Free & open source Built for EU law

Cookie consent,
without the subscription.

ZenoCookieConsent is a complete consent management platform you run on your own server: a fast, accessible cookie banner, a proof-of-consent log and a multi-tenant dashboard for every site you manage. No per-domain fees. No consent data leaving your infrastructure.

Free for unlimited domains Consent logs in your database Reject as easy as accept 7 languages

Illustration: the ZenoCookieConsent dashboard showing consent receipts for shop.example.com, and the cookie banner visitors see, with equally prominent Reject all and Accept all buttons.

Every consent receipt stays on your servers. Not ours, not anyone else's.

Why ZenoCookieConsent

Tired of paying rent on a cookie banner?

Consent management became a subscription business: priced per domain, per pageview or per seat, with your visitors' consent records stored in someone else's cloud. It does not have to be.

Free, for every domain

No plans, tiers or traffic limits. Run one site or two hundred client sites from the same installation. The only cost is the small server you already know how to run.

You own the evidence

Proof of consent is your legal obligation, so the records should be yours too. Receipts live in your PostgreSQL database and exports in your own S3-compatible bucket.

Compliant by default

Equal-prominence reject, nothing pre-ticked, scripts blocked until consent, withdrawal one click away. The defaults follow EU law, so you do not have to find the right toggles.

Everything a CMP needs

The whole platform, not a free tier.

Banner, blocking engine, audit trail and an admin dashboard for teams and agencies. Nothing is held back for a paid plan, because there is no paid plan.

Accessible cookie banner

Bottom bar, top bar or centred modal. Keyboard and screen-reader friendly, isolated in a Shadow DOM.

Prior script blocking

Mark tags with data-zeno. Scripts, iframes and pixels stay inert until their category is granted.

Proof-of-consent log

An append-only receipt for every choice: what was chosen, when, in which language and against which banner revision.

Published revisions

Edit as a draft, publish an immutable snapshot. You can always prove exactly which text a visitor saw.

Multi-tenant dashboard

Organizations, domains and roles (Owner, Admin, Member, Viewer). Made for agencies and their DPOs.

Seven languages

English, German, Danish, Spanish, French, Swedish and Norwegian, picked from the visitor's browser.

Google Consent Mode v2

One attribute, data-gcm, sends the default and update signals your Google tags expect.

Fast by design

Returning visitors get their tags released synchronously, before any network request to the consent server.

See every feature in detail

How it works

From install to compliant in an afternoon.

One server for all your sites. One script tag per site. Your tags keep working, they just wait for permission first.

1

Install on your server

./install.sh --domain consent.example.com starts the app (dashboard, API and banner script), PostgreSQL, MinIO and Caddy with automatic HTTPS. Self-hosting guide

2

Add a domain and publish

Pick colours, position and texts in up to seven languages, list your cookies, then publish revision 1.

3

Embed one script tag

Put zeno.js first in your <head> and change the type of tags that need consent. Done.

index.html
<!-- 1. First thing in <head>, synchronous -->
<script src="https://consent.example.com/zeno.js"></script>

<!-- 2. Blocked until "analytics" is granted -->
<script type="text/plain" data-zeno="analytics"
        src="https://stats.example.com/script.js"></script>

<!-- 3. Embeds load only with "marketing" consent -->
<iframe data-zeno="marketing"
        data-src="https://www.youtube-nocookie.com/embed/…"></iframe>

<!-- 4. Let visitors change their mind -->
<button onclick="Zeno.show()">Cookie settings</button>

Categories: necessary (always on), functional, analytics, marketing. Full contract in the integration docs.

Compliance

Built around how EU regulators read consent.

Valid consent under the GDPR and the ePrivacy Directive has to be free, specific, informed, unambiguous and as easy to withdraw as to give. ZenoCookieConsent makes those the defaults, not the settings you have to hunt for.

  • Reject is as easy as accept. Same button, same size, same colour, on the first layer.
  • Nothing runs before consent. Marked tags stay blocked until their category is granted.
  • Granular and never pre-ticked. Optional categories start switched off.
  • Provable. A pseudonymous receipt for every decision, tied to the exact banner revision.
  • Revocable. A persistent settings button and Zeno.show() to withdraw at any time.
  • Data stays home. No consent data is sent to a vendor, because there is no vendor in the loop.

Read the compliance overview

Compared with paid CMPs

Free and self-hosted, versus a per-domain subscription.

Hosted consent platforms are polished products, and some offer things we do not (yet). Here is an honest view of the trade-off.

“Typical paid CMP” describes common hosted, subscription-based consent platforms in general, not any specific vendor. Check each vendor's current terms.
 ZenoCookieConsentTypical paid CMP
Price modelFree and open sourceSubscription per domain, often tiered by traffic or features
Number of domainsUnlimited, in one installationBound to your plan
Where consent records liveYour PostgreSQL databaseThe vendor's cloud
Third-party processorNone. You operate it.Yes, with a DPA and transfer assessment
Banner script served fromYour own domainThe vendor's CDN
Equal-prominence rejectEnforced by designUsually possible, depends on configuration
Lock-inOpen source, your data, standard SQLProprietary platform
Automatic cookie scanningNot included. You maintain the cookie list.Commonly included
IAB TCF supportNot supportedOften available
OperationsYou run updates and backupsManaged for you

FAQ

Good questions.

Anything else? The documentation goes deeper.

Is it really free? What is the catch?

It is free and open source. There is no paid tier, no domain limit and no feature held back. The trade-off is that you host it: you need a server with Docker and someone who keeps it updated and backed up.

What do I need to install it?

A Linux server with Docker Engine 24+ and the Compose v2 plugin (1 vCPU, 1 GB RAM and 10 GB disk are enough to start) and a DNS name such as consent.example.com. Run git clone <repository> && cd zenocookieconsent && ./install.sh --domain consent.example.com, or curl -fsSL https://zenocookieconsent.citiumsoftware.com/install.sh | bash. The installer starts the app, PostgreSQL, MinIO and Caddy with automatic HTTPS. More on self-hosting.

Does using it make my site compliant?

It gives you the tools and compliant defaults: equal reject, prior blocking, granular choices, receipts and easy withdrawal. Compliance also depends on how you configure it, which tags you mark for blocking and what your privacy policy says. It is not legal advice.

Which tags can it block?

Any <script> (external or inline), <iframe> and <img> you mark with data-zeno, including elements added later by other scripts. With data-gcm, Google tags also receive Consent Mode v2 signals.

What does a consent receipt contain?

A random receipt id from the visitor's browser, the choice per category, the consent version and banner revision, language, the page URL without query string, the user agent and a keyed hash of the truncated IP address. No names, emails or account ids.

Can an agency manage client sites with it?

Yes. Organizations hold domains and members, and every member has a role per organization: Owner, Admin, Member or Viewer. A client's DPO can get read-only access to their consent log.

Stop renting your cookie banner.

Install ZenoCookieConsent on your own server today. It is free for every site you run, now and later.