Frequently asked questions
How to install the banner, list cookies, use Google Consent Mode, and read your consent and performance data.
Getting started
consent is a cookie banner you add to your website with one script tag. It shows visitors a choice, blocks common trackers until they agree, and keeps a record of each decision.
consent has three plans — Starter, Growth and Enterprise. Open Plans in your dashboard to compare what each includes and what it costs. Sites set up during the beta keep working, and nothing becomes chargeable without notice.
No tool can guarantee that. consent helps you present a banner, block scripts until a visitor chooses, and keep a record of those choices. You still need accurate wording, the right categories for cookies you actually use, and a privacy policy that matches your site.
Banner message templates are starting points, not legal advice. Edit them to fit your site.
Sign up, add your domain, customize the banner if you want, then paste the snippet from the Install tab as the first script in the <head> of every page. The banner appears for visitors who haven't chosen yet.
Install
In <head> on every page, as the first script — before Google Tag Manager, gtag.js, or any analytics or ads snippet. Don't add async or defer. The banner needs to run first so it can send Consent Mode signals and block trackers before those tags load.
Place the Install snippet first in <head>, then Google's container snippet immediately after it.
Do not add the banner as a Custom HTML tag in Tag Manager. The banner needs to run first.
- The snippet is on the page and is the first script in
<head>. - The page hostname matches the domain in Details, or an extra hostname on the allowlist (
wwwvs the bare domain is a common miss). - The site status in Details is Active, not Paused.
- You haven't already made a choice in this browser. Open the live preview on Install and hit Reset, or try a private window.
- If you're on localhost, a preview URL, or Tag Manager preview, add a token (see below) — those hostnames usually aren't on your allowlist.
The domain is your live site. The banner loads and records consent there.
The allowlist is for extra stable hostnames that should show the same banner — for example www, a staging subdomain, or another brand domain. You don't need to repeat the primary domain. Allowlist changes apply when you save.
A token is for pages with no stable hostname you can list: localhost, a one-off preview URL, or Google Tag Manager preview. Add the token before the snippet. Generating or removing a token takes effect immediately.
<script>window.__cosmoopsConsentToken = "YOUR_TOKEN";</script> <script src="https://your-consent-host/api/embed/SITE_ID/script.js"></script>
The banner is shown until a visitor makes a choice. To let them change it later, add a “Manage cookie preferences” link (for example in your footer) that opens the same Customize view:
<a href="#" onclick="window.cosmoopsConsent.showPreferences(); return false;">Manage cookie preferences</a>
Their choice is saved in the browser (localStorage), not as a cookie. That's why Reset on the Install preview, or a private window, shows the banner again.
Yes. On the Banner tab, set Color mode to Automatic, then design a light look and a dark look. The banner picks one in this order:
- Your site's own choice — if your site has its own light/dark switch, it can tell the banner which one is showing.
- The visitor's system setting (their operating system or browser light/dark preference).
- Your default scheme, for a browser that doesn't report a preference.
To tell the banner your site's choice, set an attribute on the <html> tag, or call the function from your script. The call wins if you use both. Anything other than light or dark is ignored, and setColorScheme("auto") goes back to following the visitor's system:
<html data-cosmoops-color-scheme="dark">
window.cosmoopsConsent.setColorScheme("dark"); // or "light"A change applies right away, including to a banner that is already open. The font, text size and corner rounding are shared by both looks. In Manual mode the banner always uses the colors set on the Banner tab and ignores all of this.
Yes. Listen for window.cosmoopsConsent.consent or the cosmoopsConsentUpdated event, and run or skip your own tags from there. Auto-blocking still applies to recognized trackers unless you handle those yourself.
Cookies & blocking
Listing and blocking do different jobs:
- The Cookies tab is what visitors see when they open Customize — a table with each cookie's name and domain, its provider (with a link to their privacy policy), purpose, and expiry.
- Blocking (on Install) stops a script from running until the matching category is allowed.
- Declining a category removes the cookies you've listed under it from the visitor's browser — only the listed ones, so a cookie that isn't on the Cookies tab is left alone.
