How it works
One scenario, run cleanly, with no cry-wolf false positives
Paste your URL
Enter any page — we resolve to its domain and load it fresh.
Load cold, no consent
A real headless browser loads the page as a first-time visitor would, before touching the cookie banner.
Classify, don't guess
Every cookie and request is checked against known tracker/cookie databases and read for Consent Mode signals (denied vs granted) — not a naive "anything fired = fail".
Get an honest verdict
Clean, warn, fail, or fail (elevated) for session replay — and inconclusive, never a false pass, if the site couldn't be scanned.
What counts as a violation
The nuance most free tools miss
OK — denied/cookieless pings
Consent Mode advanced sending a denied, cookieless signal before consent. That's compliant, not a problem — we don't cry wolf on it.
Violation — real tracking before consent
An analytics/ads cookie was actually set, or a granted tracking signal was sent, before the visitor chose anything.
Elevated — session replay before consent
Tools like Clarity, Hotjar or FullStory recording screens/clicks before consent — worse than plain analytics, flagged on its own.
Our own data hygiene
We check technical behaviour, not people. No sign-up, no account, no personal data collected for the free check. To keep repeat checks instant and avoid re-scanning the same site over and over, we cache only the domain, the verdict, and a timestamp— never the page content, never tied to your IP or identity. That's the standard we'd expect from any site we audit, applied to our own tool first.
