Your cookie scanner knows what actually runs on your site. Your privacy policy says what you tell visitors runs on it. The Policy alignment check compares the two and shows you where they disagree, so your policy does not silently fall behind your marketing stack.
You will find it at the top of each site's Legal Documents page. It needs two things to run: at least one completed cookie scan, and a published privacy policy (a draft is not compared - the check looks at what your visitors are actually shown).
What it compares
From your latest completed scan, the check collects the third-party providers behind what was found: cookies matched against Kukie's known-cookie database (for example _fbp resolves to Meta Pixel), and the third-party hosts that scripts and cookies came from (for example static.hotjar.com resolves to Hotjar). Your own domain is never counted - only third parties.
From your privacy policy, it reads both the answers you gave in the wizard (the "Which third-party services does your site use?" question in particular) and the full text of the published document. Matching understands common aliases: a policy that says "Facebook" covers a detected Meta Pixel, and naming a provider anywhere in the document text counts even if you never ticked it in the wizard.
Reading the results
- Providers detected but not found in your policy - each one is listed with its evidence: the cookie names or script hosts the scan saw, and the cookie category where known. This is the list worth acting on.
- Mentioned but not detected (may be unused) - the reverse view: providers your policy names that the last scan did not see. This is informational only. A scan covers only the pages it visited, so a provider used on an unscanned page can appear here without anything being wrong.
- "Your privacy policy covers every provider we detected." - the two sources agree.
The check reports observations, not verdicts. "Detected on your site but not found in your privacy policy" is a fact you can verify; whether and how your policy must name a given provider is a question for you and, where it matters, your legal adviser. Kukie.io does not provide legal advice.
Clearing a finding
- Open the Privacy Policy wizard from the same page.
- In the Third-party services section, tick the detected service - or add it as a custom entry if it is not in the list.
- Publish the updated policy. The check re-runs against the new version automatically.
If the scan detected something you have since removed from your site, run a fresh scan instead - the check always uses your latest completed scan.
When it refreshes
Results are recomputed whenever a new scan completes or your privacy policy changes, and are cached for up to an hour in between. There is nothing to trigger manually.
One important boundary: the check only ever reads. It never edits, regenerates or republishes your legal documents - every change to your policy goes through the wizard and your own explicit Publish.
