Skip to content

Consent security and data: what is stored and where

For each choice the log keeps the date, the categories, the type of choice, the banner language, the page path (if you leave it on), the country, the domain the choice came from, a random record ID and the ID of the previous record if the visitor changed an earlier choice. It does not keep IP addresses, browser data, names or emails.

The banner sets one first party cookie on your site, fb_consent. It holds the record ID, the version number of your consent settings, the allowed categories as a number and the time of the choice. It lives for the consent period, about 12 or about 6 months, with Path=/ and SameSite=Lax, and with Secure on https pages. This cookie is necessary: without it the banner would ask on every page. If the browser refuses the cookie, the choice lasts only until the visitor leaves the page.

The page behind a record ID needs no sign in. Anyone who has the exact address can open it. The ID is random, and search engines are told not to index the page. It shows the choice and the banner text, and nothing else about the visitor.

Sites, settings and the log are stored in a Cloudflare D1 database. The script for each site is stored in Cloudflare KV and served from fewbase.com. Emails go out through the fewbase platform.

  • Log records: 12 months, then deleted by a job that runs every night.
  • A deleted site: its settings are removed when its last log record is deleted.
  • The script is about 10 KB compressed, plus about 1 KB for each language.
  • Browsers cache it for 5 minutes. That is why changes take up to 5 minutes to appear.
  • It loads in the <head> without async. If fewbase.com cannot be reached, the browser skips the script: your page works, the banner is not shown, the connected tools do not load, and tags you marked with type="text/plain" stay off.
  • The line of code cannot use Subresource Integrity (integrity=), because the script changes when you save settings.

Only the owner of the fewbase account. Changes to connectors and own scripts are emailed to the owner and listed on the Changes tab.

  • The banner does not scan your site. A script you did not connect or mark runs as before.
  • The log checks which domain a record comes from, but a request can fake it. Someone could send false records to use up the monthly limit of a site. There is a rate limit per site and address. If this happens to you, write to us.