# Poliogo > Poliogo is an automated cookie consent and legal compliance platform for developers, indie hackers and agencies. It connects to a codebase, finds the third-party services that code actually calls — including raw fetch and axios calls to APIs with no SDK installed — generates the Privacy Policy, Terms of Service and Cookie Policy those services require, installs a consent banner that blocks trackers before consent, and opens a pull request when a scan finds the stack has changed and the documents stopped being true. It also ships a keyboard-operable accessibility menu and scans pages against WCAG 2.1 and 2.2 level AA, reporting the criteria a page fails with the file and line for each. Poliogo is a compliance platform, not a law firm, and nothing it produces is legal advice. It is built for the case where the code changes faster than the paperwork: the documents are regenerated from what the repository proves, not from a questionnaire answered once at launch. ## Plans - **Free** (free) — Ship your first project with its policies in place. - **Starter** ($15/mo, $12/mo billed annually) — For indie devs shipping fast. - **Pro Builder** ($49/mo, $39/mo billed annually) — For serious builders and growing startups. - **Agency** ($149/mo, $119/mo billed annually) — For agencies managing client sites. Manual drift scans and consent banner views are unlimited on every plan, Free included. Full comparison: https://poliogo.com/pricing ## Start here - [Home](https://poliogo.com): what the product does, and the four-step flow - [Pricing](https://poliogo.com/pricing): all four plans, feature by feature - [Connectors](https://poliogo.com/connectors): every way to connect a project, and what each one reads - [Setup guides](https://poliogo.com/docs): connecting a project, per provider - [Documentation](https://poliogo.com/documentation): MCP setup, CLI commands, config files and the embed/document APIs - [Integrations](https://poliogo.com/for): what each service in a stack collects and which clauses it forces - [Free scan, no account](https://poliogo.com/scan): paste a public repository or a live web address and see what it finds - [Changelog](https://poliogo.com/changelog): what shipped and when ## Product - [A cookie banner that blocks trackers before consent](https://poliogo.com/product/cookie-cmp): Poliogo scans your site, classifies every cookie and tracking script, and ships a banner that holds trackers back until a visitor agrees — and writes a consent record for every choice. Geo-aware, Consent Mode v2 and TCF 2.3 ready, and styled to match your brand. - [Three documents, written from what your code actually does](https://poliogo.com/product/legal-documents): Privacy Policy, Cookie Policy and Terms of Service — assembled from a maintained clause library built from published regulatory text, matched to the services Poliogo detects in your code. Documents you can read, edit, and own. - [A privacy policy written from your real product](https://poliogo.com/product/privacy-policy): Most privacy policies are copied from a template and describe a business that isn't yours. Poliogo reads the services your code actually uses and assembles a policy that matches — then keeps it matching. - [Terms written for the way you actually sell](https://poliogo.com/product/terms-conditions): Subscriptions, free trials, refunds, what happens when someone breaks the rules, and how much you can be held responsible for — all covered, in language you can read once and understand. - [Reads your code to find every service you use](https://poliogo.com/product/stack-fingerprinting): Poliogo reads your project — and produces the list of services your product really talks to. That list is the base of what your documents and banner are built from. - [Compliance checks inside your AI editor](https://poliogo.com/product/mcp-server): Poliogo ships a first-party MCP server for Cursor, Claude Code and Windsurf. Your agent scans the workspace, generates documents, installs the pages and checks for drift — without you ever opening a dashboard. - [Built for vibe-coders and what no-code platforms generate](https://poliogo.com/product/no-code-platforms): Every one of these builders writes its code somewhere you can connect. Lovable, Bolt.new, Base44, Replit and FlutterFlow sync to GitHub, and v0 deploys through Vercel. Turn that sync on once, point Poliogo at it, and it reads the stack your builder actually generated — giving you back documents and a banner in one embed snippet, with no Git knowledge required. - [Add a new service and Poliogo tells you what changed](https://poliogo.com/product/drift-monitoring): The day you add a new tool, your privacy policy quietly becomes wrong. Poliogo re-scans your project, compares it against the snapshot your documents were written from, and explains the difference in plain English. - [Poliogo writes the code and opens a PR. You review and merge.](https://poliogo.com/product/automatic-pull-requests): Policy updates shouldn't arrive as emails. Poliogo pushes a branch with the updated documents and banner wiring, opens a pull request with a plain-English explanation of what changed and why, and waits for your review. - [A