Free · blocks trackers before consent
Not just a “we use cookies” strip: analytics and advertising scripts do not run until the visitor agrees, and embedded videos and maps stay behind a clear placeholder until then. Categories, a preference centre, per-region modes, Google Consent Mode v2 and a consent log — all in the free tier. Built for sites with EU visitors and any analytics on board.
No card · a minute to sign up, another for the tag · settings reach your site in 5 minutes
Scripts on the block list are neutralised, cookie writes are buffered, and embedded videos and maps are replaced with a localised placeholder that opens the settings.
The country is resolved by IP, then your rule applies: strict opt-in, opt-out, a soft mode, a notice, or a hidden banner with a settings link. The page language arrives as a language pack.
“Accept all”, “Reject” or the preference centre with four categories. GPC and Do Not Track signals are honoured automatically, and toggles are never pre-ticked.
Allowed scripts start, cookies of rejected categories are cleaned up, Google, Meta and Microsoft receive consent signals, and the decision goes into an anonymous log.
A free Cenaly.com account and your site domain in the "My website" section.
One line before </body> — in your theme, in a Tilda or Wix HTML block, in Shopify's theme.liquid. It serves every widget.
Each widget is a toggle and a settings form. Changes reach your site without touching code; CDN cache is five minutes.
The tag
<script src="https://cdn.cenaly.com/site/v1.js" data-domain="your-site.com" async></script> One tag for all widgets. `data-domain` is your site; everything else lives in the admin.
The engine installs before the config loads: it intercepts cookie writes, neutralises scripts from the block list, replaces embedded videos and maps with placeholders and supports manual `type="text/plain"` markup. After consent the scripts are re-injected and cookies of rejected categories are removed. Best for anyone required to ask first, not after.
The country is resolved by IP, then your rule applies: opt-in for the EU, opt-out where that is the norm, a soft mode, a notice, or a hidden banner. GPC and Do Not Track are handled automatically. Best for sites with visitors from several countries.
If the scan report proved that nothing beyond strictly necessary cookies runs on your site, the first layer informs instead of asking. It does not switch blocking off: a new tracker that appears later is still blocked. Best for brochure sites and landing pages with no advertising pixels.
Google Consent Mode v2 with proper wait-for-update, a named dataLayer event for GTM, Microsoft UET, Meta Pixel and Clarity — vendors receive signals rather than going dark with the banner. Best for anyone measuring conversions.
The site scan finds which cookies and trackers your site actually loads, and a live declaration table embeds into your policy with a single container, updates from the scan results and localises itself. Best if your declaration was written by hand a year ago.
An anonymous consent log: what the visitor chose and when, without IP or full user agent. A floating button and any link carrying `#cenaly-consent` open the preference centre — the same mechanism covers a “Do Not Sell” link in your footer. Best for anyone who wants a history of decisions rather than a dismissed banner.
Strict opt-in: analytics and advertising wait for consent instead of starting with the page.
Consent Mode v2 passes the consent state to vendors — the visitor’s choice reaches your tags instead of staying inside the banner.
The scan confirmed it — so the first layer informs instead of asking. A new tracker that appears later is still blocked.
Before consent their place is taken by a clear placeholder with a settings button, not an empty rectangle.
The plugin installs the banner without touching your theme; linked to your account the site behaves like an ordinary location, consent log included.
The age gate asks first, and only after it does the cookie question appear.
Colour, position and labels adapt to your site. The widget lives in a Shadow DOM — your styles don't break it, and it doesn't break yours.
On desktop
On mobile
On your side: The four categories and their descriptions are already written; the set of buttons, theme, position and logo are your settings. In the US mode the first layer becomes “Do Not Sell or Share My Personal Information” — also ready to go.
On desktop
On mobile
On your side: Once consent is given, allowed scripts start and buffered cookies are written; a refusal stays a refusal until the policy version changes. The floating button lets the guest change their mind — which both the law and your lawyers expect.
Exact menu names and plan requirements, taken from each platform’s own help center.
Sites built with our website builder ship with the widgets already wired — nothing to paste.
Step-by-step guides per platform — in the help center →Free
Free on sites built with our website builder
Widgets are the door into the Cenaly.com platform: requests, chats and orders from your site land in the same admin as everything else, and some owners later buy extensions. We earn from plans and from four paid add-ons rather than from the widgets — which is why we charge nothing per visitor, impression, request or domain.
| Without the widget | With the widget | |
|---|---|---|
| When trackers start | ✕ The strip is there, but analytics and ads start along with the page | ✓ Scripts on the block list don’t run until the visitor agrees |
| Visitor’s region | ✕ The same banner is shown to the entire world | ✓ The mode follows the country: opt-in, opt-out, soft, notice or hidden |
| Consent signals | ✕ The visitor’s choice stays inside the strip: no tag or vendor is told about it | ✓ Consent Mode v2, the dataLayer event for GTM, UET, Meta Pixel and Clarity all receive the consent state |
| Cookie list | ✕ The cookie list in the policy was typed by hand a long time ago | ✓ The scan shows which cookies your site really loads, and the live table updates the declaration |
| History of decisions | ✕ There is nothing to show what the visitor chose, and when | ✓ An anonymous log keeps the choice and its timestamp — without IP or full user agent |
A cookie banner is not a “we use cookies” strip but a consent mechanism: it has to ask before analytics and advertising start counting the visitor, and to remember the answer. The order is what matters — question first, trackers second, which is why the tag goes in front of third-party analytics.
