Form Watchdog
Privacy Policy
How Form Watchdog accesses, processes, stores, and protects information.
Last updated: October 4, 2026
Form Watchdog respects your privacy and is designed to minimize the amount of data it stores.
This Privacy Policy explains how Form Watchdog accesses, processes, stores, and protects information when you connect your Google account and use the service.
1. What Form Watchdog does
Form Watchdog connects to Google Forms™ to monitor new form responses and send email notifications.
Depending on your notification and follow-up settings, Form Watchdog can:
- notify you that a new response has been received;
- optionally include the contents of the response in the notification email;
- monitor responses independently through the Google Forms™ API;
- retry Form Watchdog notifications when an email delivery attempt fails;
- help you track responses as unhandled, overdue, handled, or temporarily snoozed;
- send a single reminder when a response remains unhandled after the delay you selected;
- let you explicitly view the details of a specific response when you need them for follow-up.
Form Watchdog does not modify your Google Forms™ or their responses.
2. Google account information
When you connect Form Watchdog with Google, we receive limited information necessary to identify your account and provide the service.
This may include:
- your Google account identifier;
- your verified Google email address;
- authorization information required to access the Google Forms™ you choose to monitor.
Your Google password is never provided to Form Watchdog.
3. Google Forms™ access
Form Watchdog requests read-only access to:
- the structure of the Google Form you choose to monitor;
- responses submitted to that Form.
This access is used only to provide Form Watchdog's monitoring, notification, reminder, and response follow-up features.
Google Forms™ Editor Add-on
The Form Watchdog Google Forms™ Editor Add-on helps you connect the Google Form that is currently open to your Form Watchdog workspace. It displays a menu and connection interface within Google Forms™ so you can start and complete that connection from the selected Form.
The add-on uses the Apps Script scopes forms.currentonly, script.container.ui, script.external_request, and openid. The forms.currentonly scope limits its Forms access to the currently open Form; during connection, the add-on reads only that Form's identifier, not its questions or response answers. The script.container.ui scope allows the add-on to show its interface in Google Forms™. Apps Script uses UrlFetchApp to make an outbound HTTPS request to Form Watchdog. The script.external_request scope permits outbound requests to external hosts; by itself, it does not grant access to Google account data or additional Forms. The openid scope provides the Google identity token used for the secure handoff.
When you select “Connect to Watchdog,” the add-on sends the current Form's identifier and a Google identity token to the Form Watchdog backend. The backend verifies the token and creates a temporary, single-use connection handoff that expires after 15 minutes. You then complete the connection on the Form Watchdog website; the add-on does not itself complete the website's Google authorization.
The add-on's Google identity authorization is separate from the Google OAuth connection used by the Form Watchdog web application. The identity token identifies the Google account for the secure handoff. To monitor a Form and access its responses, you separately authorize the web application to access the Forms you choose, as described below.
When you explicitly choose “View details” for a response, Form Watchdog retrieves that specific response from Google Forms™ using your authorized Google connection. This may include respondent information made available by Google Forms™, as well as the Form questions and submitted answers.
Response answers are retrieved only when requested and are displayed only to the authenticated Owner of the connected Form. Authorized members of a Team workspace can access follow-up metadata for workspace responses; Responders are limited to responses assigned to them. The Team response page does not expose Google Forms™ answers. Opening a response follow-up page by itself does not retrieve answers. Response details retrieved through “View details” are not added to the Form Watchdog database solely as a result of viewing them.
Form Watchdog does not create, edit, or delete your Google Forms™ or responses.
4. Response content
Form Watchdog provides two email-content modes.
Notification only
This is the default and privacy-recommended mode.
In this mode, Form Watchdog detects that a new response exists but does not include the respondent's answers in the notification email.
The response content remains in Google Forms™ and is not stored by Form Watchdog.
Full response in email
You may optionally choose to include the form answers directly in your notification email.
When this option is enabled, Form Watchdog temporarily processes the response content to create the notification email.
If you explicitly enable response content in Reminders, Form Watchdog may temporarily store an encrypted copy of the response solely to generate the requested Reminder. The copy is encrypted using Cloud KMS, assigned a 72-hour expiration, and deleted earlier when the response is marked handled or the Reminder workflow finishes. Firestore TTL removes expired copies asynchronously.
Otherwise, Form Watchdog does not store the contents of your form responses in its database.
The response content is transmitted to our email delivery provider solely for the purpose of delivering the notification or Reminder you requested.
5. Information we store
Form Watchdog stores only information necessary to operate the service.
This may include:
- your Google account identifier;
- your verified notification email address;
- the Google Form you selected;
- monitoring status and activation time;
- your notification and Reminder preferences;
- encrypted Google authorization credentials;
- technical identifiers used to determine whether a response has already been processed;
- a stable internal reference used to identify the same response within Form Watchdog without storing its submitted answers;
- response follow-up status, such as whether a response is unhandled, overdue, handled, or temporarily snoozed;
- outcomes and notes that Owners or authorized Team members add while following up on a response;
- Reminder timing, snooze timing, and follow-up timestamps;
- notification status, retry count, and technical timestamps;
- an optional, short-lived encrypted response copy when you explicitly enable response content in Reminders;
- session and security information necessary to authenticate your account.
