By consent event. Never by domain.
One billing axis across the whole platform: consent events per month, pooled per organization. Adding a new site never changes the price. No paid plan gates functionality — only volume and support.
Hobby
1,000 events/month
No overage — a 20% grace band, then it pauses until you upgrade
- Cookie scanner — on-demand or scheduled, unlimited scans
- Consent statements & regulatory pages (Privacy, Terms, Cookie), versioned
- TCF v2.2, Google Consent Mode v2, DSAR, webhooks
- MCP connector for AI agents (Claude and others)
- Unlimited sites & domains, every SDK
- 2 seats · community support · no credit card
Growth
10,000 events/month
$0.25 per additional 1,000 events
- Everything in Hobby
- 10 seats, 20 webhook endpoints, 600 req/min API
- Optional overage spending ceiling, set by you
- 180-day audit log retention
- Email support
Scale
Negotiated volume, by contract
Volume-discounted rate
- Everything in Growth
- Unlimited seats & webhook endpoints, 3,000 req/min API
- 730-day (2-year) audit log retention
- Contractual SLA and dedicated support
- Negotiated DPA, data residency options
Overage past the included quota is billed once a month, on the invoice — never as standalone charges per 1,000-event block.
Full feature comparison
No paid plan gates functionality — every tier gets the same product. The only axes that change are event volume, limits, and support.
| Hobby | Growth | Scale | |
|---|---|---|---|
| Consent & vault | |||
| Consent events included | 1,000/mo | 10,000/mo | Negotiated |
| Overage | — | $0.25 / 1,000 events | From $0.18 / 1,000 (volume-discounted) |
| Unlimited sites & domains | ✓ | ✓ | ✓ |
| Every SDK (JS, iOS, Android, Flutter, WordPress, Shopify) | ✓ | ✓ | ✓ |
| Ed25519 signed, offline-verifiable receipt | ✓ | ✓ | ✓ |
| Cookie compliance | |||
| Cookie scanner, on-demand | ✓ | ✓ | ✓ |
| Scheduled recurring scans (interval you set) | ✓ | ✓ | ✓ |
| Cookie classification review queue | ✓ | ✓ | ✓ |
| Consent statements & regulatory pages | |||
| Versioned consent statements (purposes) | ✓ | ✓ | ✓ |
| Privacy Policy, Terms, Cookie Policy, Accessibility Statement — versioned | ✓ | ✓ | ✓ |
| TCF v2.2 + Google Consent Mode v2 | ✓ | ✓ | ✓ |
| Integrations & API | |||
| Webhook endpoints | 3 | 20 | Unlimited |
| API rate limit | 60 req/min | 600 req/min | 3,000 req/min |
| MCP connector for AI agents (Claude and others) | ✓ | ✓ | ✓ |
| Data rights & audit | |||
| DSAR export, rectification, crypto-shred | ✓ | ✓ | ✓ |
| Audit log retention | 30 days | 180 days | 730 days |
| Team & support | |||
| Seats | 2 | 10 | Unlimited |
| Support | Community | Contractual SLA + dedicated | |
| Overage spending ceiling | — | Optional, self-set | — |
| Standard DPA (Art. 28) | ✓ | ✓ | ✓ |
| Negotiated DPA / data residency | — | — | ✓ |
Because the domain has no relationship to what it actually costs to serve your traffic, and it penalizes anyone running multiple brands or environments. A consent event actually reflects real usage.
You get a 20% grace band above the included 1,000 events, with a console warning. Past that, new writes are explicitly rejected until you upgrade — a consent event is never silently dropped.
It accumulates through the month and is billed once, together with the base fee, as a single line on your invoice — never as separate charges per 1,000-event block.
No. Only LIVE-mode events count toward quota and the invoice.
Plug in the consent layer.
One vault, one source of truth, in the EU. One tag or one API call — your banner is live today.