12.Children
ask.ai is meant for adults building forms for work or personal projects. You must be 18 or older to create an account, and we don't knowingly collect data from children. Form owners are responsible for getting the permissions the law requires before collecting answers from children.
13.Changes to this policy
If we change this policy, we'll update the date at the top. For important changes we'll also let account holders know by email or in the app before the changes take effect.
14.Contact
Questions about privacy, or a request about your data: privacy@tryask.ai. ask.ai is run by ask.ai.