HTML Form Builder (Your Google Sheet as the Backend)
Drag a form together, paste it on your site — answers land in your own Google Sheet.
Form
Add a field
Press a field to add it to the form (after the open one), or drag it to its place.
Fields
After sending
Google Sheet
The answers go from the visitor’s browser straight to a Google Sheet of yours, through a small Apps Script that you add to the Sheet (see Set up). MySmartCoPilot never sees them.
Emails
File uploads
Files from upload fields are saved in a folder of your Google Drive (private to you) and linked in the row. Leave the folder empty and the script makes one when you run setup.
Spam protection
Tracking
Hidden values the form adds to each answer, from the address of the page it is on.
Look
Texts and messages
Edit or translate
What the form says to visitors. Words in braces are filled in, for example {max}.
Try your form here: the steps, conditions and checks work as on your site. Nothing is sent — the row below shows what your Sheet would get.
The preview starts in a moment.
The row your Sheet would get
| Column | Value |
|---|
Paste this into your Google Sheet: Extensions → Apps Script. It runs in your Google account and asks only for what this form needs.
Checks
Connect your Google Sheet
Accessibility
| Colours | What | Contrast | Result |
|---|
About the HTML Form Builder (Your Google Sheet as the Backend)
Build a web form by pressing or dragging fields into place — short and long answers, email, phone, numbers, dates, dropdowns, single and multiple choice, consent boxes, ratings, file uploads and hidden values — then add steps, conditional fields (“show this only when…”), checks for each answer, hidden UTM values and spam protection. A live preview runs the real form, so you can try every step and see the exact row your Sheet would get.
The builder writes two things: the form (HTML, CSS and a small script, as one snippet or as files for strict Content-Security-Policies) and a Google Apps Script that you add to your own Google Sheet. Each answer then goes from your visitor’s browser straight to that Sheet — optionally with an e-mail to you from your own Gmail and uploads saved in your own Drive. MySmartCoPilot hosts nothing and never sees the answers.
How to use it
- Pick a template (lead form, admission enquiry, event registration, GST invoice request, feedback) or start blank.
- Press a field type to add it, or drag it into place; drag the handle (or use its arrow keys) to reorder. Open a field to set its label, help text, rules and conditions.
- Add steps for longer forms, and choose what happens after sending, spam protection, tracking and the look.
- Try it in Preview: fill it in and press send — nothing is sent, and the row your Sheet would get appears below.
- Follow Set up: paste the Apps Script into your Sheet (Extensions → Apps Script), run
setup, deploy it as a web app (Execute as: Me, Who has access: Anyone) and paste the web app address into the builder. - Copy the embed code (or download the ZIP) and paste it into your site. Send the form once yourself to see the first row.
Examples
What can we help with? → Something else
A required “Tell us more” box appears; for the other choices it stays hidden and is not sent.
Submitted at | Full name | Work email | … | utm_source | utm_campaign | Page address (date and time) | Asha Kulkarni | asha@example.com | … | newsletter | spring | https://www.example.com/contact
The first row gets the column titles; a field added later gets a new column at the end, and old answers stay where they are.
29ABCDE1234F1ZX
The last character of this GSTIN does not match — check it for a typo.
The form checks the 15-character shape and the check character, in the browser and again in the Apps Script.
Common uses
- A contact or lead form on a website, a landing page or a Carrd/Wix/WordPress/Webflow site, with UTM values for campaign tracking.
- Admission enquiries for a school or coaching centre, with steps and an optional document upload.
- Event registrations with ticket types, guests and dietary needs.
- Customer feedback with satisfaction and recommendation scales.
How the answers reach your Sheet
When someone sends the form, its script posts the answers as JSON to your Apps Script web app, as plain text (a “simple” cross-site request: the browser sends it without asking first, which Apps Script could not answer). The script’s doPost checks the answers again with the same rules as the form, waits for a lock so two answers at the same moment cannot collide, and adds a row. Apps Script returns its answer through a redirect to script.googleusercontent.com, which the form follows (Google: Content Service).
- Execute as: Me runs the script under your account, so it can write to your Sheet; Who has access: Anyone lets the form post without a Google sign-in (Google: Web Apps).
- The script asks only for the permissions the form needs: e-mail sending only with notifications, Drive only with uploads, external requests only with Turnstile.