A script can be blocked without being listed, and a cookie can be listed without being blocked. Use both: the script stays off until visitors agree, and they can see what they're agreeing to.
When a visitor reopens the banner and saves, the new choice applies straight away. Turning a category on lets its held-back scripts load immediately. Turning one off removes the cookies and stored entries you've listed under it from their browser, and — with Google Consent Mode in Advanced mode — tells Google's tags to stop using theirs.
A few things can't be removed from a web page: cookies the server marks HttpOnly, cookies that belong to another company's domain (a third party's own cookies), and storage that belongs to a third-party embed on the page. A cookie listed without a path — an older listing — can only be removed from pages under its path. A script that was already running keeps running until the next page load, when it stays blocked. For a cookie to be cleared it has to be on your Cookies tab, so run a scan and approve what it finds.
Cookies under Necessary are never removed. If a cookie your site needs to log people in or hold a cart is listed under another category, declining that category would sign them out — move it to Necessary.
When you add or delete a cookie on the Cookies tab, visitors who have already made a choice are asked again the next time they load a page. Cookies you've deleted are also cleared from their browser straight away, no matter how many changes they missed since their last visit.
Each cookie can be listed once for a given name, domain and path. To change a cookie's name, domain, path, category or expiry, delete it and add it again. You can update its provider, purpose and privacy link at any time, and visitors aren't asked again for that.
Cookies under Necessary are never cleared this way, so deleting a login or cart cookie from the list won't sign anyone out. If your site keeps setting a cookie you've deleted, it returns on the visitor's next visit and the next scan lists it under Suggested cookies.
If the consent script is placed first, it recognizes and blocks common trackers inserted at runtime (including Meta Pixel, TikTok Pixel, LinkedIn Insight, and HubSpot) until the matching category is allowed.
Google Analytics and Google Ads depend on Consent Mode on the Banner tab. In Basic they are blocked until the visitor allows Statistics or Marketing. In Advanced they are not blocked — they're told what the visitor chose and honor it themselves (cookieless pings until then).
For a hardcoded script, or one we don't recognize, change its type to text/plain and add data-cosmoops-consent set to preferences, statistics, or marketing. We'll run it once that category is allowed:
<script type="text/plain" data-cosmoops-consent="statistics" src="https://www.googletagmanager.com/gtag/js"></script>
- Necessary — required for the site to function. Always on; visitors can't turn it off.
- Preferences — remembers settings like language or region.
- Statistics — analytics about how visitors use the site.
- Marketing — used to show relevant ads.
You can turn Preferences, Statistics, and Marketing off in the Banner tab if you don't use them, and you can edit the labels visitors see.
When you add a site we scan it in the background, and you can run Scan again from the Cookies tab. Each suggestion comes with the domain it is stored under and, for providers we recognize, a link to their privacy policy. Suggested cookies stay off the public banner until you approve them. Unrecognized names still get a visitor-facing provider and purpose (from the cookie's domain and category) — they open for review first so you can check the details before they're added.
Sites are also re-scanned automatically about once a week, a few at a time, so a tracker added since the last scan appears under Suggested cookies without anyone pressing Scan. A cookie that has moved to another domain or path shows up there too, and, if the old entry came from a scan, it is flagged. The Cookies tab also flags cookies you added from a scan that the latest scan didn't find — it's up to you whether to delete them — and cookies listed under a less strict category than the one we recognize them as. Cookies you add yourself are never flagged for missing from a scan, since some only appear after sign-in.
Google Consent Mode
Basic: Google's tags don't load until a visitor allows the matching category — Statistics for Analytics, Marketing for Ads. Nothing is sent to Google beforehand, not even cookieless pings. Visitors who decline are missing from reports.
Advanced: Google's tags load right away and honor each category. Until Statistics or Marketing is allowed they send cookieless pings (no cookies, no identifiers) so Google can estimate what it can't see. Once allowed, they measure normally.
