What this covers
This policy applies to everyone using ConsentCook, on any plan. It exists because parts of the service act on your instructions against the wider internet — the site check fetches pages you name, and the banner runs on sites you say you control — and those are the parts that can be misused.
Only scan sites you are responsible for
Site checks load and crawl the address you give us from our own servers. Only ask us to check a site you own or run, or one whose owner has asked you to. Do not use the checker to probe, map or load-test somebody else's site.
Do not misrepresent consent
The point of ConsentCook is an honest record of what a visitor chose. Do not configure a banner to record consent a visitor did not give, do not present a banner designed to mislead someone into agreeing, and do not alter or fabricate consent records. A receipt that is not true is worse than no receipt at all.
Do not misuse the service
No attempts to break, overload or gain unauthorised access to the service or to other customers' data. No reselling or reverse engineering the service. No automated traffic beyond what your own sites genuinely generate. Security researchers are welcome — the responsible-disclosure policy sets out how, and following it means none of this is held against you.
Unlawful and harmful use
Do not use ConsentCook on sites that are unlawful where they operate, or in support of activity that is. We are not the internet's referee and we do not police the content of customer sites, but we will act on something clearly and seriously wrong when it is brought to our attention.
What we do about a breach
Normally we get in touch and give you a chance to put it right, because most breaches are mistakes. For something serious or ongoing — active abuse, an attack, or misrepresented consent — we may suspend the account first and talk afterwards. We will always tell you what we did and why, and you can export your data.
Reporting misuse
If you think someone is misusing ConsentCook, email legal@consentcook.com. Security vulnerabilities go to security@consentcook.com under the responsible-disclosure policy.