About Consentinel

We built this because
Local Businesses started getting sued.

Consentinel started as a fix for one of our own websites. It became a product the day we realized the standard GDPR tools everyone trusts were checking a list instead of watching the page.

Consentinel blocks what it can control and makes the rest actionable. It identifies third-party and platform-level exposure, shows administrators where it occurs, and directs them to the system where it can be corrected.

The letter

In 2026, a client of ours was sued under a California wiretapping law. They are not in California. They had a cookie notice on their website — the kind that announces cookies are in use and does nothing else. Their own in-house lawyer had reviewed it and signed it off, because at the time it looked like what everyone else had.

Nobody in that chain had heard of CIPA. CIPA is a law written in the 1960s about telephone tapping, decades before the web, later extended to electronic communications, and it reaches any website a Californian can open. There is no revenue threshold and no minimum customer count — none of the things that keep a small business outside other privacy laws apply. A banner that announces tracking rather than stopping it offers no protection at all. That is exactly the pattern these claims are built on.

Then it happened again

A few days later we found out a business in our own family was being sued for the same thing. By the same person.

That's when it stopped looking like bad luck. What we found was a pattern: people working through American business websites in volume, looking for exactly this — tracking running, and a banner that does not stop it — and sending letters. Not one letter. Campaigns of them. The businesses on the receiving end were nonprofits, business-to-business companies, small shops. People who had never been told the law existed, being asked to pay for not knowing.

We wanted to put a stop to it. That's the whole reason this company exists.

Then we looked at our own site

The uncomfortable part came next.

We build and look after websites for a living, so the first thing we did was check our own. We ran the scan that came with our cookie consent plugin. It said we were clean.

We were not. Our site was running a screen recorder — the kind of script that captures what a visitor types, where they move their mouse, how far they scroll. It is exactly the technology named in these lawsuits. Their consent app never saw it, because it was not watching the page. It was matching addresses against a list of known companies, primarily for GDPR compliance, and this one either was not on the list or was not marked as risky enough to be blocked.

We opened the browser's developer tools and watched the screen recorder start tracking before the banner had been touched.

That issue — between what the tool reported and what the browser actually did — is the entire reason Consentinel exists as a product rather than a checklist.

A scanner tells you what it recognizes. A browser tells you what happened. Only one of those is a record.

So we built something that watches

Not a scanner. Something that visits.

Consentinel loads your site in a real browser, twice. Once as a visitor who refuses cookies, once as a visitor who accepts them. It watches every request each version makes. No list, no assumptions — just what the page actually did. Companies it does not recognize do not get dropped; they go into a bucket labeled “Unknown Trackers”, because the ones nobody has cataloged are the ones that caught us.

Then we pointed it at our own site again.

On a 173-page check in August 2026, that screen recorder ran 972 times. Every single one of them after the visitor agreed. The thing that started all this can't move now until someone says yes — and we can show it, page by page, with a date on it.

That same check still came back exposed, and we're not going to bury that. Seven trackers were still running before consent: fonts pulled in by style files, and a beacon added by our own hosting provider. Nothing any tool of this kind can reach, ours included. They're on our own report, about our own site, in exactly the place we'd put yours.

What we decided not to do

We could have built the same list-based scanner everyone else ships and called it done. It is cheaper to build and easier to sell. It would also have told us again, that our own site was clean.

We chose not to, because that setup is what the letters are built on.

So the rule here is that we tell you where we stop, instead of selling you past it. When something is beyond what any tool of this kind can block — a tag a website builder loads before ours, a font pulled in by a style file, tracking that happens on a server where no browser can see it — we identify where it appears, explain the exposure, show your administrator where to act, and we write it down. There's a page on this site that does nothing but list what we can't block. It's there on purpose.

What we believe

Three things we won't compromise on.

Watch the page, don't read a list

We identify trackers by what they do, not by whether someone has cataloged them. A tracker nobody has heard of still runs. Something watching the page still sees it.

Say where we stop

What can be blocked depends on where your platform lets our code run. We'd rather tell you what we can't stop than pretend the gap isn't there.

Put a date on it

A dashboard saying “blocked” isn't a record. A dated account of what actually ran before consent, that nobody can edit afterwards, is.

Run the same check that started all this, on your own site.

Check my site free

One site, unlimited visitors, no credit card.

Consentinel is compliance software, not legal advice. Nothing on this page creates an attorney-client relationship or guarantees compliance. We don't identify any party, matter or proceeding, and nothing here is a statement about the merits of any claim.