banner that looks like you built it](https://poliogo.com/product/design-customizer): Vibe Presets get you shipping in under 60 seconds. Full customization, Magic Brand Auto-Detect and complete CSS control are there when you want the banner, modals and Trust Center to be indistinguishable from your own UI. - [When someone asks for their data, it's already handled](https://poliogo.com/product/dsar-portal): People have the right to ask for a copy of their information, or to have it deleted. Poliogo gives you an intake page, verifies it's really them, and tracks every request against its legal deadline. - [One public page with your policies](https://poliogo.com/product/trust-center): When a customer, a partner, or a big client asks how you handle data, send them a link. It shows your current policies, the processors involved, and when everything was last updated — white-label on Agency. - [An accessibility menu on your site, and a statement that tells the truth](https://poliogo.com/product/accessibility-widget): Poliogo adds a floating accessibility menu to your pages — text size, contrast, dyslexia-friendly font, stop animations, large cursor — scans your code for the accessibility failures a machine can prove against WCAG 2.2 AA, the benchmark behind the ADA, EN 301 549 and IS 5568, and publishes an accessibility statement written from what it actually found. ## Who it is for - [One subscription covers every side project](https://poliogo.com/solutions/indie-developers): Ship your first version with the documents already in your repo. Starter covers three projects with MCP built in, weekly automatic scans, and no per-site billing — so the next side project doesn't mean the next invoice. - [Daily scans and automatic updates as your product ships](https://poliogo.com/solutions/startups): Your team merges every day, and every merge can change what your product collects. Pro Builder scans daily, writes the policy updates automatically, and pushes them to a side branch for review — so compliance keeps pace with your release cadence. - [Unlimited client sites, your branding, separate client logins](https://poliogo.com/solutions/agencies): Look after every client website from one screen, with real-time monitoring across the portfolio and your own name on the whole thing. Clients get scoped logins that show them only their own projects. - [Built for what Lovable, Bolt.new, v0 and Base44 generate](https://poliogo.com/solutions/ai-no-code-builders): Your builder wired Stripe, Supabase and OpenAI into your app in an afternoon. Poliogo reads what the generated code actually calls — including the raw HTTP requests no template ever mentions — and produces the documents that match. ## Cookie consent, by framework - [Cookie consent for Next.js](https://poliogo.com/cookie-consent-nextjs): Installed automatically as a pull request. Detected from next.config.js; policy page at /privacy. - [Cookie consent for React](https://poliogo.com/cookie-consent-react): Installed automatically as a pull request. Detected from vite.config.ts; policy page at /privacy. - [Cookie consent for WordPress](https://poliogo.com/cookie-consent-wordpress): Hosted platform — one script tag, banner and policy pages served by Poliogo. Detected from your theme's header.php; policy page at /privacy. - [Cookie consent for Shopify](https://poliogo.com/cookie-consent-shopify): Hosted platform — one script tag, banner and policy pages served by Poliogo. Detected from your theme's theme.liquid; policy page at /pages/privacy-policy. - [Cookie consent for Vue](https://poliogo.com/cookie-consent-vue): Installed automatically as a pull request. Detected from vite.config.ts; policy page at /privacy. - [Cookie consent for Nuxt](https://poliogo.com/cookie-consent-nuxt): Installed automatically as a pull request. Detected from nuxt.config.ts; policy page at /privacy. - [Cookie consent for SvelteKit](https://poliogo.com/cookie-consent-sveltekit): Installed automatically as a pull request. Detected from svelte.config.js; policy page at /privacy. - [Cookie consent for Astro](https://poliogo.com/cookie-consent-astro): Installed automatically as a pull request. Detected from astro.config.mjs; policy page at /privacy. - [Cookie consent for Angular](https://poliogo.com/cookie-consent-angular): Detected and named; the route registration is handed over as exact steps. Detected from angular.json; policy page at /privacy. - [Cookie consent for Remix](https://poliogo.com/cookie-consent-remix): Detected and named; the route registration is handed over as exact steps. Detected from remix.config.js; policy page at /privacy. - [Cookie consent for Laravel](https://poliogo.com/cookie-consent-laravel): Detected and named; the route registration is handed over as exact steps. Detected from artisan; policy page at /privacy. - [Cookie consent for Django](https://poliogo.com/cookie-consent-django): Detected and named; the route registration is handed over as exact steps. Detected from manage.py; policy page at /privacy/. - [Cookie consent for Ruby on Rails](https://poliogo.com/cookie-consent-rails): Detected and named; the route registration is handed over as exact steps. Detected from config/routes.rb; policy