FAQ
Do I need anything besides the plugin?
Yes: your own Jev API key from TypeSafe, Vercel AI Gateway or OpenRouter (or a proxy you run). It is not included, and usage is billed to you by that provider. As of 2026-09-22, TypeSafe has paused new signups, so most new users start with Vercel AI Gateway or OpenRouter. See Getting a key. Test mode works without a key.
How much does it cost to run?
As of 2026-09-22, Jev costs $0.042 per million input tokens and nothing for output. A Formsieve check sends about 1,100 to 1,500 input tokens (our estimate; about 1,300 is typical), so 1,000 checks cost about $0.055 and 10,000 about $0.55. Submissions stopped by the free pre-filters or the replay cache cost nothing. OpenRouter adds a 5.5% fee when you buy credit; Vercel charges no markup. You can cap the requests sent per form per hour and per month (a retry counts as a request, as the provider bills it). See Cost and caps.
What data is sent, and to whom?
Only after an administrator opts in: the ordinary text and choice fields of the submission (phone numbers redacted by default), the domain of the sender's e-mail address, your site and form description and a few numeric signals, over HTTPS to TypeSafe AI, Inc. (USA), directly or through the gateway you choose. Never IP addresses, full e-mail addresses, passwords, payment fields, uploads, or fields that look like health, ID or bank data. See How it works and Data processing by route.
Does it replace reCAPTCHA, Turnstile, Akismet or honeypots?
It can, and it also works alongside them. CAPTCHAs judge the visitor; Formsieve judges the message, so it also catches the human-typed sales pitches that pass a CAPTCHA. When Gravity Forms' honeypot has already flagged a submission, Formsieve makes no API call; Gravity Forms' built-in Akismet check runs after Formsieve and only sees what Formsieve allowed. When Akismet, reCAPTCHA or Turnstile has already flagged a submission, Formsieve makes no API call. Keeping a honeypot is recommended because it is free.
What happens if the API is down or slow?
Each check has a 3-second timeout and at most one quick retry. If it still fails, Formsieve fails open: the entry is saved and delivered as usual, with a Formsieve note "Not checked (API unavailable)" (Gravity Forms), or the mail is sent as usual, and the note "Formsieve: not checked (API unavailable)" is kept in Flamingo and the Formsieve log (Contact Form 7). After repeated failures it pauses calls for 10 minutes. You can choose fail closed (unchecked submissions are treated as spam) instead. See Verdict bands and actions.
Will it slow my forms down?
The check adds one API round trip to the submission (not to page loads). TypeSafe quotes 70–500 ms for Jev; the time from your server depends on your host's location and network. Formsieve shows the average and 95th-percentile latency on its dashboard.
Can a real lead be lost?
Formsieve is built to avoid it: only confident spam is blocked, the uncertain middle is delivered with a "[Possible spam NN%]" tag, and failures deliver by default. Blocked Gravity Forms entries are kept in the Spam folder (unless you chose to discard or refuse them for a form). Blocked Contact Form 7 submissions are kept in Flamingo's Spam folder when Flamingo is installed, which we recommend. No filter is perfect: check your spam folder now and then, and mark mistakes "Not spam" so Formsieve learns the sender.
How accurate is it?
We publish accuracy only for what we have measured, on the certification set described in Calibration, and only for English. Your results depend on your forms and your visitors; the dashboard's corrections count shows how it does on your site.
Does it work in languages other than English?
It checks submissions in any language, but TypeSafe says Jev is best in English and handles other languages "not equally well". Formsieve raises its thresholds slightly on non-English sites as a precaution. We make no accuracy claim for other languages yet.
Is the plugin translated?
Yes, into Spanish (Spain, es_ES). The admin screens and notices appear in Spanish when the language in your user profile (or, if it is not set, the site language) is Español; the daily error e-mail and the texts visitors see, such as the AI notice under forms, follow the site language. Contact Form 7 is different: it shows each form, including the Formsieve texts inside it, in the language the form was created in, and it stores the message shown to a refused visitor with the form (Messages tab), so check forms created before you changed the language. The translation ships in the plugin's languages folder; there is nothing to install.
For another language, translate the .pot file in that folder with a tool such as Poedit and save the compiled file in wp-content/languages/plugins/ as formsieve-for-gravity-forms-<locale>.mo (for example formsieve-for-gravity-forms-fr_FR.mo) or formsieve-for-cf7-<locale>.mo (for example formsieve-for-cf7-fr_FR.mo). Files there take precedence over the ones in the plugin and survive updates. A translated interface says nothing about filtering accuracy in that language (see above).
Can I try it without a key?
Yes. Test mode returns simulated verdicts for every submission with no API calls, shows a red badge in the admin bar and marks log rows as demo. Turn it off before relying on Formsieve.
Can I use one key on several sites?
Yes, on your own sites. Do not create several accounts with one provider to collect extra promotional credit; TypeSafe's terms forbid it.
Does it work on multisite?
It is designed for it: each site of a network keeps its own route, key, consent, settings and log, and uninstalling cleans up every site. A key defined in wp-config.php applies to the whole network, so Formsieve does not send it to a Custom base URL that a site administrator typed; set the base URL network-wide too with the FSV_GF_API_BASE constant or the fsv_gf_api_base filter (Gravity Forms) or FSV_CF7_API_BASE constant or the fsv_cf7_api_base filter (Contact Form 7) if you need that. Multisite has not been tested for version 1.0.0 yet, so try it on a staging network first.
How does Formsieve help with GDPR?
No software is compliant by itself; compliance depends on how you use it. Formsieve gives you consent before anything is sent, data minimisation, a notice for visitors, privacy-policy text, export and erasure tools and log retention, and names every company that receives data. Data is processed in the United States on every route. See Privacy kit.
Do I need Flamingo with Contact Form 7?
It is not required, but we recommend it: Contact Form 7 stores nothing by itself, so without Flamingo a blocked submission cannot be restored. With Flamingo you can read spam and mark it "Not spam".
Why does the dashboard count fewer submissions than there are log rows?
The dashboard counts what visitors submitted. Re-checks you start from an entry's Formsieve panel and WP-CLI samples are listed in the log and their API calls are included in the cost, because they were billed, but they are not counted as submissions. Test mode rows are left out of every figure. See Cost and caps.
Is the probability shown to visitors?
No, the score stays in your admin. A blocked visitor on a Gravity Forms form sees Gravity Forms' default confirmation (or your custom spam confirmation on Gravity Forms 2.10 or later), or a validation message if the form refuses spam with a validation error. A blocked visitor on a Contact Form 7 form sees a spam message from the form's Messages tab, which by default reads like a sending failure.
What does the licence cover, and do I need to activate anything?
The CodeCanyon version has no activation and no licence field; it works fully as soon as it is installed. Updates come through Envato Market or a manual download (Envato Market updates). Filtering never depends on a licence or activation.
Is Formsieve made by Gravity Forms or TypeSafe?
No. Formsieve is an independent product of Thinking42. It is not affiliated with, endorsed by, or sponsored by TypeSafe AI, Inc. or Rocketgenius, Inc.
Is Formsieve made by the Contact Form 7 team or TypeSafe?
No. Formsieve is an independent product of Thinking42. It is not affiliated with, endorsed by, or sponsored by TypeSafe AI, Inc. or Rock Lobster Inc.