FormGuard — Security & Privacy Overview

LidaBan Studio · formsuite.dev/formguard · Prepared for district procurement review · October 2026

Product

Google Forms™ add-on (Google Workspace Marketplace): response caps, per-option quotas, scheduled close/reopen, owner alerts.

Data collected

None. No student or respondent data is read, transmitted, stored, or logged by the vendor.

Architecture: zero data collection

Configuration storageAll FormGuard settings are stored as properties inside the customer's own Google Form — within the district's Google Workspace tenant, under district control.
External callsThe add-on runtime performs no external network requests. There is no vendor server in the data path.
Response dataForm responses are never read. The add-on toggles form acceptance and option visibility only.
NotificationsOptional alerts are sent by the form owner's own Google account to recipients the owner chooses.

Privacy agreements & compliance

CA-NDPACalifornia Student Data Privacy Agreement v1.5 fully executed with San Bernardino City USD via CITE Privacy Services — Document Ref GMWHH-DGNBA-TUZMK-XBM4S, term through September 26, 2029. Exhibit E piggyback available to California districts.
MarketplacePublished on Google Workspace Marketplace (Google-run security review of OAuth scopes; single sign-on via district Google accounts; no separate student login).
FERPA/COPPA postureNo education records or personal information are collected, so no data-processing beyond the executed DPA scope occurs.

Permission scopes (all Google-verified at install)

Full purpose-by-purpose list: formsuite.dev/formguard/permissions.html

Operations

Support & incidentslidaban2025@gmail.com — acknowledged within one business day; security incidents reported to affected LEA contacts within 72 hours of confirmation.
Change practiceVersioned releases; behavior changes documented on the public changelog; no data model changes possible by design (no vendor-side data store).
SubprocessorsNone for the add-on's core function. Payment/licensing (optional Pro tier) is handled by Creem (Merchant of Record) and involves license keys only — never student data.