# The site check

What the check looks at and what the numbers mean.

The check opens your site in a fresh browser in Western Europe, visits up to six pages without clicking anything, and records what loads.

## What you see

- **Cookies and trackers before a visitor agrees**: cookies and outside services in the Statistics or Advertising categories that loaded before the visitor made a choice. In Europe and the UK, this is what regulators fine sites for. The number should be zero.
- **Cookies**: every cookie and browser storage key we found, with what it is for and which company set it.
- **Outside services**: other websites your pages contacted while loading. Fonts, payments and security checks are normal. Ad networks and analytics are trackers.
- **Other cookie banner found**: if your site already has a cookie banner, we name it so you can remove it after switching.

## How we know what a cookie is for

1. We look it up in a database of thousands of known cookies and services.
2. For anything the database doesn't know, an AI model (Jev, from TypeSafe) picks the most likely of the four categories and says how sure it is. Below 70 percent we mark it **Not sure** instead of guessing. A cookie is only treated as Required when the model is at least 90 percent sure, and an outside service is never treated as Required on the model's word alone.
3. You have the last word. Every row on the Cookies tab has a **Used for** choice you can change, and outside services have a **Before a visitor agrees** switch (Blocked or Runs). Your corrections are kept when the site is checked again.
4. Services that sites need in order to work, such as reCAPTCHA, Cloudflare and payment providers, are always Required.

## How accurate the AI is

We measure it. We take 400 cookies whose purpose we already know (100 of each kind), hide the answer, and ask the model to judge each one from its name and the domain that set it, the same information it gets during a check. Results from 27 September 2026, model jev-1.13.0:

- **Whether a cookie needs consent:** right 96.9% of the time. This is what decides whether the banner holds a cookie back.
- **Cookies a site needs to work:** 92 of 100 recognised as required. A cookie is only marked required when the model is at least 90% sure, and an outside service is never marked required on the model’s word.
- **The exact category:** right 65% of the time. Most mistakes are preferences mistaken for statistics or the other way round. Both wait for consent, so these mistakes don’t change what the banner blocks.

The AI only judges cookies our database doesn’t already know, and you can correct any category on the Cookies tab. We re-run this measurement when the model changes and update this page.

## What happens with the results

- Trackers we are sure about become rules, and the banner holds them until a visitor agrees. Anything we are unsure about waits for you to pick what it is used for on the Cookies tab.
- The cookie list page for your visitors is built from the results.
- The banner's colours, font and wording are taken from your pages.
- Where the banner shows follows the law where each visitor is. See [Where the banner shows](/docs/regions).

Run a new check (**Visit again** on the Cookies tab) whenever you add a tool to your site. Checks browse from Western Europe, so the results show what a first-time visitor there meets. Each check records the country it browsed from.

## Monthly checks

We check every site again every 30 days. If a check finds something new that would run before visitors choose, or something we can't identify, we email you and show it at the top of the Cookies tab. Nothing changes on your site until you decide.

## Seen on real visits

Our visit only sees public pages, and it never signs in. Services that only load behind a login, such as in-app chat, product analytics or session recording, are invisible to it.

So the banner itself reports what it sees on real visits. On about one page view in ten, it sends the names of the outside services the page contacted and the names of the cookies the page can read, never their values and nothing about the visitor. The Cookies tab lists anything those visits found that our visit didn't, with the company and what it's used for when we know them. Pick what each is used for and whether it waits for consent, as with everything else on the tab.

The list leaves out noise: a name has to turn up on at least 3% of reports, and hosts that browser extensions add to pages (password managers, writing assistants, shopping add-ons) are dropped. It starts after 10 reports and covers the last 7 days.
