Widgy collects answers from people who aren't you, and feeds some of them straight to your AI. That only works if it's safe. Here's exactly how we look after you and your respondents — no vague 'enterprise-grade' hand-waving, just what's actually in the product.
Last updated July 2026This is the one most form builders never think about. When your AI reads responses back through MCP, respondent free-text is untrusted input from the public internet — and left unchecked, a cleverly worded answer could try to give your AI instructions it was never meant to follow.
So we defend against it in layers. Every submission is run through a strip that removes hidden and invisible characters — the tricks used to smuggle instructions past a human reader — both when it's submitted and again when your AI reads it. And when responses are handed to your AI, respondent-written fields are explicitly labelled as untrusted content, so your assistant treats them as data to record, not commands to obey.
Widgy is served over HTTPS everywhere, with HSTS preloaded so browsers refuse to connect any other way. Every response carries a tight set of security headers: a Content-Security-Policy and frame protection that stop your workspace from being embedded and clickjacked by another site, and X-Content-Type-Options: nosniff so browsers can't be tricked into misreading a file.
The two things most dangerous to get wrong, we don't build ourselves. Sign-in runs on Clerk, a dedicated identity provider — Widgy never stores your password. Payments run on Stripe, so your card number goes straight to them and is never seen or stored by us. These are the same providers trusted by companies far larger than this one.
Widgy is hosted in the European Union, and your forms and responses are stored and processed there. Your data doesn't get quietly shipped somewhere with weaker protections.
The answers your form collects belong to you. You — the person who built the form — are the only one who gets to read them, through your own dashboard or your own AI. And you're never locked in: you can delete any form and every response attached to it yourself, whenever you like. When it's gone, it's gone.
No tracking-for-tracking's-sake, no selling your data — not now, not as a business model later. We keep what's needed to run the service and nothing more. Under the hood Widgy leans on a small set of well-known providers so we're not reinventing the risky parts: hosting and your database on Railway (in the EU), sign-in on Clerk, and payments on Stripe. The full detail of what we store and why lives in the privacy policy, and the ground rules are in the terms.
No faceless corp, no support-ticket black hole. Widgy is built by one person — me, Jereth — in the open, and I put my name and my email on it because I stand behind it. If something feels off, or you just want to know how a piece of this works, write to me directly at jereth@widgy.co and you'll get a real reply from the person who built it.
Spotted something that looks like a security hole? Please tell me before anyone else — email jereth@widgy.co and I'll jump on it. Responsible disclosure is genuinely appreciated here.