FillOut
FillOut.com · Productivity · US · www.fillout.com
services/fillout.yamlVendor data-handling terms
The only training statement is the Google carve-out. Training on form responses is not addressed.
“User data obtained through Google Workspace APIs will not be used to develop, improve, or train generalized AI and/or machine learning models.”
“We will only retain your Personal Data for as long as is necessary to fulfill the purposes for which it is collected, or to comply with our legal obligations.”
The policy has European and US-state sections but does not name a storage location.
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| fillout.com | app | observed |
Assessment
Reasoning: A form builder with AI features; the data at stake is form responses, which are third-party personal data for which the deploying organisation is controller. The policy does not name a storage location or address training on responses beyond the Google carve-out.
Flags: Form respondents' personal data (deployer is controller) · Storage location not stated · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Google-data and retention terms verified against the Fillout privacy policy; storage location not stated.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.