This Privacy Policy explains how 854 Labs LLC (“854 Labs”), an Indiana limited liability company operating html.contact (“html.contact”, “we”, “us”, or “our”), handles information when you use html.contact.
html.contact is a form backend. Customers create forms, whitelist source domains, verify recipient emails, receive submissions in a dashboard, optionally store one attachment, and send notification emails.
Roles
For form submissions, html.contact processes submission content on behalf of the customer who created the form. End users who submit forms should review the privacy policy of the website or organization operating that form.
For account registration, billing, support, security, abuse prevention, product analytics, legal compliance, and service administration, html.contact processes certain information for its own business and service-administration purposes.
Customers are responsible for deciding what their forms collect, providing their own notices and consents, and using html.contact lawfully.
Information We Collect
We may collect:
- Account information, such as email address, first name, and last name.
- Verified recipient emails linked to an account.
- Form configuration, allowed domains, form names, and routing settings.
- Form submission fields, such as names, emails, phone numbers, messages, and other fields chosen by the customer.
- One optional attachment per submission, if the customer form accepts file uploads.
- Source and security metadata, such as source host, source URL, user agent, approximate Cloudflare location signals when available, rate-limit signals, and IP-derived security signals.
- Email delivery and audit metadata, including recipient status, provider status, message IDs, and delivery lifecycle information when available.
- Billing, subscription, invoice, and usage metadata processed through Stripe.
- Product analytics events using internal unique IDs rather than email addresses.
- Support, privacy, legal, security, and trust correspondence.
We do not collect profile photos at launch.
Prohibited Data
html.contact is not intended for sensitive or regulated data. Do not use the service to collect or process:
- Health information or PHI.
- Payment card numbers.
- Social Security numbers, tax IDs, government IDs, or identity documents.
- Passwords, private keys, API keys, secrets, or credentials.
- Children’s data.
- GLBA, FERPA, HIPAA, PCI, or similar regulated workloads.
- Other highly sensitive personal data.
See the Acceptable Use Policy for more.
How We Use Information
We use information to:
- Provide, operate, secure, and improve html.contact.
- Receive, store, display, export, and route form submissions.
- Send notification, verification, billing, security, and support emails.
- Enforce allowed-domain checks, recipient verification, rate limits, spam screening, usage limits, and abuse controls.
- Provide account, billing, and customer support.
- Monitor reliability and product usage.
- Investigate abuse, security reports, legal requests, and policy violations.
- Comply with legal, accounting, tax, and operational obligations.
Product Analytics
We use PostHog for product analytics to understand usage patterns and improve the product. Public and authentication pages use cookieless analytics without PostHog browser storage or identified visitor profiles. Inside the signed-in app, analytics may use local browser storage and an internal unique user ID so we can understand product usage over time.
We do not use PostHog for advertising, cross-context behavioral advertising, email tracking, session replay, or form-submission inspection. Analytics events use internal unique IDs rather than email addresses, and our analytics helpers deny or redact sensitive properties such as emails, form keys, API keys, submitted fields, message bodies, Stripe payloads, cookies, passwords, submission IDs, and attachment IDs.
On public pages, we prefer analytics configurations that avoid non-essential persistent storage where feasible. Logged-in app analytics may use product analytics tied to internal unique IDs.
Connected MCP Clients
A verified, fully onboarded account holder may authorize a compatible AI or coding-agent client, including ChatGPT, with specific scopes. The default forms:read scope permits committed public-documentation tools, bounded form configuration and account usage, public installation instructions, deterministic form-readiness checks, and bounded review of form markup supplied by the client. The separate forms:write scope permits confirmed form creation, allowed-domain replacement, basic form-setting changes, synthetic test submissions, and owner-only notification tests.
Recipient and submission data require additional, non-default authorization. With recipients:read, a client may list account-linked email addresses and their verification and deliverability state and may read a form’s complete To, CC, and BCC routing snapshot. With recipients:write, a client may send a verification email to a proposed linked address and, after confirmation, replace a form’s complete routing snapshot using verified linked addresses. With submissions:read, a client may list bounded submission metadata and read the visitor-provided fields and safe attachment metadata of a specifically selected submission. Account holders should authorize only the scopes needed for the task.
Documentation tools use a fixed build-time allowlist and do not fetch user-supplied URLs. Form diagnosis returns bounded status codes and recommendations without recipient addresses, suppression reasons, billing internals, or submission content. Form-code review does not execute the supplied markup or fetch a URL, and does not return the supplied code. Supply only the relevant form markup and omit unrelated source files, secrets, tokens, credentials, and personal data. Submission list results omit visitor fields and identity. Submission detail results exclude raw network and security metadata, full source URLs, email-provider identifiers, internal spam signals, event payloads, and private attachment-storage keys. The MCP integration does not expose payment records, billing management, account administration, API-key management, deletion actions, arbitrary outbound email, or linked-email deletion.
