Where submissions live
Open your project, click Analytics in the sidebar, then the Forms sub-tab. You’ll see:- Each form on your site as its own record, with a running submission count. Forms register themselves automatically the first time they receive a submission.
- The Submissions panel — every captured lead, newest first, with the fields the visitor filled in.
Work the inbox
The Submissions panel is built to be triaged like an email inbox:- Search across everything a visitor typed, plus form names.
- Filter by status (New, Read, Responded, Spam, Archived), by form, by Has email, or by In CRM.
- Bulk actions — select submissions and choose Mark as spam, Not spam, Archive, or Delete.
Delete removes a submission from your list but keeps the underlying analytics event, so your form conversion numbers stay accurate. It does not delete a CRM contact the submission may have already created. An Undo link appears for 10 seconds after deleting.
Choose who gets notified
Click Notifications in the Forms tab.1
Set project-wide recipients
Under Send every submission to, enter up to 10 comma-separated email addresses. These apply to every form on the project unless a form overrides them.
2
Add a Slack webhook (optional)
Paste a
hooks.slack.com webhook URL. Submissions post to Slack alongside the email — it does not replace it.3
Override per form
Each form in the Per form list can have its own recipients, and its own Notifying / Muted toggle. Muting a form stops the email only — the submission is still captured and still appears in the tab. To stop capturing a form, see Choose which forms Hiveku captures.
Choose which forms Hiveku captures
By default Hiveku captures every form on your deployed site. That suits a marketing site, where almost every form is an enquiry. It does not suit a web app: sign-in screens, password resets, admin pages and the details your own users type into the app are not leads, and capturing them turns each one into a CRM contact, a notification email, a workflow run and possibly an ad conversion. Open your project, click Analytics, then Forms, then Capture. Every setting there applies from the next submission, with nothing to deploy.Capture settings only apply to forms Hiveku captures automatically on your deployed site. Hosted Hiveku forms, and forms your site sends to a workflow’s webhook address, are never affected.
The capture switch
Capture is on by default. Switched off, Hiveku captures no form on the site automatically. The switch overrides every other setting on this page, including markup in your site’s code.Site type: Marketing site or Web app
- Marketing site (the default): every form is captured except the ones you exclude.
- Web app: only the forms you choose are captured, meaning forms set to Always, forms on pages an include path rule matches, and forms marked
data-hiveku-capture="on"in your site’s code. Everything else is skipped.
Skip sign-in and password forms
On by default. Hiveku skips a submission that carries only sign-in details (an email address or username, a password, a code) and nothing that reads as a name, phone number, company or message, when it:- comes from a sign-in, sign-out or password page: an address ending in
/login,/log-in,/signin,/sign-in,/wp-login,/logout,/log-out,/signout,/sign-out,/forgot-password,/reset-passwordor/password-reset(a file extension such as.phpmakes no difference), or any address withauthorpasswordas a whole part of it, such as/auth/callbackor/users/password/new; - is sent to a sign-in address; or
- includes a password field.
Path rules
A path rule excludes or includes every form on the pages it matches. A site can have up to 50.- Rules start with
/. Capital letters, a trailing slash and anything after?are ignored. - A rule matches the page the form was on, not the address the form sends its data to.
- Not allowed:
/*or*on their own (use the capture switch or the Web app site type instead),**, full web addresses,?,#and spaces. - When several rules match a page, the most specific one wins, so you can exclude
/portal/*and still include/portal/contact. When an exclude and an include are equally specific, the exclude wins.
Always, Never or Default for one form
Each form in the Capture list has its own setting:- Always: captured, even on a Web app site, on a page a path rule excludes, or when it looks like a sign-in form. Only the capture switch and
data-hiveku-capture="off"in your code override it. - Never: not captured.
- Default: follows the site type, Skip sign-in and password forms and your path rules.
Why a form is or is not captured
Each form in the Capture list shows its status and the reason. Mixed means some of its submissions are captured and some are not, for example the same form on several pages when a path rule excludes only some of them.
When settings disagree, the most specific wins, in this order: the capture switch, then markup in your site’s code, then the form’s own setting, then Skip sign-in and password forms, then the most specific path rule, then the site type. If none of them applies, the form is captured.
