If you let webserver-user "own" your files, than every other CGI script can read your files.
To make something about that, you may make your scripts setuid. And then create all files in some directory other than cgi-bin which is only readable/writable/executable by your userid.