- Text that starts with
=,+,-or@gets an apostrophe in front, so an answer can never become a formula in your Sheet. - Without JavaScript in the visitor’s browser the form still posts the classic way, and the script answers with your thank-you text.
Spam protection
- Bot trap (on by default): a field people never see — anything typed into it marks a bot — and answers sent within two seconds of opening the page are ignored. Bots get a normal thank-you, so they learn nothing.
- Cloudflare Turnstile: a check on your page that tells people from bots, verified by your script with Turnstile’s siteverify service. Turnstile’s no-cost plan covers up to 20 widgets with unlimited checks (Turnstile plans). The site key goes into the form; the secret key goes only into the script’s properties (Project Settings → Script properties →
TURNSTILE_SECRET), never into the page. Each check’s token is valid for 5 minutes and can be used once, so the form renews it after a failed attempt (Turnstile: server-side validation).
Accessibility of the forms it makes
Every form follows WCAG 2.2 for forms: each field has a visible label tied to it, choices sit in a fieldset with a legend, required fields are marked in text and with required, problems are shown in words next to the field (linked with aria-describedby) and listed at the top, where the focus goes, with links to each field. Steps move the focus to the step’s heading; sending and its result are announced. Inputs and buttons are at least 44 px tall, focus is always visible, and Set up shows the colour contrast of your theme for text, buttons, borders and errors.
Limits to know
- E-mails: scripts may send to 100 recipients a day from a personal Google account and 1,500 from Google Workspace (Google’s quota page, which says these can change). The notification is skipped when the quota is used up; the answer is still saved.
- Uploads travel inside the answer, so keep files small (up to 10 MB each here) and test with your largest file. They are saved privately in a folder of your Drive and linked in the row.
- Confirmation e-mails to the person who answered contain only your own text — never their answers — so nobody can use your form to send their words from your account. Use them with Turnstile on.
- In some Google Workspace organisations the administrator does not allow web apps for “Anyone”; then the form cannot post to your Sheet — ask the administrator, or use a personal Google account for the Sheet.
Limitations
- The tool writes the form and the script; you deploy the script in your own Google account (a one-time, five-minute set-up) and paste the form into your site.
- Answers are stored only in your Google Sheet; there is no dashboard or response viewer here — the Sheet is the dashboard.
- Payments, signatures and logins are not part of the forms.
- The preview needs the internet (it runs on MySmartCoPilot’s sandbox address); building, the code and the downloads work without it.
- Your form is saved in this browser only. Use Save form file to keep it, or to open it in another browser.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot. The live preview runs in an isolated frame loaded from a separate MySmartCoPilot address; your form and test answers are handed to it inside your browser and never uploaded. Building, the code and the downloads work offline. Forms you publish send their answers straight from your visitors to your own Google Sheet.
Frequently asked questions
Does MySmartCoPilot see or store the answers?
No. The form posts straight from your visitor’s browser to the Apps Script in your own Google account, and the script writes to your own Sheet. MySmartCoPilot is not in between, hosts nothing and has no copy.
Does running the form cost anything?
Nothing extra: the Sheet and the Apps Script come with your Google account, Cloudflare’s no-cost Turnstile plan covers up to 20 widgets, and the form is hosted on your own site. Your account’s Google quotas apply (for example how many e-mails a script may send a day).
Google says the app is not verified — is that safe?
That warning appears for scripts you write or paste yourself, because Google has not reviewed them. The script is in your own account and you can read every line in the Apps Script tab; choose Advanced → Go to the project to allow it.
Can I change the form after it is live?
Yes. Change it here and paste the new embed code into your site. New fields get new columns at the end of your Sheet. If you change the script itself, deploy a new version (Deploy → Manage deployments → Edit → New version); the web app address stays the same.
My site blocks inline scripts (a Content-Security-Policy). What do I use?
Use the files for a strict CSP: embed.html, form.css and form.js (in the ZIP or under Embed code). Allow connect-src https://script.google.com https://script.googleusercontent.com and form-action https://script.google.com, plus script-src and frame-src https://challenges.cloudflare.com with Turnstile.
Can I track which campaign brought each lead?
Yes. Under Tracking, the form adds utm_source, utm_medium, utm_campaign, utm_term and utm_content from the page address (and optionally gclid, fbclid and msclkid, the page address and the referrer) as hidden values, each in its own column.
Can I translate the form?
Yes: write the labels in any language, set the language code under Look, and translate the messages under Texts and messages (required-field and format messages, the step counter, the sending and error messages).