Legal Center
Acceptable Use Policy
Sensitive data
Because Kaptly places no system-level restriction on what a form can ask for, you agree not to use Kaptly to collect passwords, complete payment-card numbers, government identification numbers, medical records, or other highly sensitive information, unless you have independently confirmed the appropriate legal basis and safeguards are in place — which Kaptly's current beta infrastructure has not been reviewed to provide.
Illegal or harmful content
You may not use Kaptly to collect, store, or distribute content that is illegal, infringing, or intended to harass, defraud, or harm others.
File uploads and malware
Uploaded files are checked against an extension allowlist, size limit, and basic content-signature rules, but are not scanned for malware. You may not use file-upload fields to distribute malware or other harmful files.
Abuse of automations and delivery targets
Outbound webhooks, automation emails, and Slack messages may not be used to spam, phish, or otherwise abuse third parties. You may configure only webhook and Slack destinations you are authorized to use, and you are responsible for having a lawful basis to disclose any personal data inserted into an automation message. Treat every delivery URL as a credential and manage channel access and retention in the destination service.
Platform abuse
You may not attempt to bypass authentication, probe for vulnerabilities outside of a coordinated disclosure process (see Security and Responsible Disclosure), or disrupt the service for other users.
Respondent rights
If you collect personal data from respondents, you're responsible for honoring their data-subject rights (access, correction, deletion) under applicable law — Kaptly gives you the tools (per-response delete) but the obligation is yours as the form owner.
Reporting a violation
Report suspected violations to support@getkaptly.com or via Report a Problem in the product.