HeyForm
Open-source, self-hostable form builder for conversational forms, surveys and quizzes — aimed at capturing people who are not customers yet
HeyForm is an open-source form builder for conversational forms, surveys, quizzes and polls, written in TypeScript and licensed AGPL-3.0. You can self-host it or use the maintainers' hosted service, and it covers the whole path from a branded public form to conditional logic, webhooks and a CSV export of the answers. For a founder its useful job is lead capture rather than research: waitlists, quiz-shaped lead magnets and qualification forms aimed at people who have not signed up yet.
What HeyForm is
HeyForm (github.com/heyform/heyform) is a form builder you can run yourself, built as a TypeScript monorepo with a Node server, a React web app and a standalone embed library so a form can live on your own site rather than only on a hosted link. It is maintained by a two-person team who also run the hosted version, and it has been in development since March 2024.
- Conversational forms one question at a time rather than a wall of fields, plus classic surveys, quizzes and polls.
- A wide input set text, email and phone through to picture choice, date pickers and file uploads.
- Conditional logic and redirects branch on an answer, and send people somewhere specific when they finish — the hook that turns a form into a step in a funnel.
- Integrations webhooks, analytics and marketing platforms, plus Zapier and Make.com for everything else.
- Theming down to custom CSS fonts, colours and backgrounds, so a form on your own domain does not look borrowed.
- Completion analytics and CSV export drop-off and completion rates per form, and the raw answers out to a file you own.
Two things to check before you self-host
The repo makes both of these easy to verify, and both are the kind of detail that is cheaper to read now than to discover later.
- AGPL-3.0, not MIT. Self-hosting it for your own forms is fine. Embedding it inside a product you offer to others is the case that needs a lawyer, because the network clause reaches users who never download your code.
- Run v3.0.1 or later. The commits leading up to the 3.0 releases in August 2026 are an explicit security remediation series — SSRF protection for special-purpose IPv6 targets, validation of untrusted answer and signature-image URLs, cascade handling for destructive deletions, bounded workspace-invitation fanout and safer GraphQL errors — with the fixes recorded in the project's own security docs.
- A published advisory series is a good sign, not a bad one: it means someone looked and the findings were fixed in the open. It does mean an old self-hosted copy is the version you do not want to be running.
Deployment is documented for a manual install and for one-click templates on several hosts, so the practical cost is a small container and a database rather than an afternoon. As with any self-hosted tool that collects personal data, the thing you inherit is the responsibility for it: backups, upgrades and whatever your privacy policy now has to say about where the answers live.
How a founder actually gets leads out of it
A form is not a channel. It converts attention you already have, so the growth question is always what sits immediately before it and what happens immediately after.
- Put it in front of a waitlist, not after signup the highest-value use is capturing people who are not ready to create an account. That is the same job as building a waitlist before you launch, with the answers attached.
- Make the quiz the lead magnet a short diagnostic that returns a result is one of the few lead magnets people finish, because the reward arrives immediately rather than by email.
- Ask one qualifying question, not six every extra field costs completions. Pick the single answer that would change how you follow up and drop the rest.
- Wire the webhook on day one a submission that lands in a database nobody opens is not a lead. Route it to wherever you actually reply from.
- Read the drop-off, not just the total per-question drop-off tells you which question is expensive, which is the only conversion feedback a low-traffic form can give you.
This is also the line between HeyForm and Formbricks, which we covered earlier and which is easy to confuse with it. Formbricks is built around in-product surveys aimed at people who are already users; HeyForm is built around a standalone public form aimed at people who are not. Both can be bent into the other shape, and neither is comfortable there.
What we have seen asking new signups questions
Our own intake asks one optional question with a few one-tap answers and a free line, and the distribution has been lopsided in a way that surprised us: the option that invites someone to paste a link to what they are working on is the only one that gets used with any regularity, while the more abstract choices sit at roughly zero. The sample is small enough that we would not build a strategy on the ratio, but the direction has held long enough to change what we ask.
The reading we take from it is that people answer a question when answering is easier than explaining. Pasting a URL costs nothing and carries a lot of information; picking the category you belong to requires deciding what you are, which is work. If you are designing a capture form in HeyForm, that is the cheap version of the lesson: prefer the question whose answer already exists somewhere the person can copy, and leave everything you merely want to know for a conversation later.
FAQ
- Is HeyForm a Typeform alternative?
- That is the closest comparison — the conversational, one-question-at-a-time format, branded themes and conditional logic are the same shape. The differences that matter are hosting and licence: you can run HeyForm on your own infrastructure and keep the submissions in your own database, and it is AGPL-3.0 rather than proprietary. What you take on in exchange is upgrades, backups and the operational side of holding other people's data.
- What does the AGPL licence mean for my startup?
- For running your own forms on your own site it is unremarkable. It matters when HeyForm becomes part of something you offer to other people over a network, because the AGPL's network clause can oblige you to publish source for the modified work. If you are considering embedding it in your product rather than using it, read the licence properly and take advice — this is the one decision on the page that is genuinely expensive to get wrong.
- How does it compare to just using a Google Form?
- A Google Form is faster to create and free, and for an internal survey it is usually the right answer. HeyForm earns the setup when the form is customer-facing: your domain and branding rather than Google's, conditional logic, redirect-on-completion into your funnel, and per-question drop-off data. If nobody outside your team will see it, the simpler tool wins.
- Is the project actively maintained?
- Yes, as of 2026-08-15. It shipped v3.0.0 on 2026-08-06 and v3.0.1 on 2026-08-13, and the preceding commit history is functional work rather than housekeeping — a substantial series of security fixes with the remediations documented. It is a small team, so read it as a maintained project with a narrow bus factor rather than a large one.
You built it. Now grow it.
AgentCeres is a managed AI marketing team — specialists draft the SEO, social, and outreach that fill your links, you approve what ships. 14-day free trial, from $39/month.