Free, for every domain
No plans, tiers or traffic limits. Run one site or two hundred client sites from the same installation. The only cost is the small server you already know how to run.
ZenoCookieConsent is a complete consent management platform you run on your own server: a fast, accessible cookie banner, a proof-of-consent log and a multi-tenant dashboard for every site you manage. No per-domain fees. No consent data leaving your infrastructure.
Free for unlimited domains Consent logs in your database Reject as easy as accept 7 languages
Every consent receipt stays on your servers. Not ours, not anyone else's.
Why ZenoCookieConsent
Consent management became a subscription business: priced per domain, per pageview or per seat, with your visitors' consent records stored in someone else's cloud. It does not have to be.
No plans, tiers or traffic limits. Run one site or two hundred client sites from the same installation. The only cost is the small server you already know how to run.
Proof of consent is your legal obligation, so the records should be yours too. Receipts live in your PostgreSQL database and exports in your own S3-compatible bucket.
Equal-prominence reject, nothing pre-ticked, scripts blocked until consent, withdrawal one click away. The defaults follow EU law, so you do not have to find the right toggles.
Everything a CMP needs
Banner, blocking engine, audit trail and an admin dashboard for teams and agencies. Nothing is held back for a paid plan, because there is no paid plan.
Bottom bar, top bar or centred modal. Keyboard and screen-reader friendly, isolated in a Shadow DOM.
Mark tags with data-zeno. Scripts, iframes and pixels stay inert until their category is granted.
An append-only receipt for every choice: what was chosen, when, in which language and against which banner revision.
Edit as a draft, publish an immutable snapshot. You can always prove exactly which text a visitor saw.
Organizations, domains and roles (Owner, Admin, Member, Viewer). Made for agencies and their DPOs.
English, German, Danish, Spanish, French, Swedish and Norwegian, picked from the visitor's browser.
One attribute, data-gcm, sends the default and update signals your Google tags expect.
Returning visitors get their tags released synchronously, before any network request to the consent server.
How it works
One server for all your sites. One script tag per site. Your tags keep working, they just wait for permission first.
./install.sh --domain consent.example.com starts the app (dashboard, API and banner script), PostgreSQL, MinIO and Caddy with automatic HTTPS. Self-hosting guide
Pick colours, position and texts in up to seven languages, list your cookies, then publish revision 1.
Put zeno.js first in your <head> and change the type of tags that need consent. Done.
<!-- 1. First thing in <head>, synchronous -->
<script src="https://consent.example.com/zeno.js"></script>
<!-- 2. Blocked until "analytics" is granted -->
<script type="text/plain" data-zeno="analytics"
src="https://stats.example.com/script.js"></script>
<!-- 3. Embeds load only with "marketing" consent -->
<iframe data-zeno="marketing"
data-src="https://www.youtube-nocookie.com/embed/…"></iframe>
<!-- 4. Let visitors change their mind -->
<button onclick="Zeno.show()">Cookie settings</button>
Categories: necessary (always on), functional, analytics, marketing. Full contract in the integration docs.
Compliance
Valid consent under the GDPR and the ePrivacy Directive has to be free, specific, informed, unambiguous and as easy to withdraw as to give. ZenoCookieConsent makes those the defaults, not the settings you have to hunt for.
Zeno.show() to withdraw at any time.Choose which cookies we may use. You can change this at any time from the cookie button in the corner.
Needed for the site and your basket to work.
Remembers preferences such as language and region.
Helps us understand how the shop is used.
Personalised ads and embedded videos.
Compared with paid CMPs
Hosted consent platforms are polished products, and some offer things we do not (yet). Here is an honest view of the trade-off.
| ZenoCookieConsent | Typical paid CMP | |
|---|---|---|
| Price model | Free and open source | Subscription per domain, often tiered by traffic or features |
| Number of domains | Unlimited, in one installation | Bound to your plan |
| Where consent records live | Your PostgreSQL database | The vendor's cloud |
| Third-party processor | None. You operate it. | Yes, with a DPA and transfer assessment |
| Banner script served from | Your own domain | The vendor's CDN |
| Equal-prominence reject | Enforced by design | Usually possible, depends on configuration |
| Lock-in | Open source, your data, standard SQL | Proprietary platform |
| Automatic cookie scanning | Not included. You maintain the cookie list. | Commonly included |
| IAB TCF support | Not supported | Often available |
| Operations | You run updates and backups | Managed for you |
It is free and open source. There is no paid tier, no domain limit and no feature held back. The trade-off is that you host it: you need a server with Docker and someone who keeps it updated and backed up.
A Linux server with Docker Engine 24+ and the Compose v2 plugin (1 vCPU, 1 GB RAM and 10 GB disk are enough to start) and a DNS name such as consent.example.com. Run git clone <repository> && cd zenocookieconsent && ./install.sh --domain consent.example.com, or curl -fsSL https://zenocookieconsent.citiumsoftware.com/install.sh | bash. The installer starts the app, PostgreSQL, MinIO and Caddy with automatic HTTPS. More on self-hosting.
It gives you the tools and compliant defaults: equal reject, prior blocking, granular choices, receipts and easy withdrawal. Compliance also depends on how you configure it, which tags you mark for blocking and what your privacy policy says. It is not legal advice.
Any <script> (external or inline), <iframe> and <img> you mark with data-zeno, including elements added later by other scripts. With data-gcm, Google tags also receive Consent Mode v2 signals.
A random receipt id from the visitor's browser, the choice per category, the consent version and banner revision, language, the page URL without query string, the user agent and a keyed hash of the truncated IP address. No names, emails or account ids.
Yes. Organizations hold domains and members, and every member has a role per organization: Owner, Admin, Member or Viewer. A client's DPO can get read-only access to their consent log.
Install ZenoCookieConsent on your own server today. It is free for every site you run, now and later.