Most GPC checkers just read the header. We load your site with the signal on and prove whether trackers actually stop.
California's Attorney General fined Sephora $1.2M in 2022 for this exact failure: the site kept sharing data with third parties after receiving a GPC opt-out.
One page, three checks. Most scans finish in under 2 minutes. A compliance score and grade, a verdict on each check, and a count of what passed and what needs attention.

Privacy policy analysis reads N/A above because it is part of the full audit, not the free check.
Enough to know whether you have a problem, not enough to fix it. The full audit is the same scan with the findings unlocked.
Creating an account includes one free credit, which unlocks the full audit on the URL you just checked. One credit covers one URL and all 54 checks. See a full sample report before you scan.
Every page is revisited with Sec-GPC: 1 header set, exactly like a Firefox or Brave visitor who has Global Privacy Control enabled.
Once without the signal, once with it. Comparing the two request sets is the only way to prove an opt-out was enforced rather than merely received.
Each tracker that keeps firing is mapped to the California regulation it breaches, with the request evidence attached, ready to hand to counsel.
A header-only tool tells you your server received the Sec-GPC header. That is the easy half. The half that gets enforced is what your tag manager, ad pixels, and analytics scripts do next, and none of that is visible from the request headers alone.
Consent platforms advertise GPC support out of the box, but a single hardcoded pixel added outside the CMP will keep firing after an opt-out, and the CMP will still report itself as compliant. The only way to settle it is to watch the outbound requests. Our full guide to GPC testing walks through the failure modes we see most often.
Global Privacy Control (GPC) is a user-configurable browser setting or extension that automatically notifies websites of the user's privacy preferences, signaling an opt-out from the sale or sharing of their personal information.
Yes. Under California's CCPA/CPRA regulations (§ 7025), businesses must recognize universal opt-out signals like GPC as valid requests to opt-out of data sale or sharing. Colorado, Connecticut, Texas, Oregon, and other states also mandate Universal Opt-Out Mechanism (UOOM) recognition.
No. There is no script, tag, or DNS change. Privisy loads your public pages in a headless browser from the outside, the same way a real visitor would, so you can run a check on a site you do not control.
Browser extensions send the GPC header, but they cannot verify if your backend server or tag managers actually block third-party trackers at the network layer. Privisy intercepts outbound traffic in a headless browser to prove compliance or identify leaks.
The scan behaves like a small number of ordinary page views and does not write to your site. It may register as a handful of sessions in your analytics. It does not submit forms, create accounts, or touch anything behind a login.
It is stored against your scan so you can return to the report later. We do not sell data, and we do not share the URL or the findings with anyone else. You can delete a report from your dashboard at any time.
One URL, no credit card. Most scans finish in under 2 minutes.
Run a free GPC check