Cookie consent without paying per domain.
A consent banner for your websites, a script-blocking engine that keeps trackers off until visitors opt in, tamper-evident proof of consent, and a multi-organization admin dashboard. Run it for one website or as a service for hundreds. Your data stays on your servers.
A self-hosted alternative to Cookiebot, Usercentrics or OneTrust, built around what European regulators actually check.
Tags marked type="text/plain" data-zeno="analytics" never run before consent. The same works for iframes and pixels.
"Accept all" and "Reject all" sit on the first layer with identical styling, enforced in code and verified by a test.
Necessary, Functional, Analytics and Marketing, with nothing pre-ticked. Each category lists its cookies: name, provider, duration and purpose.
A persistent settings button reopens the choice. Withdrawing deletes the site's first-party tracker cookies and reloads the page.
GPC is honoured as an automatic "reject all". Google Consent Mode v2 is supported.
English, German, Danish, Spanish, French, Swedish and Norwegian. Wording checks stop a "Reject" button labelled "Settings" and similar tricks.
One dashboard for every organization and website you look after.
Organizations, members with roles (Owner, Admin, Member, Viewer) and invitations. Edit the real banner with a live preview.
Visits your site like a first-time visitor in headless Chromium, accepts, and visits again. It flags anything set before consent, including Google Fonts.
A one-click library of common services (GA4, Meta Pixel, YouTube, Matomo, Hotjar and more) and an auto-rendered declaration for your cookie policy page.
Each published revision carries a SHA-256 fingerprint, so you can always prove what a visitor saw. Material changes ask visitors for consent again.
Each receipt holds a timestamp, decision, revision, language, page and a hashed, truncated IP. Export to CSV in S3, and erase receipts for data-subject requests.
An audit log of every change, hash-chained daily digests, nightly retention purge, pg_dump backups to S3 and an admin CLI.
On a Linux server with Docker and a DNS name pointing to it. The installer starts the app, PostgreSQL, MinIO and Caddy with automatic HTTPS, then prints the URL of the first-run setup page.
./install.sh --domain consent.example.com
<!-- then, on your site -->
<script src="https://consent.example.com/zeno.js"></script>
Run consent for one website or a few hundred, on servers you choose.