Point the scanner at your site and it finds the trackers and cookies, works out what category each belongs to, and turns them into ready-to-save consent purposes. You review and save — no need to know what a “purpose” or “legal basis” is.
From your project's Cookie Scanner, click Scan. We load your homepage in a real headless browser and watch every cookie set and every third-party request made — including trackers injected later by JavaScript (e.g. Google Tag Manager).
Click Generate purposes. We group everything we found into categories and pre-fill a consent purpose for each — with a plain-English name and description, a suggested legal basis, data types, and the detected services.
Tick the purposes you want and save. That's it — your banner now asks visitors for consent against real, correctly-categorised purposes. You can edit any wording, retention or data type afterwards.
Auto-classification
The common providers — Google Analytics, Meta Pixel, Hotjar, Stripe, reCAPTCHA and dozens more — are recognised instantly and categorised deterministically.
Anything our database doesn't recognise is classified by AI into the right category with a short description. These rows are labelled “auto-classified — please verify” so you know to give them a quick check.
Because we use a real browser, we see cookies and trackers that only appear after the page's JavaScript runs — the ones a simple HTML scan completely misses.
Every detection maps to one of these, each with a sensible default legal basis you can change.
Security, login, payments, CAPTCHA — no consent required.
Preferences, language, live chat.
Measurement, statistics, performance.
Advertising, retargeting, conversions.
Recommendations and tailored content.
Embeds and share buttons.
Detected but unclear — review and re-categorise.
No. The scanner classifies everything for you and pre-fills the legal basis and data types. You just review the plain-English suggestions and save; you can change anything at any time.
It marks a tracker that our known-tracker database didn't recognise and that AI classified instead. AI is accurate for most services but can occasionally misjudge an obscure one, so we flag it for a quick human check.
Most sites load their trackers with JavaScript — often through a tag manager — after the page loads. A plain HTML scan can't see those. Loading the page in a headless browser captures the cookies and requests that actually happen.
No. The suggestions (Legitimate Use for strictly-necessary cookies, Consent for the rest) are sensible starting points aligned with the DPDP Act. You remain responsible for the final configuration; consult your advisor where needed.
Create a project, add the widget, and run your first cookie scan in minutes.
Get Started — It's FreeNo credit card required · Setup in under 10 minutes