You need one if you have visitors from the EU or the UK and your site loads anything beyond strictly necessary cookies: counters, pixels, embedded videos and maps. Other regions work differently — in some, a notice and a way to opt out is enough.
Our banner is free in its base tier and does the real work: it blocks scripts and cookies until the visitor decides, passes consent to Google Consent Mode v2 and other vendors, shows the actual cookie list from a scan and keeps an anonymous log of decisions. If the scan confirmed that nothing beyond strictly necessary cookies runs, the first layer informs instead of asking. There is a WordPress plugin that needs no theme edits, and the 18+ age gate lives in the same widget, standing in front of the banner.
You don't need a banner if the site sets nothing beyond strictly necessary cookies — but that is worth confirming with a scan rather than by eye: one embedded video, map or third-party font already changes the answer, and then our first layer switches from a question to a notice. What separates the banner from legal pages is that it isn't a text but a mechanism: a policy explains data processing in words, while the banner physically holds trackers back until consent and stores the proof of the answer.
A banner in 45 languages, tracker auto-blocking, four categories and a preference centre, per-region modes, Google Consent Mode v2, a monthly scan of 10 pages and a 3-month consent log. The paid add-on lifts the limits: weekly scans of up to 30 pages and a 12-month log; the price is in the extensions catalogue.
Yes: the engine installs before the config loads and stops scripts on the block list from running, intercepts cookie writes and replaces embedded videos and maps with a placeholder. After consent the scripts are re-injected. For strict blocking the tag has to come before third-party analytics.
Yes, through Consent Mode v2: tags in GTM react to the consent signals, and a named event is pushed into the dataLayer. Microsoft UET, Meta Pixel and Clarity are supported separately.
If the scan report confirms it, the first layer of the banner informs instead of asking — nobody is bothered with a pointless question. It does not switch blocking off: a new tracker that appears later is still blocked, and the consent settings stay reachable from a link.
It depends on the region: some require consent, others accept a notice with a way to opt out. The mode is chosen per region in the settings, and borderline cases are worth discussing with a lawyer.
The categories the visitor chose and the time of the decision — anonymously, without IP or full user agent. It is a history of decisions rather than a guarantee of compliance: it shows that consent was collected and how it was arranged.
In a separate section of the same widget’s panel: a threshold of 18 or 21, confirmation buttons or a birth-year field, memory from 1 to 365 days (30 by default). The birth year is never stored anywhere, and a refusal is deliberately not remembered.
With the shared “My website” tag — it powers all 12 widgets, and the banner comes up first. For strict prior consent put a separate consent tag as the very first line of the `head` section, before third-party analytics. For WordPress there is a plugin: it installs the widget without touching your theme, and linked to your account the site behaves like an ordinary location, consent log included.
The honest answer here is longer than for the other widgets. The banner is about 34 KB gzipped and, unlike them, goes first in the head and without async: otherwise it can't intercept third-party analytics before the visitor answers, and that is its entire point. After the decision it loads nothing more: the 18+ age gate is a separate lazy half of about 5 KB that ships only when the gate is switched on, and the cookie list comes from a scan that already ran rather than being assembled in the browser. The banner renders in a Shadow DOM.
One loader — about 26 KB gzipped, with the async attribute: it reads which widgets you switched on and pulls only those, as separate files. A widget you left off is never downloaded, and the weight of each one you did switch on is stated on its own page.
No. Widgets render inside a Shadow DOM: your site's CSS doesn't affect them and theirs doesn't leak out.
It reads your page's `<html lang>` or a `data-lang` attribute on the tag. Built-in labels are translated into 45 languages — the guest chat covers the same list; your own texts you write in the admin in the languages you need.
In the cloud your account lives in: cenaly.com — AWS, cenaly.ru — Yandex Cloud in Russia. Requests, conversations and bookings stay within the brand's contour.
More — installation per platform, settings and troubleshooting — in the help center. Installation guide →
Comparisons
Privacy, terms, returns, cookies, delivery — built from your own data and embedded in your site
$9/mo
A “?” button → a side panel with your articles, search and a “was this helpful” vote
$19/mo
Modals, slide-ins, bars, embedded forms, coupons and quizzes with display rules and A/B testing
$9/mo
Free. One tag, the “Consent” toggle — and trackers wait for the visitor’s decision while you keep the log. On WordPress the plugin is enough, with no theme edits.
Start for freeNo card required · base tier is free · Consent Mode v2 and the log included