Privacy Policy
ConsentProof is a cookie consent checker, so this policy has two halves: what we hold about you as a customer, and what we record about the websites you ask us to scan. Both are listed below in full, with the retention window that applies to each.
Effective 2026-09-07
Who is responsible
ConsentProof is operated by WANG WENJIE, an individual developer, who is the data controller for the personal data described here. Questions, access requests and deletion requests all go to one address: Fuuqiu@gmail.com. One person reads that mailbox, and it is the same address printed on the contact page, in the repository and on every invoice-related email.
We do not sell personal data, we do not share it with advertising networks, we run no advertising on the site, and we do not use your scan evidence to train machine-learning models.
What we hold about you
Only what an account needs to exist and to be billed. Everything in this table is stored in a Cloudflare D1 database in our own account.
| Data | Why we have it | Kept for |
|---|---|---|
| Name and email address | To identify the account, sign you in, and send alert and billing email | Until the account is deleted |
| Password hash (email sign-in) or provider tokens (GitHub / Google sign-in, when offered) | Authentication. We never store a password in readable form | Until the account is deleted |
| Session records: a session token, its expiry, the IP address and browser user-agent of the sign-in | To keep you signed in and to let us investigate account abuse | 30 days per session, then expired and removed |
| Workspace, site list, labels, scan schedules and alert rules | This is the product: the ledger of client sites you asked us to watch | Until you delete the site or the account |
| Slack incoming-webhook URLs you paste into an alert channel | To deliver alerts to the channel you chose | Until you remove the channel or the account is deleted |
| Audit log entries: which account did which billable or destructive action, and when | Support, abuse investigation, and the usage counters on your account page | Until the account is deleted |
| Billing records: Stripe customer and subscription id, plan, status, amount, interval, seat count, period end | To know what you are entitled to and to renew or cancel it | Until the account is deleted; invoice records are retained by Stripe for their own statutory periods |
We never see or store card numbers. Payment details are entered on Stripe's own checkout page and stay with Stripe.
What a scan records about a website
A scan loads the page you submitted in a clean, real browser with no cookies and no prior consent, records what the page did, clicks the consent banner, reloads, and records what the page did the second time. Both captures are stored as evidence, because evidence you cannot re-read later is not evidence.
- The URL you submitted, and the hostname derived from it.
- Every cookie present before consent and after consent: name, domain, and the classification we resolve it to.
- Every third-party request host the page contacted in each phase, and the vendor we map that host to.
- The consent platform detected on the page, if any, and the
dataLayerstate we read Google Consent Mode v2 signals from. - Two JPEG screenshots of the page — one before consent, one after — stored in a Cloudflare R2 bucket in our own account.
- An absolute UTC timestamp and a SHA-256 hash of the captured evidence, so a report can be checked later.
Screenshots are pictures of a public web page as an ordinary visitor would see it. If that page displays personal data publicly — a name in a testimonial, a photograph, a comment — the screenshot will contain it. We do not attempt to extract, index or enrich anything on the page; we capture what the browser rendered and store it against the scan.
For scans run inside a workspace, we act on your instructions: you decide which sites to scan and for how long the evidence lives — within the authorisation you warrant in the terms. For anonymous public scans, the resulting page is permanently public at its own link, is marked noindex so it never enters a search index, and can be taken down on request to the address above.
We do not log into the scanned site, submit forms, follow links beyond the page you gave us, or attempt to bypass any access control. A scan is one page load, a banner click and one reload.
How long evidence is kept
Retention is a plan feature, and it is enforced by a nightly job rather than by a promise: scans older than the window are deleted from the database and their screenshot objects are deleted from storage. The most recent scan for a site is never pruned, so a site never loses its current state.
| Plan | Evidence history | Monitored sites | Scheduled scans |
|---|---|---|---|
| Free | 7 days | 3 | Manual only |
| Pro | 90 days | 25 | Weekly |
| Agency | 365 days | 50 | Daily |
Deleting a site deletes its scans and their evidence objects. Downgrading a plan applies the shorter window at the next nightly run.
