the product

Cookies & trackers

The scanner watches your site the way a first-time visitor experiences it. What it finds becomes a short list of decisions, the decisions become your tracker inventory, and the inventory becomes the public cookie list your visitors read.

the scannerHow scanning works

A scan loads your pages in a real browser, as a first-time visitor with consent denied, and records everything that happens: cookies set, scripts and pixels loaded, iframes embedded, local storage written, tag managers detected, and Google Consent Mode signals observed. Because the visit starts with consent denied, anything that runs anyway is exactly what a regulator would look for, and it is reported as "fired before consent" on your Home page.

Scans run three ways: queued automatically by the quick check during set-up, on demand from the Scans tab, and on a schedule (the cadence depends on plan). The scan page states its coverage honestly: how many pages were crawled and where the plan's page cap sits. What was not seen is never claimed.

Unverified domains get a shallow, passive check only. Verify the domain in Site settings to unlock full scans and alerts.

to sortOne decision per vendor, not per file

New findings land in To sort, grouped by the domain they come from. Twelve script files from one vendor are one question, not twelve: what is this company, and what should happen to it. Each group shows what was found (scripts, pixels, cookies, storage), whether any of it loads before consent (those groups come first, marked), and a best guess at the category. The guess is honest: it only appears when every finding in the group agrees, and when the tracker database is not sure, the group says "No guess, you decide".

Three actions per group: record it as a tracker (filing every finding at once), add it to an existing tracker, or ignore it. Selection works across groups for bulk decisions, and grouping is never removal: every underlying finding stays one disclosure away, with its own actions. When you record a vendor the database recognises, name, provider, privacy policy and category arrive prefilled, and the drawer tells you where each value came from.

your trackersThe inventory

Your trackers is everything you have accounted for, grouped by the banner category a visitor agrees to. This list is what the public cookie list shows, what gets blocked before consent, and what new findings are matched against. Categories come from your banner's working draft, so a category added in the editor appears here immediately, and one added here (there is a New category button) appears in the editor; a category not yet on production is marked as such.

What a tracker record contains

FieldIn plain words
Name, provider, privacy URLWhat visitors read on your banner and public cookie list, who runs it, and where its policy lives.
CategoryThe switch on your banner this tracker waits for.
Legal basis and justificationMost trackers wait for consent. One marked necessary or exempt runs always, and then a written justification is required; it is published on your public cookie list so visitors can see why it runs without being asked.
First partySet by your own domain. First-party necessary items are never counted as pre-consent findings.
Host patternsThe domains the tracker loads from, for example *.google-analytics.com. This is the field that does the blocking.
Advanced matchingScript URL substrings, iframe patterns, cookie and storage-key patterns, for trackers that need finer recognition.
Cookies seenWhat scans actually observed this tracker setting, fed into the public cookie list with lifetimes.

Block rules are created automatically when you save a tracker with third-party host patterns; they are what actually holds it back before consent, and they take effect when you next publish the banner. Embedded iframes (video players, maps) are replaced by a consent placeholder in the visitor's language until their category is allowed.

A tracker can carry the vendor’s own embed code. It is compiled into the published banner and injected only after a visitor allows its category, never before. Code that already ran keeps running until the next page load if a visitor later withdraws.

the public listThe public cookie list, and drift

The public cookie list is generated from your tracker inventory: per language, hosted at a stable address you can link from your privacy notice, and embeddable in your own pages. It updates when you publish.

Because your site keeps changing, the dashboard watches for drift: trackers found by the latest scan that the published list does not mention, or listed items that have disappeared. Drift is announced plainly on Home ("visitors are being told less than the truth") and on the Public list tab, and clears once you sort the newcomers and republish. The list never claims more than the scans support.