page at /privacy. - [Cookie consent for Webflow](https://poliogo.com/cookie-consent-webflow): Hosted platform — one script tag, banner and policy pages served by Poliogo. Detected from Project Settings → Custom Code; policy page at /privacy. - [Cookie consent for Framer](https://poliogo.com/cookie-consent-framer): Hosted platform — one script tag, banner and policy pages served by Poliogo. Detected from Site Settings → General → Custom Code; policy page at /privacy. - [Cookie consent for static HTML](https://poliogo.com/cookie-consent-html): Hosted platform — one script tag, banner and policy pages served by Poliogo. Detected from index.html; policy page at /privacy.html. ## Regulations covered - [GDPR — General Data Protection Regulation](https://poliogo.com/gdpr-compliance-generator): Applies to anyone in the EU or the EEA, wherever your company is registered. Dedicated clause set. - [UK GDPR — UK General Data Protection Regulation and Data Protection Act 2018](https://poliogo.com/uk-gdpr-compliance-generator): Applies to anyone in the United Kingdom. Dedicated clause set. - [CCPA / CPRA — California Consumer Privacy Act, as amended by the CPRA](https://poliogo.com/ccpa-privacy-policy): Applies to residents of California. Dedicated clause set. - [EU AI Act — EU Artificial Intelligence Act (Regulation 2024/1689)](https://poliogo.com/eu-ai-act-compliance-generator): Applies to anyone in the EU who uses, or is subject to, an AI system you provide. Dedicated clause set. - [COPPA — Children's Online Privacy Protection Act](https://poliogo.com/coppa-compliance-generator): Applies to children under 13 in the United States. Dedicated clause set. - [US state privacy laws — the comprehensive state privacy statutes (VCDPA, CPA, CTDPA, UCPA and successors)](https://poliogo.com/us-state-privacy-compliance-generator): Applies to residents of the twenty-odd US states with a comprehensive privacy statute. Dedicated clause set. - [Amendment 13 — Israeli Protection of Privacy Law, Amendment 13](https://poliogo.com/israel-amendment-13-compliance-generator): Applies to people in Israel. Dedicated clause set. - [ePrivacy Directive — ePrivacy Directive 2002/58/EC, the 'cookie law'](https://poliogo.com/eprivacy-compliance-generator): Applies to anyone accessing your site from the EU. Dedicated clause set. - [LGPD — Lei Geral de Proteção de Dados](https://poliogo.com/lgpd-compliance-generator): Applies to people in Brazil. Covered by the global baseline clauses. - [PIPEDA — Personal Information Protection and Electronic Documents Act](https://poliogo.com/pipeda-compliance-generator): Applies to people in Canada. Covered by the global baseline clauses. ## Integrations, by service - [Next.js](https://poliogo.com/for/nextjs): Framework. Next.js is where the compliance surface and the code sit closest together: the policy pages are routes, the banner is a layout concern, and both are files a pull request can carry. - [Supabase](https://poliogo.com/for/supabase): Backend. Supabase is database, file storage and authentication in one project, so a single dependency is simultaneously where user records live, where uploads live, and the thing setting session cookies — three disclosures from one line of your manifest. - [Vercel](https://poliogo.com/for/vercel): Hosting. Vercel is a sub-processor you did not decide to add — it is where the application runs, so every visitor's IP address reaches it before a single line of your own code does. - [Lovable](https://poliogo.com/for/lovable): AI builder. Lovable writes the code, which means integrations arrive in your project without you ever typing the import — and a policy that was accurate on launch day is stale by the next prompt. - [Stripe](https://poliogo.com/for/stripe): Payments. Stripe is the integration that changes your Terms of Service as well as your Privacy Policy — refunds, billing and tax are contract terms, and no amount of privacy drafting covers them. - [OpenAI](https://poliogo.com/for/openai): AI. Sending a user's text to a model is a disclosure obligation in its own right: the EU AI Act asks you to say an AI system is in use, and GDPR Article 22 asks whether a decision was made about somebody by a machine. - [Anthropic](https://poliogo.com/for/anthropic): AI. Claude in a product means user content leaves your infrastructure to be analysed, and the retention window is contractual rather than something your own code controls. - [Clerk](https://poliogo.com/for/clerk): Authentication. Authentication is the one integration that is definitionally personal data — there is no anonymous mode, and the session cookie is set before a visitor has agreed to anything at all. - [Firebase](https://poliogo.com/for/firebase): Authentication. Firebase is Google under another name, so adding it puts Google LLC into your sub-processor schedule even in a product with no Google Analytics anywhere near it. - [PostHog](https://poliogo.com/for/posthog): Analytics. Session replay is the part that changes the legal answer: recording somebody's screen is categorically different from counting a page view, and most policies describe only the counting. - [Google Analytics](https://poliogo.com/for/google-analytics): Analytics. Google