We do not store answers submitted by respondents unless you explicitly enable response content in Reminders. Any such copy is encrypted, assigned a 72-hour expiration, and removed earlier when it is no longer needed. Expired copies are removed asynchronously by Firestore TTL.
Response details retrieved through “View details” are not stored in the Form Watchdog database solely as a result of viewing them.
6. Google authorization credentials
Google authorization credentials that allow Form Watchdog to access your selected Form are stored in encrypted form.
Refresh tokens are encrypted using Google Cloud Key Management Service (Cloud KMS).
Plaintext refresh tokens are not stored in the Form Watchdog database.
7. Email notifications
Form Watchdog uses Resend to deliver email notifications and Reminders.
When an email notification or Reminder is sent, Resend receives the information necessary to deliver that message, including:
- the notification recipient;
- the email subject;
- the email contents.
If you enable Full response in email, the relevant Google Form response content is temporarily transmitted to Resend for email delivery. If you also enable response content in Reminders, the same limited content may be transmitted again for the single Reminder.
If you use Notification only and do not enable response content in Reminders, respondent answers are not included in those emails sent through Resend.
Resend processes this information according to its own privacy and data-processing practices.
8. Infrastructure providers
Form Watchdog currently uses services provided by Google Cloud, including:
- Cloud Run;
- Firestore;
- Cloud KMS;
- Secret Manager;
- Cloud Scheduler;
- Firebase Hosting.
These services are used to host the application, securely store technical data and credentials, and operate the monitoring service.
9. Logs
Form Watchdog is designed to avoid placing Google Form response contents, Google access tokens, refresh tokens, or other sensitive authorization credentials in application logs.
Technical logs may contain operational information such as:
- request status;
- error codes;
- processing counters;
- non-sensitive technical events.
10. How we use your information
Information accessed through Google APIs is used only to:
- authenticate you;
- identify the Google Form you have selected;
- monitor that Form for new responses;
- prevent duplicate processing;
- maintain follow-up status for responses, including unhandled, overdue, handled, and snoozed states;
- provide follow-up metadata to authorized Team workspace members, with Responders limited to responses assigned to them;
- schedule and send Reminders requested by you for responses that remain unhandled;
- retrieve and display a specific Google Forms™ response, including available respondent information and submitted answers, when the authenticated Form owner explicitly requests to view its details;
- send the notifications you have requested;
- maintain the security and reliability of the service.
We do not sell your information.
We do not sell Google user data.
We do not use Google Forms™ response content for advertising, profiling, or marketing.
We do not use Google Workspace API data to develop, train, or improve generalized artificial intelligence or machine learning models.
The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
11. Sharing of information
We share information only with service providers necessary to operate Form Watchdog, such as Google Cloud and Resend.
When you explicitly enable Slack or configure a webhook, Form Watchdog sends operational event metadata to your selected destination. This may include Form identifiers, response references, status, assignment information and SLA timestamps. Google authorization tokens and submitted response answers are not included in these operational event payloads.
We do not sell or rent personal information to advertisers, data brokers, or other third parties.
We may disclose information if required by applicable law or valid legal process.
12. Data retention
Technical data, including response follow-up metadata, is retained only for as long as reasonably necessary to provide Form Watchdog, maintain security, prevent duplicate notifications, support response follow-up, troubleshoot the service, and meet applicable legal obligations.
Google Form response contents are not stored unless you explicitly enable response content in Reminders. Those optional encrypted copies receive the limited expiration described above.
Response contents retrieved through “View details” are requested from Google Forms™ on demand and are not added to the Form Watchdog database solely as a result of being viewed.
Authentication sessions expire automatically.
Google authorization credentials may remain stored in encrypted form while your Form Watchdog connection is active.
13. Disconnecting Form Watchdog and deleting your data
You may stop using Form Watchdog at any time.
Signing out of Form Watchdog ends your active application session but does not necessarily revoke Google's authorization to Form Watchdog.
You may revoke Form Watchdog's access to your Google account through your Google Account security settings.
You may also request deletion of the personal and account data stored by Form Watchdog by contacting:
We will process legitimate deletion requests within a reasonable period, subject to information we may be required to retain for legal, security, or fraud-prevention purposes.
14. Security
We use reasonable technical safeguards designed to protect information processed by Form Watchdog.
These include:
- HTTPS encryption;
- encrypted Google authorization credentials;
- encryption of temporary response content when response content in Reminders is enabled;
- server-side sessions;
- CSRF protection;
- access controls;
- encrypted secret management;
- processing isolation between users;
- measures designed to prevent duplicate processing.
No internet service can guarantee absolute security.
15. Children's privacy
Form Watchdog is intended for business and professional use and is not designed for children.
We do not knowingly collect personal information directly from children through the Form Watchdog service.
16. Changes to this Privacy Policy
We may update this Privacy Policy as Form Watchdog evolves.
The current version and its effective date will be posted on this page.
Material changes may be communicated through the service when appropriate.
17. Contact
If you have questions about this Privacy Policy, Form Watchdog's privacy practices, or deletion of your Form Watchdog data, contact:
Google Forms™ is a trademark of Google LLC.
Google API Services User Data
Form Watchdog's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.