Skip to content
Features Pricing Free Cookie Scanner Consent Mode Checker Script Audit TCF String Decoder Cookie Database GDPR Scanner Compliance Blog
Start Free → Login
For vibe-coded apps

Cookie Consent for
AI App Builders

Shipped an app with Lovable, Bolt, v0 or Replit? It is probably collecting cookies without consent. Add GDPR and CCPA compliance in about 5 minutes - one script tag, no coding.

Works with every AI app builder

Lovable React apps from a prompt
Bolt.new Full-stack in the browser
v0 Vercel UI generation
Replit Agent-built apps
Cursor AI-first code editor
Windsurf Agentic IDE
Base44 No-code AI apps
Firebase Studio Google AI workspace

AI builders ship analytics. They don't ship consent.

A banner that appears is not the same as a consent system. Generated apps wire in tracking by default and leave the legal part to you.

Trackers load before consent

Google Analytics, Vercel Analytics and pixels fire on first paint - exactly what the GDPR and ePrivacy Directive prohibit without prior consent.

You are the data controller

Generating the app with AI does not transfer liability. As the site operator, the consent obligation - and the fines - are yours.

No banner, no opt-out

EU visitors need explicit opt-in; California needs a "Do Not Sell" opt-out. A scaffolded app has neither out of the box.

How it works

Compliant in about 5 minutes

One script tag is all your generated app needs.

1

Add one script tag

Drop the Kukie snippet into your index.html so it loads before your app bundle. Works with whatever your builder generates - React, Vite or Next.js.

2

We scan and block

Kukie scans your deployed app, auto-categorises every cookie, and blocks trackers until your visitor consents.

3

Consent, logged

The banner shows the right consent model per region, signals Google Consent Mode v2, and logs every consent for your audit trail.

Know What You Shipped

What AI-Built Apps Wire In by Default

The exact output changes with every builder release, but generated apps consistently ship the same categories of third-party services - most of them consent-relevant.

Category Typical services in generated apps Consent impact
Platform analytics Vercel Analytics, Netlify Analytics, Cloudflare Web Analytics Varies - cookieless modes exist, but script injection still needs review
Product analytics Google Analytics 4, PostHog, Plausible snippets scaffolded on request GA4 and PostHog set identifiers - consent required in the EU/UK
Error monitoring Sentry and similar SDKs added when you ask for "monitoring" Session data collection - disclose it and gate non-essential parts
Backend & auth SDKs Firebase, Supabase - auth tokens plus optional bundled analytics Auth cookies are necessary; bundled analytics are not
Fonts & embeds Google Fonts, YouTube embeds, map widgets Third-party requests that can transfer visitor IPs - EU courts have flagged remote fonts

We audit what each builder actually generates and keep the results current - see the 2026 AI builder cookie audit and the GDPR banner comparison across builders. Not sure what your own app loads? Run the free script audit.

Per-builder consent guides

Step-by-step walkthroughs for the most popular AI app builders.

Frequently asked questions

Do apps built with Lovable, Bolt or v0 need a cookie banner?
Yes, in most cases. AI app builders scaffold analytics and marketing tags (Google Analytics, Vercel Analytics, Meta Pixel and similar) by default. The moment your app sets a non-essential cookie and serves a visitor in the EU, UK or California, the GDPR, UK GDPR and ePrivacy Directive require prior consent, and the CCPA/CPRA requires an opt-out. The app being generated by AI does not change your legal obligations as the site operator.
How do I add cookie consent to a Lovable / Bolt / Replit app?
Add a single Kukie script tag to your app, ideally in index.html so it loads before your bundle. Kukie shows the consent banner, blocks third-party trackers until the visitor consents, and signals Google Consent Mode v2 automatically. No build configuration or framework plugin is required.
Does it work with the React, Vite or Next.js code these builders generate?
Yes. Kukie is a framework-agnostic JavaScript snippet, so it works with whatever Lovable, Bolt, v0, Replit, Cursor, Windsurf, Base44 or Firebase Studio produce - React, Vue, plain HTML, Vite or Next.js. You add one script tag; there is nothing to import into your component tree.
Will it block the analytics my AI builder added automatically?
Yes. Kukie auto-blocks 30+ known trackers (Google Analytics, Meta Pixel, Hotjar, TikTok and more) until the visitor gives consent, so the analytics your builder wired in respect consent state without any manual tag setup.
Is there a free plan for a side project or MVP?
Yes. The free plan needs no credit card and covers multiple sites with automatic cookie scanning and Google Consent Mode v2 - ideal for an MVP or a vibe-coded side project. See the pricing page for higher limits and advanced features.
Does Kukie support Google Consent Mode v2?
Yes. Google Consent Mode v2 is built in with all consent types, which is required for Google Ads conversion tracking in the EU. Kukie signals the correct consent state automatically once the visitor responds to the banner.

Make your AI-built app compliant

Free plan, no credit card. Add the script, scan your app, and ship consent that holds up.

Listed On