Analytics is the most-litigated integration on the web — data protection authorities in Austria, France, Italy and Denmark have each found a plain deployment of it unlawful on transfer grounds. - [Meta Pixel](https://poliogo.com/for/meta-pixel): Advertising. Under California, Colorado, Connecticut and Virginia law an advertising pixel is a sale or share of personal data — which obliges you to offer an opt-out, not merely to describe what you are doing. - [Mixpanel](https://poliogo.com/for/mixpanel): Analytics. Mixpanel builds a profile per person rather than a count per page, which moves it out of analytics and into profiling — a word the GDPR defines and gives people a right to object to. - [Sentry](https://poliogo.com/for/sentry): Monitoring. Sentry is the integration that collects personal data by accident — a stack trace carries whatever happened to be in scope at the moment the code threw. - [Pinecone](https://poliogo.com/for/pinecone): AI. A vector database is why “delete my data” is harder than it looks: an embedding derived from a deleted record is still derived from a person, and it does not vanish when the row does. - [Resend](https://poliogo.com/for/resend): Email. Transactional email is the integration people forget is an integration — a password reset is still a third party receiving your user's address and the contents of the message. - [Shopify](https://poliogo.com/for/shopify): Commerce. A storefront collects shipping addresses, which is the one category of personal data that is unavoidable, un-minimisable and has to be retained for tax far longer than anything else in the product. - [Netlify](https://poliogo.com/for/netlify): Hosting. Netlify sits between every visitor and your site, which makes its request log a record of who came to see you — held by a company most privacy policies never name. - [Cloudflare](https://poliogo.com/for/cloudflare): Hosting. Cloudflare sets a cookie on your visitors that you did not write, cannot remove and are nevertheless the one responsible for disclosing. - [Replit](https://poliogo.com/for/replit): AI builder. A repl is the editor, the host and the database at once, so Replit, Inc. holds both the code you are writing and the data your visitors leave behind in it. - [WordPress.com](https://poliogo.com/for/wordpress): Commerce. WordPress.com hosts the site and the plugins, so the list of third parties on a WordPress page is set by an admin screen rather than by anything a developer committed. ## Compared with other tools - [Poliogo vs Termly](https://poliogo.com/vs/termly): Termly asks you what your product does. Poliogo reads the code and finds out — including the services you forgot you added. (entry reviewed 2026-08-30.) - [Poliogo vs iubenda](https://poliogo.com/vs/iubenda): iubenda has you pick your services from a catalogue, one site at a time. Poliogo detects them from the source and keeps the list current as the code changes. (entry reviewed 2026-08-30.) - [Poliogo vs Osano](https://poliogo.com/vs/osano): Osano is built for a privacy team running a compliance programme across a whole company. Poliogo is built for the developer who has to ship the policy this afternoon. (entry reviewed 2026-08-30.) - [Poliogo vs Ketch](https://poliogo.com/vs/ketch): Ketch orchestrates consent across a data stack. Poliogo makes sure the documents describing that stack are true — starting from the code. (entry reviewed 2026-08-30.) ## Company - [Your policies should keep up with your code](https://poliogo.com/company/about): Every product ships with a privacy policy that was true on the day it was written. Then the product changes — a new analytics script, a different payment provider, an AI call — and the documents quietly stop being true. Poliogo watches your stack and keeps them matching the code, automatically. - [We read your code. We never keep it.](https://poliogo.com/company/security): Poliogo analyses your repository in memory and keeps the list of services it detected. The files the scanner reads are never stored; the one thing kept from your repository is the original of a file Poliogo edited when it installed your pages, so deleting the project can restore it. Every connection runs over TLS 1.3. - [Talk to the people who built it](https://poliogo.com/company/contact): Questions about what applies to you, help getting set up, agency pricing, or a customer's security review — you reach the actual team, not a ticket queue. ## Optional - [Full documentation for LLMs](https://poliogo.com/llms-full.txt): everything above, expanded — the file to read if you can fit it - [Sitemap](https://poliogo.com/sitemap.xml): every indexable URL - [Poliogo's own Privacy Policy](https://poliogo.com/legal/privacy): the document itself, in full - [Poliogo's own Terms of Service](https://poliogo.com/legal/terms): the document itself, in full - [Poliogo's own Cookie Policy](https://poliogo.com/legal/cookie): the document itself, in full - [Poliogo's own Legal Disclaimer](https://poliogo.com/legal/disclaimer): the document itself, in full - [Poliogo's own Data Processing Addendum](https://poliogo.com/legal/dpa): the document itself, in full Contact: support.polio.ai@gmail.com