A synthetic MCP test is stored as a submission, consumes normal accepted-submission usage, and may cause a real notification email to configured form recipients. In contrast, an owner-only notification test sends only to the signed-in account email, does not notify the form’s To, CC, or BCC recipients, does not create a submission, and does not consume submission usage. A linked-email verification request sends a real email only to the proposed address. These actions require an exact confirmation in addition to the applicable authorization scope.
For MCP actions that can change product or external state, html.contact stores content-free tool diagnostics such as account/client identifiers, tool name, outcome, error code, timing, and a keyed resource reference. Read-only MCP tools do not create diagnostic events. These events never store tool arguments or results.
The third-party client’s own privacy terms and data controls apply to information processed by that client. html.contact does not send account or form data to OpenAI merely because the MCP endpoint exists; information is returned to an OpenAI service only when an account holder connects and authorizes an OpenAI client and that client requests an authorized tool. Disconnect the client and revoke its html.contact authorization when it should no longer act for the account. MCP access tokens are separate from browser sessions, html.contact API keys, and social-provider tokens.
Google Sheets Connections
When this integration is available and you connect Google Sheets, we receive your Google account identifier, verified email address, and authorization credentials. We encrypt the stored credentials and use them to maintain the connection, including refreshing access while you are away. This connection is separate from Google sign-in to html.contact.
Google Picker lets you select existing spreadsheet files. We request access to the files you select, rather than your entire Drive. Google grants permission at the spreadsheet-file level, including its worksheets. We read selected-file metadata, worksheet names, managed headers, and submission IDs to configure your destination, maintain columns, and reconcile deliveries. Setup may inspect an existing worksheet to confirm that it is empty. We do not persist unrelated worksheet contents.
When you enable a form’s destination, we send newly accepted responses to its dedicated worksheet. Rows include submitted fields, attachment filenames where applicable, the submission ID and timestamp, and an authenticated link to the submission. Attachment bytes and public attachment-download links are not exported. Existing submissions are not exported automatically.
Encrypted retry payloads expire after seven days. We retain safe integration-delivery metadata for up to 30 days. You can pause or remove a form’s destination, disconnect the shared Google connection in Settings, or revoke the grant through your Google account. Disconnecting deletes locally usable Google credentials and cancels pending exports. Rows already exported to Google remain under your control and are not deleted when their source submission is deleted from html.contact. Google’s own privacy terms apply to information stored there.
We do not sell Google user data, use it for advertising, or use it to train generalized AI or machine-learning models. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Cookies And Similar Technologies
html.contact may use necessary cookies and browser storage for login, sessions, security, preferences, dashboard operation, and first-party referral attribution for signup credits or promotions.
We do not use advertising cookies or cross-site advertising trackers.
html.contact is an endpoint service. It does not automatically embed cookies, trackers, scripts, or banners on customer websites. Customers are responsible for their own website notices, cookie disclosures, form labels, and consent requirements.
How We Share Information
We share information with service providers that help operate html.contact. These include infrastructure, billing, analytics, uptime/status, and email-alias providers. See Subprocessors.
We may also disclose information when needed to:
- Provide support or respond to a request.
- Process billing through Stripe.
- Send operational emails.
- Investigate abuse, security incidents, fraud, spam, or policy violations.
- Comply with law, legal process, or enforceable government requests.
- Protect html.contact, customers, end users, or the public.
- Transfer the service in connection with a merger, acquisition, financing, reorganization, or sale of assets.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
Storage And International Processing
html.contact is operated from the United States. Information may be processed in the United States and in other locations where our service providers operate.
The service is U.S.-first at launch. We do not claim EU data residency or broad enterprise EU/UK compliance coverage at launch. If your organization needs a DPA, email legal@html.contact.
Retention, Export, And Deletion
Submission persistence is a core product feature. We store submissions so customers can view, export, and manage them.
Customers can export forms and submissions through available product features. Account access, correction, export help, and deletion requests can be sent to support@html.contact. Privacy-specific questions can also be sent to privacy@html.contact.
Deletion may exclude limited records retained for security, abuse prevention, billing, tax, accounting, legal, audit, or compliance reasons.
We do not promise an automatic inactivity deletion policy at launch.
Security
We use technical and organizational measures designed to protect the service. See the Security page for details.
No internet service can guarantee perfect security. You are responsible for protecting your account, using strong passwords, keeping private API keys secret, and never placing hc_live_ keys in browser code.
Children
html.contact is not intended for children and must not be used to collect children’s data.
Your Choices And Requests
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of certain personal information. Send requests to support@html.contact. We may need to verify your identity or account ownership before acting on a request.
End users who submitted a form on a customer website should contact the website or organization operating that form first.
Changes
We may update this Privacy Policy from time to time. If changes are material, we will provide notice by email, in-app notice, or another reasonable method.
Contact
For privacy questions, email privacy@html.contact. For support, access, export, or deletion requests, email support@html.contact.
Written correspondence may be sent to:
854 Labs LLC
5534 Saint Joe Road
Fort Wayne, IN 46835
United States