- Necessary → security_storage (always granted)
- Preferences → personalization_storage, functionality_storage
- Statistics → analytics_storage
- Marketing → ad_storage, ad_user_data, ad_personalization
Every visit starts with denied for everything except security_storage, then updates to the visitor's stored choice. That's why the consent script must load before GTM or gtag.
Yes, if you want Tag Manager to send Consent Mode signals from inside your container. You still need the Install snippet on the page for the banner.
Running both is safe — both start by denying everything except Necessary. Keep the template's Global row set that way, and keep Consent Mode on Advanced.
Configure region defaults, URL passthrough, and ads data redaction in one place. If both are set, the template takes priority.
They set what each visitor starts with, before they choose — only in Advanced mode. Add a Global row for the worldwide default, then extra rows for specific countries or regions. If there's no Global row, everything except Necessary starts denied.
Codes are ISO 3166-2: a country (GB, FR) or a subdivision (US-CA). Separate multiple codes with commas. Global can't share a row with country codes.
Both apply in Advanced mode while Marketing is denied. Passing ad click IDs through URLs helps Google keep conversion measurement without cookies. Redacting ad identifiers strips those IDs when ads storage is denied.
If you also use our Tag Manager template, set these in one place — the template's values take priority.
Consent data
In their browser: the choice itself (so the banner doesn't keep asking). On our side: an anonymous visitor ID, which categories they allowed, and when. We don't collect visitors' IP addresses, names, or other directly identifying information through the banner.
Individual log entries are kept for the period your plan includes (30 days on Starter, 12 months on Growth, 3 years on Enterprise), then deleted. The totals and daily chart are not affected — those stay so you can see trends. Banner configuration is kept until you delete the site or your account.
While an entry exists you can open it on the Consent data tab to see what that visitor was shown: the banner and the exact cookie list, including each cookie's provider and purpose as they read at the time. That history is saved every time you change the banner or the cookie list, and it is kept after the log entries themselves are deleted. It starts from when cookie lists began to be recorded — earlier choices show the banner but not the list.
Performance
It loads your live site and reports performance, accessibility, best practices, and SEO scores, plus sitemap and robots.txt health, Core Web Vitals, and the highest-impact things to fix. There's a public checker with no account, and a fuller report on the Performance tab after you sign in.
It reads your homepage and looks for the policies a site like yours is expected to have — privacy policy, cookie policy, terms, refund and shipping policies, and contact and grievance officer details — and tells you which are required, which are recommended, and whether each one is there. The public checker shows the findings; after you sign in, the Compliance tab keeps them for your site and the Policies tab drafts the ones you're missing from your answers and your cookie list. Drafts are a starting point, not legal advice.
This test is a single run we just did (mobile or desktop). Real visitors is 28 days of field data from people who actually used the site. A site without much traffic may not have real-visitor numbers yet.
Account
Starter:
- 1 website
- Consent log kept 30 days
- 10 manual cookie scans a month
Growth:
- 1 website, with up to 2 more as add-ons
- Consent log kept 12 months
- 100 manual cookie scans a month
- Automatic weekly cookie scans
- Glass and gradient banners, and automatic light/dark
- Consent Mode defaults by region
- Consent history — what each visitor was shown
- A banner without the “Powered by” credit
Enterprise:
- 10 websites, with more as add-ons
- Consent log kept 3 years
- Unlimited manual cookie scans a month
- Automatic weekly cookie scans
- Glass and gradient banners, and automatic light/dark
- Consent Mode defaults by region
- Consent history — what each visitor was shown
- A banner without the “Powered by” credit
Prices and billing cycles (monthly or annual) are on the Plans page in your dashboard.
Upgrades apply straight away. If you move to a plan with fewer websites, or without a feature, nothing is deleted and your existing banners keep working — you just can't add websites beyond the new limit, or switch on what the plan doesn't include.
If a subscription ends, your sites and settings are kept. Choose a plan again whenever you want to carry on managing them.
Pause from Details — the banner is hidden but the site and its settings stay. Delete from the same tab; that permanently removes the site and the banner on your website will stop working.
Email hello@cosmoops.com. For how we handle data, see the Privacy Policy; for using the service, see the Terms of Service.