Why most SvelteKit consent banners do not work
An analytics import at the top of +layout.svelte is evaluated during SSR and again on hydration. Both fire before the banner's onMount, so consent arrives after two pageviews rather than none. A banner that renders after that has recorded a decision, not enforced one — and the enforcement is the part the ePrivacy Directive and the GDPR are actually about.
- ✓Poliogo's banner intercepts the tracking scripts rather than sitting beside them, so a tag that has not been consented to never executes.
- ✓Strictly necessary cookies — session, security, cart — are never held, so nothing about your product breaks while a visitor is deciding.
- ✓Every choice is written to a consent record with a timestamp and what was on screen at the time, which is the evidence a regulator asks for.
Installing it in SvelteKit
Poliogo recognises a SvelteKit project from svelte.config.js, works out where its router lives, and opens a pull request. You review a diff and merge it — there is no dashboard step in the middle and nothing to copy by hand.
- ✓Pages are written in SvelteKit's own convention — src/routes/privacy/+page.svelte — so your existing +layout wraps them and the styling matches the rest of the site with nothing to configure.
- ✓The banner tag goes in src/app.html, above %sveltekit.body%, which is the one place it is guaranteed to be parsed before your app's modules are evaluated.
- ✓Adapter-static and adapter-node projects install identically: the pages are route files either way, and the banner is served from a script tag rather than bundled.
GitHub, GitLab or Bitbucket. Poliogo looks for svelte.config.js to confirm this is a SvelteKit project and finds the router directory from the files that are actually there.
A plain-English list of every service your code calls — payments, login, analytics, AI — with the file and line each one was proved from. Nothing is written until you approve it.
It adds src/routes/privacy/+page.svelte and its two siblings, and mounts the banner in src/app.html. One review, one merge, and /privacy answers.
The next time a scan finds a tracker in your code, the next pull request follows with a plain-English diff explaining what changed and why — on its own on GitHub with Pro Builder, on your one-click approval otherwise.
What you get on a SvelteKit project
The banner is one part of it. The scan underneath is what keeps the rest true.
It finds the trackers itself
AutomaticOne scan of your SvelteKit project spots Google Analytics 4, Plausible, PostHog, Sentry and around fifty more — and sorts each into strictly necessary, analytics or advertising without being told.
It holds them until people agree
Most banners record a choice and let the scripts run regardless. This one gates execution, which is the behaviour the ePrivacy Directive describes and the one an auditor can actually observe.
Policy pages, not just a banner
Privacy, cookie and terms pages written into your project — src/routes/privacy/+page.svelte and its siblings — so they are yours, indexable, and styled by your own layout.
Geo-aware without a country list
European visitors get a consent gate, Californians an opt-out with Global Privacy Control honoured, Israeli visitors their own regime. GDPR is on every plan; CCPA and Israeli law from Starter.
It notices when you add something
DriftThe next scan of the repository is diffed against the snapshot your documents were generated from, so a new tag becomes an update you approve rather than a quiet inaccuracy.
Consent Mode v2 and TCF 2.3
Google Consent Mode v2 signals go out on every plan, so your ad reporting keeps modelling conversions for visitors who decline. IAB TCF 2.3, which many EU ad networks require, is included from Pro Builder.
Questions people ask
Will the banner slow down my SvelteKit site?
No. The banner is a small async script that loads in the background and paints in one frame — it is not a framework, a UI library or a tag manager. Your Core Web Vitals do not move, which matters because for most sites the consent banner is the only third-party script on a page that has any reason to be there.
Does it actually block Google Analytics 4 before someone agrees?
Yes, and that is the difference worth paying attention to. An analytics import at the top of +layout.svelte is evaluated during SSR and again on hydration. Both fire before the banner's onMount, so consent arrives after two pageviews rather than none. Poliogo holds the non-essential scripts back until a visitor chooses, rather than asking politely while they run anyway — which is the part regulators look at.
Where does the privacy policy page end up in a SvelteKit project?
At src/routes/privacy/+page.svelte, which serves /privacy. It is a normal file in your project — your layout wraps it, your styles apply to it, and you can edit it afterwards like anything else in the repository.
Do I need to know which cookies my site sets?
No — that is the scan's job. It finds the tracking your project actually uses (Google Analytics 4, Plausible, PostHog and around fifty more), sorts each one into strictly necessary, analytics or advertising, and writes the cookie table for you. You confirm the list rather than compiling it.
Is this free?
The Free plan covers one project with a privacy policy, a cookie policy, the banner and unlimited manual re-scans — no credit card, and not a trial. Paid plans add Terms of Service, automatic background monitoring, more projects and the MCP server for Cursor and Claude Code.
What happens when I add a new tracker later?
The next scan of the repository sees it, updates the cookie classification and the policy text, and shows you exactly what changed in plain English before anything is published. On Free you run that scan whenever you like; paid plans watch for it in the background.
Put a working consent banner on your SvelteKit site
Connect the project and see what the scan finds in under 60 seconds. Free plan, no credit card, and nothing is written or published until you approve it. Poliogo is a compliance management technology platform, not a law firm, and this page is not legal advice.
Start free — no credit cardPoliogo is an automated code analysis and document display tool, not a law firm. Poliogo does not provide legal advice, representation, or guarantees of statutory compliance, ADA/WCAG certification, or legal immunity. Visual banners and generated documents are advisory tools and do not substitute for professional legal review.