Privacy by design · Data-minimizing · no account

Your signatures stay your business.

PetiForm is built so that captured personal data does not travel to us during offline use in the first place. It stays local on your device and only leaves it as the signature list you create yourself as a PDF – or, when online sync has been actively booked, deliberately through the connection designed for that purpose.

Data stays local Data-minimizing under the GDPR No account required
Tablet with protected document and PDF output

Privacy principles

Local instead of cloud

Captured signatures are stored exclusively on your device. In the free offline version, there is no server they would be sent to automatically.

Offline: out as a PDF

Without actively booked online sync, personal data only leaves the device in the signature list you create yourself. Sharing and backups transfer the petition – never the captured people.

Only necessary fields

Each petition type defines which fields are allowed. Strict types enforce a minimal data set – data minimization is built in, not optional.

No account. No tracking. No cloud requirement.

Privacy in PetiForm is not a setting you have to hunt for – it is the architecture. What is not transmitted during offline use cannot get lost in transit.

0 Accounts Open the app and start collecting – no registration at all.
0 Cookies No cookie banner needed, because there is simply nothing to manage.
0 Trackers No analytics scripts, no advertising, no profile about you.
0 Hidden uploads Without actively booked online sync, captured data stays in the local database.
Data flow

What stays on the device – and what leaves it

PetiForm draws a clear line between your petition and the people who sign it.

Tablet with local database, protected PDF output and petition sharing without personal data

Names, signatures and consents stay in the local database without actively booked online sync – only the PDF you create yourself goes out.

Stays on the device

  • Name, address and other details of the signers
  • The signature provided
  • Text and time of the consent given
  • The technical capture timestamp for local statistics

Leaves the device – under your control

  • The finished signature list as a PDF – triggered by you
  • When sharing by QR code or file: only the petition with its frozen template, without captured people
  • When backing up: petitions and templates, without entries
Shared QR codes and .petiform files never contain the collected signatures either. They only pass on the cause together with the related fields, so co-organizers can collect on their own device.

Built-in protection building blocks

Not an add-on, but part of the capture flow.

Data minimization

Allowed fields per petition type

The app defines which fields are permitted for each type. For strict types such as a citizens' initiative, the data set is limited to what is legally necessary – surname, first name, date of birth, address, date and signature. Additional fields cannot even be added there. For strict types, a GDPR notice also points out the data minimization principle.

Minimal data set enforced GDPR notice

Consent is logged

For every entry, the accepted consent text is recorded together with the timestamp – documented in a traceable way, without this data leaving the device.

Duplicate protection

PetiForm detects duplicate entries during capture based on identity details – every voice counts exactly once, and the list stays clean.

Required-field checks instead of gimmicks

PetiForm checks that all required fields are filled in. By design, there is no double opt-in, no email verification and no identity validation – so there is no additional data collection beyond what the signature list requires.

Duplicate check Required-field check Consent documented
Scenario

What your collection day at an information booth could look like

Four moments where protection simply runs along with the process – without you having to think about it.

1

Consent recorded

Someone signs at your booth – PetiForm records the consent text and timestamp directly with the entry.

2

Duplicate protection checks immediately

During capture, the app compares the identity details – duplicate votes never arise in the first place.

3

The entry stays local

Even in a dead zone with no signal at all: every entry first lands in the database on your device.

4

In the evening: the PDF

You create the signature list yourself – without actively booked online sync, this PDF is the path by which data leaves the device.

Field control

For each field, you decide: show or hide

Visibility can be set per field – on the PDF list and in the public area.

On the PDF list

For each field, you can define whether it appears in the generated PDF. That way, the list shows only what it needs to show.

Reduced for public views

For public views, the data set can be reduced – for example, showing only city and date instead of the full address.

Email private by default

You decide per field what appears publicly – by default, nothing. For sensitive fields such as email, the app warns you before you show them publicly.

Compared

Paper list, cloud tool – or PetiForm

The same five questions – where is the data stored, do you need an account, who checks duplicates, is consent documented, what leaves the device when sharing?

Paper list

  • The data sits as a loose stack of paper at the booth – every glance sees all previous entries
  • No account, but no checks either: duplicates only become visible when everything is typed up at the end
  • Consent text and timestamp usually are not recorded anywhere
  • Sharing means handing over the entire list with all personal data

Typical cloud tool

  • Signer data lives on third-party servers – outside your control
  • Accounts and cookies are usually the ticket in, often with tracking on top
  • Whether duplicates are checked and consents are documented cleanly depends on the provider
  • The platform decides what is transferred when sharing – not you

With PetiForm

  • The data is stored in the local database on your device
  • No account required – open the app and start collecting
  • Duplicate protection checks during capture
  • Consent is logged with text and timestamp
  • When sharing, only the petition leaves – never captured personal data

When you go online

Online sync is an optional, bookable feature of the planned paid tiers – not a default setting. Anyone who wants to connect multiple devices actively chooses to do so. When sync is used, the data flows through servers in the EU (Germany).

The planned approach is a page vault: only protected PDF pages of the signature list generated by the device are synced. Without actively booked online sync, PetiForm remains in local offline mode.

PetiForm is currently fully offline.

Always voluntary Servers in the EU (Germany) Bookable, not automatic
See planned tiers

Self-hosting for full data sovereignty

Organizations can run PetiForm on their own infrastructure via Docker image on the "Organization" tier. Then the data lives wherever your organization decides – maximum control instead of relying on third parties.

Docker image Your infrastructure Full data sovereignty −20 %

Like all paid tiers, self-hosting is currently a preview and is not yet bookable.

For organizations
Honestly: PetiForm's protection is based first and foremost on the fact that data is not transmitted during offline use, but stays local. Codes used for sharing are lightly obfuscated so that content is not casually readable – but this is deliberately not a high-security confidentiality mechanism. For sensitive lists: keep your device and the PDFs you create safe.

For sensitive lists, we recommend

  • Enable the device lock – PIN, fingerprint or face recognition protect the local database too
  • Store generated PDFs securely and share them only deliberately – offline, they are the path by which data leaves the device
  • Back up and share calmly: backups and shared codes do not contain entries anyway
Multiple devices sharing a petition by QR code, protected by a lock symbol
Only the petition is shared – never captured personal data.

The legal details

This page explains how PetiForm protects data. The full, legally binding version is in the privacy policy.

Go to the privacy policy

Still have questions?

What gets uploaded? Do I need an account? Is the list accepted? We answer the most common questions compactly.

Go to the FAQ

Privacy that simply runs along with your work.

Start for free – data-minimizing, offline and without an account.