OZY Forms is a complete form builder for WordPress. Conditional logic, multi-step forms, file uploads, digital signatures, calculations, payments, entry management and integrations are all included — there is no pro tier, no addon store and no feature locked behind an upgrade prompt.
Most form plugins save every submission to your database and never mention it. OZY Forms tells you what it keeps, per form, and lets you change it.
New forms store submissions, so the entry list, exports, analytics and AI insights all work immediately. Any form can be switched to email-only or metadata-only in its Data & Privacy tab — and before that change is applied, the plugin shows you exactly which features it turns off, which ones keep working, and confirms that existing entries are untouched and the change is reversible.
Alongside that, each form controls whether IP addresses are stored at all (off, hashed, or full — hashed by default), whether browser and referrer details are kept, and whether entries are deleted or anonymised automatically after a set number of days. The plugin also contributes accurate text to your site’s privacy policy draft, generated from how your forms are actually configured rather than a fixed claim.
Out of the box, OZY Forms contacts nothing. Every external service listed below is opt-in and requires you to supply your own credentials. There is no telemetry, no phone-home and no tracking of any kind.
OZY Forms contacts nothing on its own. It has no telemetry, no phone-home, no analytics call-back and no tracking of any kind. Every service listed below is optional: it is contacted only after you have entered your own credentials for it and switched it on, and only for the purpose described next to it. If you configure none of them, this plugin makes no outbound requests at all.
On WordPress 7.0 and later the AI features prefer the AI Client built into WordPress. In that case this plugin sends the request to core, and core sends it to whichever provider you configured under Settings Connectors; the terms and privacy policy of that provider apply, and no credentials are stored by this plugin. The providers below are the fallback, used only when you enable an AI feature and save your own API key for one of them. What is sent: the prompt you type when generating a form or an email template, and the stored field values of the entries you ask it to summarise, tag or analyse. Sent when you press the relevant button in the admin, or on submission if you turn on AI spam checking.
Used only when a form contains a payment field and you have saved that gateway’s keys. Card details are entered inside the provider’s own iframe or SDK and go straight from the visitor’s browser to the provider; this site never receives them. What this site sends: the amount, the currency, the payment token returned by the provider, and the billing name and email if your form collects them. Sent when a form with a payment field is submitted.
Used only when you switch the built-in SMTP on and pick a provider. What is sent: the notification, autoresponder or test email your site produces, which means the recipient addresses, the subject, the message body and any attachments you have configured, delivered over an authenticated SMTP connection using the credentials you entered. Sent when the plugin sends an email.
Used only for a service you connect with your own credentials and then enable on a specific form. What is sent: the submitted field values you map to that service’s fields, plus the form name and the submission time. Sent when a submission on that form succeeds.
Used only after you save that service’s keys under OZY Forms Settings and a form actually uses it.
A CAPTCHA has two halves. The provider’s widget script is loaded into the visitor’s browser from the provider’s own domain, which is how the challenge is drawn and is also a request that tells the provider a page was viewed. The token it produces is then posted from this site to the provider’s verification endpoint, together with your secret key, when the form is submitted. Nothing else about the submission is sent.
Akismet is checked from this site only, with no browser-side component. What is sent: the submitted field values, the visitor’s IP address, user agent and referrer, and your site address. Sent when a form is submitted, and once more when you save the key so it can be confirmed.
The default anti-spam layer is a honeypot field and a local maths question. Neither contacts anything, and a form falls back to the maths question whenever the chosen CAPTCHA provider has no keys saved.
Two features need code served by the provider rather than by this site, because the provider will not accept data collected any other way. They load only on a page carrying a form that uses them.
Nothing else in this plugin loads code from anywhere but your own site.