IP addresses
Public scans need no account, which means the only way to keep the free tier free is to count them per network. When you run an anonymous scan we store a counter in a key derived from your IP address in Cloudflare KV, together with the current UTC date; the key expires automatically within 48 hours and is never joined to an account, a scan record or an email address. The limit it enforces is 3 scans per IP per day · 1 scan per site per hour.
Cloudflare, as our hosting provider, processes request metadata including IP addresses to route traffic and to protect the service from attack. That processing is described in Cloudflare's own privacy documentation.
Legal bases (UK / EU GDPR)
| Processing | Basis |
|---|---|
| Creating and running your account, running the scans you asked for, delivering alerts, taking payment | Performance of a contract (Art. 6(1)(b)) |
| Rate limiting, abuse prevention, security logging, product analytics in aggregate | Legitimate interests (Art. 6(1)(f)) — keeping a free tier usable and the service available |
| Scanning the publicly reachable pages of a website you nominate and storing the result as evidence | Legitimate interests (Art. 6(1)(f)) of you and of us in auditing consent behaviour, within the authorisation you warrant in the terms |
| Keeping billing and tax records | Legal obligation (Art. 6(1)(c)) |
We do not rely on consent for anything on this site, because we set no non-essential cookies and send no marketing email. You will not receive an email from us that you did not configure or that is not about your own account.
Sub-processors
Four vendors, each doing one thing. There is no analytics suite, no session recorder, no customer-messaging widget and no advertising pixel anywhere in the product.
| Provider | What it does | What it sees |
|---|---|---|
| Cloudflare | Hosting (Workers), database (D1), rate-limit counters (KV), evidence storage (R2), and the headless browser that performs a scan (Browser Rendering) | Everything the product stores, plus request metadata such as IP address |
| Stripe | Payments, subscriptions, the customer portal and invoices | Your email, billing address, tax id if you give one, and your payment method — which we never receive |
| Resend | Sending alert and account email | Recipient address and the message body, which contains the site name and the change we detected |
| Slack (only if you configure it) | Delivering alerts to a channel you chose, via a webhook URL you paste in | The alert message you asked us to post there |
We rely on the data-processing terms and, where applicable, the Standard Contractual Clauses published by each of these providers. Data is stored on Cloudflare's global network and may be processed outside the UK and EEA. If we ever add a fifth vendor, it will appear in this table before it is switched on.
Your rights
If you are in the UK or the EEA you have the rights below, and you exercise all of them by emailing the address at the top of this page. We answer within 30 days and do not charge for it.
- Access — a copy of what we hold about you.
- Rectification — correct anything that is wrong.
- Erasure — delete the account and everything attached to it.
- Restriction and objection — including objecting to processing we base on legitimate interests.
- Portability — your sites, scans and findings in a machine-readable form.
- Complaint — to your national supervisory authority, or to the UK Information Commissioner's Office, if we have not put something right.
Account deletion is handled by hand today rather than by a button in the app: email Fuuqiu@gmail.com from the account address and we delete the account, its workspaces, sites, scans, findings and stored screenshots within 30 days. Anonymous public scan results are not attached to an account, so tell us the result link and we will remove it. Billing records held by Stripe are kept for as long as their own statutory retention requires.
Security and breaches
Traffic is served over TLS. Passwords are hashed. Slack webhook URLs are treated as credentials: the API only ever hands them back in a masked form, and the full value leaves the database only at the moment an alert is delivered. Secrets are held as platform secrets, never in the repository.
No system is perfect. If you believe you have found a vulnerability, email Fuuqiu@gmail.com with the details and please do not disclose it publicly until it is fixed. If a breach affects your personal data and is likely to result in a risk to you, we will tell you and the relevant supervisory authority without undue delay.
Children
This is a business tool sold to agencies and developers. It is not directed at children, and we do not knowingly create accounts for anyone under 16.
Changes to this policy
When the product changes, this page changes in the same release — a new sub-processor, a new category of stored data or a new retention window is written here before it ships. Material changes to how we handle personal data are emailed to account holders. The effective date at the top of the page is the date of the current wording.