Opt a form in or out in code
A developer can mark a form in your site’s code:data-hiveku-capture="off" is honoured by every Hiveku script on the page, including Hiveku Analytics. Use it for search boxes, filters and anything else that is not a lead. data-hiveku-capture="on" is how a web app keeps its real lead forms. The markup beats a form’s own setting and every path rule; only the capture switch overrides it.
A form with no <form> element that your code sends with window.hivekuCaptureForm(fields, name) counts as opted in, so it is captured on a Web app site too.
Markup arrives with your site’s next deploy. On pages that also run Hiveku Analytics, allow up to a day for visitors’ browsers to pick up the updated analytics script.
When changes take effect
- New submissions: immediately, with no deploy.
- Analytics reports: within about a minute.
- Ad conversions: conversions waiting to be sent for a form you just excluded are held back automatically. Conversions already sent to an ad platform stay there.
- Submissions captured before the change: they stay until you erase them.
Erase submissions captured by mistake
Changing a setting does not remove what was already captured. Erase permanently removes the captured submissions your current settings exclude, so change the setting first, then erase. To erase one form’s submissions, set that form to Never (or exclude its pages), then use Erase. Erase removes:- the automatically captured submissions your current settings exclude, including any you had marked as spam or deleted from the list;
- the files visitors uploaded with them;
- the form notes on your CRM contacts;
- ad conversions still waiting to be sent for them;
- the submitted details kept in your workflows’ run history;
- CRM contacts that exist only because of those submissions. A contact with any other history (a deal, an email, another form) is kept.
- notification emails already sent;
- conversions already sent to an ad platform (Meta does not allow deleting them);
- visitors Hiveku Analytics already identified from these forms;
- changes these submissions made to contacts that existed before them;
- the copy of each submission kept with your site’s analytics.
Muting a form is not the same as not capturing it
Muting a form under Notifications stops the email only. A muted form is still captured: it still creates CRM contacts, runs your workflows and can send ad conversions. To stop that, use the Capture settings above.Spam protection
Form spam protection has two layers: built-in scoring that is always on, and optional Google reCAPTCHA you can switch on per site.Built-in scoring (always on)
Every captured submission is checked for bot fingerprints at the moment it arrives — things like a filled honeypot field, a form submitted faster than a human can type, bursts of submissions from one source, link-only message bodies, and disposable email domains. Analytics and ad-pixel beacons that disguise themselves as form submissions are caught too. Submissions that score as spam are filed under the Spam filter in the Submissions panel. A spam-filed submission is never emailed to you, never added to your CRM, and never triggers a workflow — but it is also never deleted. If a genuine lead lands there, select it and click Not spam: it returns to your inbox and the notification email is delivered within a few minutes.Google reCAPTCHA (optional)
For sites getting hit harder, add invisible reCAPTCHA scoring on top:1
Turn it on
Go to Hosting → Integrations in your project and toggle Form spam protection on. The setting is per environment, so enable it for the environment you care about — usually production.
2
Pick a sensitivity
- Lenient — only certain spam is filed. Right for a high-value, low-volume form where a missed lead is expensive.
- Balanced — recommended for most forms. The default.
- Strict — files borderline submissions too. For a form that is actively being hammered.
3
Deploy
The protection attaches at build time, so click Deploy after enabling it.
Nothing is ever deleted by spam protection at any sensitivity. Filed submissions stay under the Spam filter and are one click from restored.
Escalate a single hammered form
If one specific form keeps attracting bots, you can require a visible “I am not a robot” checkbox on just that form: open Forms → Notifications, find the form in the Per form list, and tick Require a visible “I am not a robot” checkbox on this form.File uploads
Any form on a deployed site can accept files (resumes, photos, PDFs, quote attachments) with no extra setup. The files are stored by Hiveku and travel with the submission.Add a file field
Put a named file input inside the form, exactly like any other field:multiple) and for the starter template’s FileUpload component. If you build sites with the Hiveku coding agent or the Claude Code plugin, they already know this rule.
