( Consent log )

Proof of consent a regulator would actually accept

Every choice stored with a timestamp, the categories agreed to, the policy version shown, the coarse region, and a signature. Exportable to CSV whenever somebody asks.

https://

Free scan · no account · results in about a minute

( How it works )

A record of a decision, not a record of a person

Each record holds when the choice was made, what was agreed to, which version of your policy was on screen at the time, a coarse region, and a signature that shows the row has not been edited since. There is no visitor identifier, deliberately: the record proves a decision happened under stated terms, and attaching an identity to it would make the compliance artefact into personal data of its own. Records are held in the EU for 24 months.

Specifics
Stored per record
timestamp, decision, categories, policy version, region, signature
Not stored
No visitor identifier, no IP, no fingerprint
Retention
24 months, in EU, Frankfurt
Export
CSV, on demand, no ticket required

The same records, summarised monthly in your own branding. What an agency sends a client without writing anything.

( Worth knowing )

A count is not evidence

Plenty of tools show you how many people accepted. That is a metric, not proof. What gets asked for in a complaint is a specific record on a specific date showing what a visitor saw and what they agreed to, and whether it has been altered since. If the answer is a dashboard number with no per-record export, the answer is no evidence.

( Questions )

What does the signature prove?

That the record has not been edited since it was written. Without it a consent log is a table somebody could have changed, which is exactly the objection raised when one is produced as evidence.

Why is the policy version stored?

Because consent is to specific terms. A record that says somebody accepted, without saying what they were shown, does not establish informed consent when your policy has changed three times since.

Can I export it?

Yes, to CSV, at any time, for one site or all of them. It is the file a client’s lawyer or a regulator asks for.

Where are the records stored?

In EU, Frankfurt, for 24 months. They stay yours: disconnecting a site or cancelling a plan does not delete them.

Also called
proof of consent GDPRconsent records export CSVcookie consent audit trailGDPR consent evidence retentionsigned consent log

$10 a site. No asterisks.

Unlimited pages, unlimited visitors, 24 months of consent records in the EU. Less per site as you add more.

Start your free trial
( More on the product )
Attesso: cookie consent for people who do not write code© 2026 · EU-hosted · $10 a site