OZY Forms Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
OZY Forms is a complete form builder for WordPress. Conditional logic, multi-step forms, file uploads, digital signatures, calculations, payments, entry management and integrations are all included — there is no pro tier, no addon store and no feature locked behind an upgrade prompt.
What it does
- Drag and drop builder with 48 field types, from plain text through to signatures, repeaters, calculations and product fields.
- Conditional logic with nested AND/OR groups, 15 operators and 10 actions. Evaluated in the browser for responsiveness and again on the server, which is what actually decides.
- Multi-step forms with 8 progress indicator designs, per-step server validation, and Save & Resume.
- Calculations using a spreadsheet-style formula language with 14 functions.
- Payments through Stripe, PayPal, Razorpay, Square, Mollie or Authorize.Net. Card details are entered into the provider’s own iframe and never touch this site.
- Built-in SMTP for 11 providers, so a separate mail plugin is not required. Queued delivery, retries with backoff, and a delivery log.
- 20 email designs plus a template library, autoresponders and conditional routing.
- AI features — generate a form from a description, summarise and tag submissions, find themes across responses, generate email templates. On WordPress 7.0 and later these run through the AI Client in core, so whichever provider you connect once under Settings Connectors is the one they use. On older versions, or if no connector is set up, you can save your own key for OpenAI, Anthropic, Groq, Gemini or Mistral instead.
- Migration from Gravity Forms, WPForms, Fluent Forms, Formidable, Contact Form 7, Ninja Forms, Forminator and Everest Forms — read-only, with a preview and a full undo.
- 30 integrations including Zapier, Make, Mailchimp, HubSpot, Google Sheets, Airtable, Notion, Slack, Discord, Telegram, Twilio, Trello, Asana, ClickUp, monday.com, Salesforce, Zoho, Pipedrive and generic webhooks.
- Page builders — Gutenberg block, Elementor, Divi, WPBakery, Beaver Builder, Oxygen, Bricks, Avada, Brizy, plus a shortcode and a classic widget.
You decide what gets stored
Most form plugins save every submission to your database and never mention it. OZY Forms tells you what it keeps, per form, and lets you change it.
New forms store submissions, so the entry list, exports, analytics and AI insights all work immediately. Any form can be switched to email-only or metadata-only in its Data & Privacy tab — and before that change is applied, the plugin shows you exactly which features it turns off, which ones keep working, and confirms that existing entries are untouched and the change is reversible.
Alongside that, each form controls whether IP addresses are stored at all (off, hashed, or full — hashed by default), whether browser and referrer details are kept, and whether entries are deleted or anonymised automatically after a set number of days. The plugin also contributes accurate text to your site’s privacy policy draft, generated from how your forms are actually configured rather than a fixed claim.
Privacy and external services
Out of the box, OZY Forms contacts nothing. Every external service listed below is opt-in and requires you to supply your own credentials. There is no telemetry, no phone-home and no tracking of any kind.
External Services
OZY Forms contacts nothing on its own. It has no telemetry, no phone-home, no analytics call-back and no tracking of any kind. Every service listed below is optional: it is contacted only after you have entered your own credentials for it and switched it on, and only for the purpose described next to it. If you configure none of them, this plugin makes no outbound requests at all.
AI providers
On WordPress 7.0 and later the AI features prefer the AI Client built into WordPress. In that case this plugin sends the request to core, and core sends it to whichever provider you configured under Settings Connectors; the terms and privacy policy of that provider apply, and no credentials are stored by this plugin. The providers below are the fallback, used only when you enable an AI feature and save your own API key for one of them. What is sent: the prompt you type when generating a form or an email template, and the stored field values of the entries you ask it to summarise, tag or analyse. Sent when you press the relevant button in the admin, or on submission if you turn on AI spam checking.
- OpenAI – api.openai.com – Terms – Privacy
- Anthropic – api.anthropic.com – Terms – Privacy
- Groq – api.groq.com – Terms – Privacy
- Google Gemini – generativelanguage.googleapis.com – Terms – Privacy
- Mistral – api.mistral.ai – Terms – Privacy
Payment gateways
Used only when a form contains a payment field and you have saved that gateway’s keys. Card details are entered inside the provider’s own iframe or SDK and go straight from the visitor’s browser to the provider; this site never receives them. What this site sends: the amount, the currency, the payment token returned by the provider, and the billing name and email if your form collects them. Sent when a form with a payment field is submitted.
- Stripe – api.stripe.com – Terms – Privacy
- PayPal – api-m.paypal.com – Terms – Privacy
- Razorpay – api.razorpay.com – Terms – Privacy
- Square – connect.squareup.com – Terms – Privacy
- Mollie – api.mollie.com – Terms – Privacy
- Authorize.Net – api.authorize.net – Terms – Privacy
Email delivery (SMTP)
Used only when you switch the built-in SMTP on and pick a provider. What is sent: the notification, autoresponder or test email your site produces, which means the recipient addresses, the subject, the message body and any attachments you have configured, delivered over an authenticated SMTP connection using the credentials you entered. Sent when the plugin sends an email.