What visitors see
When a visitor picks a file, it uploads in the background with a plain status line under the input (“Uploading resume.pdf 42%”, then “resume.pdf ready”). The submit button waits until every file has finished, and the form then submits as usual. An upload that fails never blocks the lead: the submission still arrives, without that file.Limits
The file type is taken from the extension and verified against the file’s contents before anything is stored. Under Forms → Notifications → Uploads you can switch uploads off for a project, narrow the accepted types, raise or lower the size limit and change the retention period.
Where the files appear
- Analytics → Forms: each submission lists its files with size and a Download link.
- Notification email: the files arrive as real attachments, up to 5 files or 25 MB per email. Larger sets are listed by name with a link to the Forms tab.
- CRM contact: an Attachments section on the contact, plus document links on the form activity card in the contact’s timeline.
- Workflows: the form-submitted trigger exposes
{{trigger.attachments}}(name, size, type and a download link valid for 24 hours), and the Send Email node has an Attach form files toggle.
Retention and removal
Files are kept for one year by default (adjustable between 30 days and one year per project). Deleting a submission removes its files after 7 days; deleting a project or an account removes them with it. A file that has been removed shows as Expired in the Forms tab, or as Removed: malware detected when the scanner flagged it.Opting out of uploads
To keep Hiveku from uploading files from a particular form or input, adddata-hiveku-uploads="off" to the <form> or to the <input>. The submission is still captured; only the file handling is skipped. To stop Hiveku capturing a form at all, use data-hiveku-capture="off" instead: see Opt a form in or out in code.
Malware scanning
Every uploaded file is scanned for malware after it lands. A file becomes downloadable once its scan is clean, usually within a few minutes; until then the Forms tab and the CRM show Scanning for malware, and the notification email waits up to 10 minutes for the verdict before going out without the file (it stays downloadable from the Forms tab afterwards). A file the scanner could not read (for example a password-protected document) is delivered with a Could not be scanned note. A file the scanner flags is removed immediately and shown as Removed: malware detected; nothing is delivered.Duplicate prevention
One physical submission produces exactly one lead. A single form submit can be observed more than once — by the page script and by your site’s backend, for example — and repeat submits of identical content within a few minutes are common. Hiveku links these captures together automatically, so you see one row in the Submissions panel, receive one notification email, and get one CRM contact. URL variations of the same page (like a trailing slash) count as the same form, not two separate records.Troubleshooting
A real lead was filed as spam
A real lead was filed as spam
Open the Submissions panel, set the status filter to Spam, select the submission, and click Not spam. It moves back to your inbox and the notification email is delivered within about 5 minutes. If it happens repeatedly on the same form, switch the sensitivity to Lenient under Hosting → Integrations.
Spam is still getting through
Spam is still getting through
Switch the sensitivity to Strict under Hosting → Integrations, and add the visible checkbox to the specific form being targeted (see above). Remember to Deploy after changing the Hosting toggle — the protection attaches at build time.
I'm not receiving notification emails
I'm not receiving notification emails
Check three things in Forms → Notifications: that recipients are set (if none are, submissions fall back to the address shown in the hint), that the form isn’t Muted in the Per form list, and that the submission didn’t land under the Spam filter. If no submission arrived at all, check that the form is still captured under Forms → Capture.
A form stopped receiving submissions
A form stopped receiving submissions
Open Analytics → Forms → Capture and find the form. Its status and reason show whether a capture setting now skips it: the capture switch, a path rule, the Web app site type, Skip sign-in and password forms, or the form set to Never. Set the form to Always to capture it again from its next submission.
Sign-ins or an app's own screens show up as leads
Sign-ins or an app's own screens show up as leads
Your site is probably a web app on the Marketing site default. Set your real lead forms to Always, switch the site type to Web app (or exclude the app’s pages with a path rule), then use Erase to remove what was already captured.
A submission arrived without its file
A submission arrived without its file
Check that uploads are switched on under Forms → Notifications → Uploads, that the file type and size are within the limits above, and that the form or input does not carry
data-hiveku-uploads="off". A site that submits the form from code while an upload is still running sends the lead without the file; let the visitor press the submit button instead.What’s Next?
Leads to CRM
Auto-create tagged CRM contacts from form submissions
AI Form Response
Send an instant AI-drafted reply to every new lead
Track Analytics
See the traffic behind your form conversions
CRM Contacts
Manage the pipeline your leads flow into