Legal
Privacy Policy
Last updated 2 September 2026
Wellform is operated by Media Yard LLC, a New Jersey limited liability company of PO Box 73, Pennsauken, NJ 08110, United States. It is the data controller for the account information described below. This policy describes what we collect and what we do with it. It is written to be checkable against how the service actually behaves rather than to cover every hypothetical.
The short version
Documents you send are rendered in memory and returned in the response. By default nothing is stored — the HTML you post and the PDF we produce are gone when the request finishes. Storage happens only when you explicitly ask for it. We never look at document contents, never log them, and never use them to train anything. The rendering pipeline contains no AI. Details are in the AI policy.
What we collect
Account data
Your email address, your plan, and identifiers linking you to your Stripe customer and subscription records. This is what an account is. For this data we are the controller.
API keys
Stored only as SHA-256 hashes. The plaintext exists once, when the key is created, and is never recoverable — not by you and not by us. We also record a non-secret prefix so you can tell keys apart, and the time a key was last used.
Usage counts
A per-month tally of documents produced, per account. This is what your bill is calculated from. It is a number, not a record of what you rendered.
Document content
HTML you submit is held in memory for the duration of the request and
discarded. If you pass "store": true, the resulting PDF is written
to object storage and you receive a URL. Identical output is stored once, since
keys are derived from a hash of the content itself. For other people's personal
data inside those documents, you are the controller (or their processor) and we
are the processor (or sub-processor). See the
data processing agreement.
Files sent to the public checker
The checker at wellform.dev/check takes no account and identifies nobody. An uploaded PDF is written to a temporary directory inside the container so the validator can open it and deleted when the request returns. It is not stored, not logged, and not used to train anything. If the document you are checking contains personal data, none of it reaches us beyond the life of that request.
Because the endpoint is open to anyone, it is rate limited. We keep a salted SHA-256 hash of the requesting IP address with a timestamp — never the address itself — and rows older than the one-hour limit window are deleted as later requests arrive. The hash is not reversible and is not linked to any account.
Request logs
Our infrastructure provider records standard request metadata — timestamp, status code, response time, IP address. Document bodies are not written to logs.
Payment data
We never receive or store card numbers. Checkout and the billing portal are hosted by Stripe, and card details go directly to them.
How long we keep it
| Data | Retention |
|---|---|
| Submitted HTML | Duration of the request only. Never written to disk. |
| Generated PDFs (unstored) | Duration of the request only. |
| Generated PDFs (stored on request) | 30 days, then deleted automatically. |
| Account and key records | Life of the account, then 90 days. |
| Usage counts | Retained for billing and tax records. |
| Files sent to the public checker | Duration of the request only. Never written to storage. |
| Checker rate-limit hashes | One hour, then deleted. |
| Request logs | As retained by our infrastructure provider, currently 7 days. |
Who else processes data
Document processing (we are processor or sub-processor)
This is the Article 28 / SCC Annex III list. It is the list we are held to in the DPA.
| Legal name | Address | Location of processing | Contact | What they do |
|---|---|---|---|---|
| Cloudflare, Inc. | 101 Townsend Street, San Francisco, CA 94107, United States | United States, and the Cloudflare region nearest the caller | dpo@cloudflare.com | Compute, object storage of stored output, database, DNS, request metadata logs |
Account and payments (we are controller)
Neither of these receives document content.
| Legal name | Address | Location of processing | Contact | What they do |
|---|---|---|---|---|
| Stripe, Inc. | 354 Oyster Point Boulevard, South San Francisco, CA 94080, United States | United States | privacy@stripe.com | Payments, subscriptions and invoicing of your account. |
| Resend, Inc. | 2261 Market Street, San Francisco, CA 94114, United States | United States | privacy@resend.com | Delivery of account email: key recovery, plan changes and service notices. |
Before a new party begins processing customer personal data we will update this page and email account holders at least thirty days in advance. If you object on reasonable data-protection grounds within that window, write to us and we will look for an alternative; if there is none, you may terminate the affected subscription without penalty and receive a pro-rata refund of any prepaid fees.
We do not sell personal data, and we do not share it with anyone for advertising. We will disclose data if legally compelled, and where we are permitted to tell you, we will.
Your customers' data
Documents of the kind Wellform exists to produce — invoices, statements, reports, school letters — frequently contain other people's personal data, including in some cases children's data. Where that is the case you are the controller (or a processor for your own customer) and we are the processor (or sub-processor): we act on your instructions, which in practice means rendering what you send and storing it only if you ask. Because unstored content never persists, the surface for that data is a single request. The terms of that processing are set out in our data processing agreement, which applies automatically to every account — you do not have to ask for it or sign anything. If your procurement process needs a countersigned copy, write to support@wellform.dev.
Health data is out of scope. Wellform is not configured for information governed by HIPAA or comparable health-privacy law, and the terms ask you not to send it.
International transfers
Our infrastructure is globally distributed and a request may be processed in a region near the caller. Data at rest is held with the providers listed above. In practice this means personal data may be processed in the United States and in other countries where those providers operate.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, incorporated into our data processing agreement — together with the UK Addendum issued under section 119A of the Data Protection Act 2018 for UK transfers, and the Swiss Federal Data Protection and Information Commissioner's adaptations for Swiss transfers. On request we will provide our assessment of US law as it applies to this processing, to you or to a supervisory authority. Cloudflare, Stripe and Resend each maintain their own transfer mechanisms for the onward transfers they make.
EU representative
We are established in the United States and have not appointed a representative in the Union under Article 27 GDPR. Contact for data-protection matters is support@wellform.dev and the postal address below. If we appoint a representative, this section will name them.
Your rights
Depending on where you live you may have rights to access, correct, delete or export your personal data, to object to or restrict processing, and to complain to a supervisory authority. Email support@wellform.dev and we will respond within 30 days. We will ask you to verify control of the account before acting.
Deleting your account removes account and key records on the schedule above. Usage totals needed for tax and accounting are retained. Stored documents can be retrieved or deleted through the API until they expire.
Security
Traffic is encrypted in transit. Keys are stored hashed. Rendering runs unprivileged in an isolated container, and requests to private, loopback and link-local network addresses are refused so that submitted markup cannot be used to reach internal systems. No system is perfectly secure, and we do not claim otherwise.
Children
Wellform is a developer tool for businesses. We do not knowingly create accounts for anyone under 16, and the service is not directed at children as users.
That is about who may hold an account. It is not a claim that documents are free of children's data. School letters, pupil reports and similar files will often name children. You are the controller (or processor) of that data; we process it only as described in the DPA, and only because you sent it.
Changes
If we make a material change we will email account holders and update the date at the top of this page.
Contact
Media Yard LLCPO Box 73
Pennsauken, NJ 08110
United States