Not “we comply”. Here is what compliance looks like.
Valid consent must be freely given, specific, informed, unambiguous and withdrawable. Each of those is a design decision in the dialog below.
Allow the app to use a small amount of your unused internet bandwidth. Only on Wi-Fi, only while charging.
no personal data · turn off anytime in settings
annotated · numbers match the principles
“Support this app — no ads” states what the user gets in exchange. A purpose that is disclosed but not understandable does not make consent informed.
Wi-Fi only, charging only, no personal data, scope named. Conditions that appear after the tap are not conditions the user agreed to.
Same size, same position, same tap target, no pre-selection. A decline that is harder to reach than an accept is the single most common reason a consent flow fails review.
The SDK stays inactive until a grant exists. On decline it does not initialise, does not retry, and does not ask again on the next launch.
Withdrawal has to be as easy as granting. The revocation is written to the log and honored on the device within seconds, not at the next session.
Every decision leaves a receipt.
A grant and a withdrawal are the same kind of record. That is what makes the consent state auditable rather than assumed.
One master list, enforced at the gateway.
Not a statement of intent. Requests to prohibited categories are dropped before they leave our infrastructure.
| No. | Category | Examples | Status |
|---|---|---|---|
| 01 | Public web data | Price monitoring, ad verification, brand protection, market research | PERMITTED |
| 02 | Search results & SERP | Rank tracking, visibility monitoring at documented rates | PERMITTED |
| 03 | Critical infrastructure | Energy, utilities, telecom, transportation, emergency services | PROHIBITED |
| 04 | Email, cloud & productivity | Email providers, cloud storage, collaboration platforms | PROHIBITED |
| 05 | Financial infrastructure | Banks, payment systems, card networks, crypto exchanges | PROHIBITED |
| 06 | Government & military | .gov, .mil, law enforcement, public administration | PROHIBITED |
| 07 | Healthcare & education | Medical databases, .edu, student information systems | PROHIBITED |
| 08 | Account creation & abuse | Bulk registration, credential stuffing, ticket and sneaker bots | PROHIBITED |
| 09 | Attack traffic | DDoS, port scanning, vulnerability probing, malware distribution | PROHIBITED |
Four steps, one gate.
Prohibited destinations are dropped at our gateway, in the EU — not on the user's device, and not on trust.
Data and jurisdiction.
Store readiness.
What a partner gets for the review process, so the store conversation is not improvised:
First in, best terms.
A limited set of founding partners get elevated rates, a direct line to the team, and a say in the SDK roadmap.
Request access