Free beta · no account · no card

Your cookie banner says
“Reject all”. Does it?

Most consent banners record a refusal and then load the same trackers anyway. FixMyCookies clicks decline for you, reloads the page, and reports what was still watching.

  • Nothing to install to look
  • Real browser, not a HEAD request
  • We never say “you're compliant”
live demo — the real banner, running in this page working, not a video

1. A page tries to load two trackers

Below is the actual fixmycookies.js that ships to customers. A script on this page is trying to inject a Meta Pixel and a Hotjar session recorder. Watch what happens before you decide anything.

Waiting for a decision. Trackers have not fired yet.
0 blocked
The banner is below-left of your screen (bottom on desktop). Click Reject all and then press Try to inject trackers again — the blockers stay up. Press Accept all to release them.

Blocked request log

Every attempt the SDK stopped, as it happened.

  • nothing attempted yet
What it finds

Findings, not a score out of 100

Every finding names the service, shows the evidence we saw, and says what to do about it. You can disagree with us with the data in front of you.

Trackers before consent

Analytics, ad pixels and session recorders that load on first paint, before anyone has been asked anything.

A refusal that does nothing

“Reject all” clicked, page reloaded, and the same trackers still fire. Our most serious finding, and the one almost nobody tests.

Cookies set too early

Named cookies with their vendor, purpose and lifetime — including the ones JavaScript can't see because they're HttpOnly.

Google Consent Mode

Whether consent default is declared at all, and whether any category is granted before the visitor has chosen.

Global Privacy Control

We signal GPC the way a browser does and check whether advertising still loads. In California that signal is not decorative.

Policy that names nothing

“We use cookies to improve your experience” and not one cookie named. A regulator can check that in ten seconds.

How it works

Three scenarios in one real browser

Not a HEAD request. The interesting part of consent happens after the page loads, and you cannot see it from HTML.

First visit

A clean browser profile loads your page. Everything that fires before any choice is recorded, with timings.

Reject all, then reload

We find the refusal control, click it, reload, and diff the network activity. If the trackers come back, that is the headline.

Accept all

What consent actually unlocks — useful when someone asks you why the analytics dashboard went quiet.

Our limits

Things we will not do

A compliance product that lies to you about compliance is worse than no product. So, in writing:

01

We will never tell you that you are compliant

No scan can establish that. It depends on your lawful basis, your contracts and your data flows — none of which are visible from outside your business.

02

We will never invent a statistic

No made-up percentages, no “average fine” figure, no customer counts we can't evidence. Where a number appears here, you can check it.

03

We will say when a result is unproven

Consent banners are usually shown only to visitors a site thinks are in the EU. When we cannot appear European, we say a missing banner is unproven — not that none exists.

04

We will show our working

Every report exposes the raw observations behind it, including the cookies and third parties, so a developer can verify each conclusion directly.

05

We will not sell with fear

GDPR Art. 83(5) allows up to €20 million or 4% of total worldwide annual turnover, whichever is higher. That is the ceiling, not the expectation, and we will not blur the two to sell you a subscription.

Free while in beta

Free, and honest about why

FixMyCookies is in beta. The scanner works, the banner works, and both are free to use while we finish the hosted version. There is no card field anywhere on this site because there is nothing to charge you for yet.

What exists today

The scanner, the refusal test, the consent banner SDK, signed consent receipts, and the reports.

What does not

Hosted accounts, scheduled monitoring emails, and billing. We will say so on the day that changes.

What that means for you

Use it, keep the reports, and don't build a process that depends on us existing yet.

Get the banner

Install

The banner, in two lines

Self-hosted, self-contained, and it makes no third-party requests of its own.

<!-- In <head>, WITHOUT defer: it must install its hooks
     before your tag manager runs. -->
<script src="/fixmycookies.js"></script>
<script>
  window.FixMyCookiesConfig = {
    endpoint: '/api/consent',   // where signed receipts are sent, optional
    policyUrl: '/privacy'
  };
</script>

<!-- Anything held back until consent: -->
<script type="text/plain" data-consent="analytics"
        src="https://www.googletagmanager.com/gtm.js?id=GTM-XXXX"></script>
It blocks known tracker domains injected by any other script — the tag manager adding a pixel nobody knew about is exactly the case it catches — defaults Google Consent Mode v2 to denied, honours Global Privacy Control as a refusal, and keeps “Reject all” the same size and prominence as “Accept all”. Consent receipts are signed with HMAC-SHA256 so you can prove a record hasn't been altered since it was written. That is evidence, not a legal certificate, and we will not call it one.
Questions

Worth asking

Why might you find no banner when there is one?

Because location decides. Many consent banners are only shown to visitors a site believes are in Europe. Our scanner presents itself as European, but it cannot change the IP address it connects from — so a site that geolocates by IP still shows us the non-European page.

When that happens the report marks the absence unproven rather than deciding it for you. We would rather say “we don't know” than be confidently wrong.

Is this free? What's the catch?

Free while in beta. The catch is that it is a beta: the hosted scanning service and scheduled monitoring are not finished, and this page tells you so rather than implying otherwise. See the terms.

I don't have EU visitors. Does this apply to me?

If you have EU or UK visitors, GDPR or UK GDPR applies — where your business is based doesn't change that. Other regimes differ in kind, not just in name: California's CCPA/CPRA is principally an opt-out and disclosure regime rather than a prior-consent one, so a GDPR-shaped banner may be the wrong shape for it.

Is this legal advice?

No, and it is not a substitute for it. We describe observed behaviour and cite the rule an observation relates to. Whether it creates exposure depends on facts we cannot see.

What are the known gaps in the beta?

Stated plainly, because you will find them eventually: single-page apps are observed on one load only; a banner hidden inside a cross-origin iframe will be missed; login-gated pages are not scanned by design; and consent receipts tell you what a browser reported, not that a particular person understood anything.