TL;DR: You can now encrypt form submissions. Choose between server-side encryption (we protect your data) or public-key encryption (only you can read it).

Why Encryption Matters

If you collect sensitive information - client details, medical inquiries, legal requests, financial data - you want that data protected. Encryption ensures that even if someone gained unauthorized access to the database, they’d only see gibberish.

This is especially relevant for GDPR compliance, healthcare providers, legal professionals, and anyone handling confidential client communications.

Three Encryption Modes

When you create a new form, you can now choose how submissions are protected:

None (Default)

This is how Formshive has always worked. Submissions are stored as-is. This is fine for non-sensitive data like newsletter signups or general inquiries.

Server Encryption

We encrypt your submissions before storing them. When you view them in the dashboard, we decrypt them for you automatically.

Think of it like a bank vault: your data is locked away securely, and we handle the keys. This protects against database breaches while keeping all features working normally.

Public-Key Encryption (Nostr)

This is the most private option. The server encrypts submissions with your public key, and only your private key can decrypt them.

This feature is powered by the Nostr standard, which means it works with Nostr browser extensions (like Alby or nos2x) that manage your keys automatically. You don’t have to handle encryption keys manually - your browser extension takes care of it.

The data is briefly visible to the server during processing (for validation, etc.). Once stored, even we can’t read your submissions - only you can unlock them.

  1. Form submission to server (TLS encrypted)
  2. Server encrypts submission with your public key
  3. Encrypted submission stored in database
  4. You view submission in dashboard and decrypt it with your private key (via browser extension)

Requirements:

  • You must be logged in with Nostr (not email)
  • You need a Nostr browser extension like Alby or nos2x

What Works With Each Mode

Not all features work with every encryption mode. Here’s what to expect:

Feature None Server Public-Key
Email notifications with content Yes Yes No*
Auto-response emails Yes Yes No
Webhooks with submission data Yes Yes No*
Integrations (Pipedream, etc.) Yes Yes No*

*With public-key encryption, you can still receive notifications and webhook calls, but they won’t include the submission content (since we can’t read it). You’ll get a link to view and decrypt the submission in your dashboard.

Important Notes

  • Choose wisely: The encryption mode is set when you create the form and cannot be changed later
  • File uploads: Attached files are stored separately and are not encrypted, regardless of which mode you choose
  • Lost keys: With public-key encryption, if you lose access to your private key, your submissions are gone forever - we cannot recover them

How to Use Encryption

  1. Go to your dashboard and click New Form
  2. In the form settings, look for Encryption Mode
  3. Select your preferred option:
    • None for standard forms
    • Server for encrypted storage with full features
    • Public-Key for maximum privacy (requires Nostr login)
  4. Save your form and start collecting submissions

For public-key encrypted forms, you’ll see a Decrypt button when viewing submissions. Click it, and your browser extension will unlock the content.

Which Mode Should You Choose?

  • Newsletter signups, feedback forms: None is fine
  • Contact forms, business inquiries: Server encryption adds peace of mind
  • Sensitive data, privacy-critical applications: Public-key encryption if you need maximum security and can accept the trade-offs

Encryption is available now for all Formshive accounts. Create a new form to try it out.