- Gmail / Google Workspace – smtp.gmail.com – Terms – Privacy
- Outlook / Microsoft 365 – smtp.office365.com – Terms – Privacy
- SendGrid (Twilio) – smtp.sendgrid.net – Terms – Privacy
- Mailgun – smtp.mailgun.org or smtp.eu.mailgun.org – Terms – Privacy
- Amazon SES – email-smtp.REGION.amazonaws.com – Terms – Privacy
- Postmark – smtp.postmarkapp.com – Terms – Privacy
- Brevo – smtp-relay.brevo.com – Terms – Privacy
- Elastic Email – smtp.elasticemail.com – Terms – Privacy
- Mailjet – in-v3.mailjet.com – Terms – Privacy
- SMTP2GO – mail.smtp2go.com – Terms – Privacy
- Custom SMTP – the host you enter yourself. The terms and privacy policy of that host’s operator apply.
Integrations
Used only for a service you connect with your own credentials and then enable on a specific form. What is sent: the submitted field values you map to that service’s fields, plus the form name and the submission time. Sent when a submission on that form succeeds.
- Zapier – hooks.zapier.com, at the Zap webhook URL you paste in – Terms – Privacy
- Make – the Make webhook URL you paste in – Terms – Privacy
- Mailchimp – your data centre host at api.mailchimp.com – Terms – Privacy
- ActiveCampaign – the account API URL you enter – Terms – Privacy
- HubSpot – api.hubapi.com – Terms – Privacy
- MailerLite – connect.mailerlite.com – Terms – Privacy
- Brevo – api.brevo.com – Terms – Privacy
- Constant Contact – api.cc.email – Terms – Privacy
- GetResponse – api.getresponse.com – Terms – Privacy
- Drip – api.getdrip.com – Terms – Privacy
- Kit (formerly ConvertKit) – api.convertkit.com – Terms – Privacy
- Google Sheets – sheets.googleapis.com and oauth2.googleapis.com – Terms – Privacy
- Airtable – api.airtable.com – Terms – Privacy
- Notion – api.notion.com – Terms – Privacy
- Slack – the incoming webhook URL you paste in – Terms – Privacy
- Discord – the webhook URL you paste in – Terms – Privacy
- Telegram – api.telegram.org – Terms – Privacy
- Twilio – api.twilio.com – Terms – Privacy
- MessageBird (Bird) – rest.messagebird.com – Terms – Privacy
- Vonage – rest.nexmo.com – Terms – Privacy
- Trello – api.trello.com – Terms – Privacy
- Asana – app.asana.com – Terms – Privacy
- ClickUp – api.clickup.com – Terms – Privacy
- monday.com – api.monday.com – Terms – Privacy
- Salesforce – the instance URL you enter – Terms – Privacy
- Zoho CRM – the API domain you enter – Terms – Privacy
- Pipedrive – your company subdomain at pipedrive.com – Terms – Privacy
- Freshsales – the Freshworks domain you enter – Terms – Privacy
- Webhook and Custom API – the URL you enter yourself. Nothing is sent anywhere else; the terms and privacy policy of whatever endpoint you point it at apply.
Spam protection
Used only after you save that service’s keys under OZY Forms Settings and a form actually uses it.
A CAPTCHA has two halves. The provider’s widget script is loaded into the visitor’s browser from the provider’s own domain, which is how the challenge is drawn and is also a request that tells the provider a page was viewed. The token it produces is then posted from this site to the provider’s verification endpoint, together with your secret key, when the form is submitted. Nothing else about the submission is sent.
- Google reCAPTCHA – script from www.google.com/recaptcha/api.js, verified at www.google.com/recaptcha/api/siteverify – Terms – Privacy
- hCaptcha – script from js.hcaptcha.com/1/api.js, verified at api.hcaptcha.com/siteverify – Terms – Privacy
- Cloudflare Turnstile – script from challenges.cloudflare.com/turnstile/v0/api.js, verified at challenges.cloudflare.com/turnstile/v0/siteverify – Terms – Privacy
Akismet is checked from this site only, with no browser-side component. What is sent: the submitted field values, the visitor’s IP address, user agent and referrer, and your site address. Sent when a form is submitted, and once more when you save the key so it can be confirmed.
The default anti-spam layer is a honeypot field and a local maths question. Neither contacts anything, and a form falls back to the maths question whenever the chosen CAPTCHA provider has no keys saved.
Scripts loaded into the visitor’s browser
Two features need code served by the provider rather than by this site, because the provider will not accept data collected any other way. They load only on a page carrying a form that uses them.
- Payment gateways load their card entry SDK: js.stripe.com, www.paypal.com/sdk/js, checkout.razorpay.com, web.squarecdn.com (sandbox.web.squarecdn.com in test mode) and js.authorize.net (jstest.authorize.net in test mode). The terms and privacy policies are the ones listed under Payment gateways above.
- CAPTCHA providers load their widget script, listed under Spam protection above.
Nothing else in this plugin loads code from anywhere but your own site.
Screenshots
The form builder: the field library, the canvas, and the settings panel for the selected field.
The forms list, showing each form’s storage mode, submission count and shortcode.
A multi-step form on the front end, with the numbered progress indicator.
The AI generator, where a provider is connected before describing the form you want.
The entry list, filtered to one form.
The Data & Privacy tab and the storage consequences dialog.
Email and SMTP setup with delivery diagnostics.
Payment gateway configuration.
The migration screen detecting other form plugins.
A finished form on the front end.

