Privacy Audit
A real browser visit captures what your page actually does with visitor data — cookies set, third-party domains contacted, known trackers, HTTPS status, and whether a privacy policy and consent banner are present.
Cookies • Trackers • Third-party sharing • Powered by AI • Results may vary
What it covers
- Cookies, form fields, third-party domains, and known tracker matches
- HTTPS status, privacy-policy link, and consent-banner presence
- DPIA flag when patterns typically warrant a formal assessment under GDPR
- A deterministic score plus an AI-written narrative explaining it
Frequently asked
It loads your page in a real browser and captures outbound requests, cookies, form fields, third-party domains, known tracker matches, HTTPS status, your privacy policy link, and whether a consent banner is present.
Deterministically, from what was actually observed on the page: personal data collection (+20 penalty), third-party sharing (+20), trackers detected (+10), no privacy policy (+10), no consent banner (+5), no HTTPS (+10) — subtracted from 100.
A Data Protection Impact Assessment flag is raised when the scan detects patterns (e.g. sensitive data collection plus third-party sharing) that typically warrant a formal DPIA under GDPR. It's a signal to investigate further, not a legal determination.
No - it checks what loads during an automated single-page visit. Trackers behind consent gating, server-side tracking, or multi-step flows may not appear. Use this as a first-pass signal alongside a full privacy/legal review.
Typically 20–40 seconds — a headless browser visit to collect signals, followed by a short AI analysis step to generate the narrative and recommendations.