Cookie scanner
Find every cookie automatically
Consent experience
A cookie policy generator turns a set of guided questions into a finished document. Kukie generates three: a cookie policy, a privacy policy and terms and conditions. The cookie tables are filled in from your most recent scan, so the policy lists the cookies your site actually sets. Each one publishes at its own URL.
What it produces is a starting point for review, not legal advice. Kukie says so on the face of every document, and this page says so before it says anything else.
Almost every cookie policy on the internet arrived the same way. Somebody found a template, or copied one from a company that looked similar, changed the name at the top and pasted it into a page. The result names cookies the site has never set, omits the three it does set, and gives durations nobody measured. It is a document about a hypothetical website.
That is a problem because a cookie policy is one of the few compliance claims a stranger can check. Anyone can open your site, look at what it stores, and compare that with what your policy says. When the two disagree, the disagreement is the finding.
This belongs near the top of the page rather than in a footnote, because getting it wrong is expensive and because a tool that oversells itself here is not a tool you should trust with the rest. A generator assembles a document from your answers. It does not know your business, it has not read your contracts, and it cannot tell you whether your site is compliant.
This is built into the product, not just written on this page. Every document Kukie generates carries a notice at the top stating that it was produced automatically, that it does not constitute legal advice, and that it should be reviewed by a qualified legal professional. Publishing one requires you to tick an acknowledgement saying you have read that, and the acknowledgement is time-stamped and kept with the document. Kukie provides the technical infrastructure for cookie consent management; whether your site is compliant depends on how you configure it and may require additional legal measures specific to your organisation.
Three generators, three separate wizards, one site. Most sites need the first two. The third matters once you sell something, host accounts or accept anything a visitor uploads.
| Document | What it covers | What gets filled in for you | When to regenerate |
|---|---|---|---|
| Cookie Policy | What your site stores on a visitor's device, why, for how long, and how somebody changes their mind later | The cookie tables, grouped by category, from your most recent scan: name, provider, purpose and duration. Also your web address, the services the scan identified and the longest cookie lifetime it found | After a scan turns up cookies you have not seen before, and whenever you add or remove a tool |
| Privacy Policy | What personal data you collect, why you hold it, who you share it with, how long you keep it and what rights visitors have | Your organisation name and web address, whether your site uses cookies at all, and the categories of third party your detected cookies point at, such as analytics or payments | When you change what you collect, bring in a new processor, or start serving a region you did not before |
| Terms and Conditions | The rules for using your site: accounts, acceptable use, user content, payments and refunds, liability and governing law | Your web address, with the rest driven by what you tell the wizard about accounts, paid features and how disputes should be settled | When your commercial terms move, for example a new refund period or a change of jurisdiction |
Each document is generated, saved and published on its own. Doing the cookie policy first is the usual order, because it is the one your banner links to.
A blank page is the reason most policies get copied. The wizards are built the other way round: every question that can be answered from something Kukie already knows arrives with that answer in the box, and you either accept it or change it.
The part of a cookie policy nobody can write from memory is the cookie table, so Kukie does not ask you to. Your most recent cookie scan already holds every cookie found on your site with its provider, its purpose and how long it lasts, sorted into the categories your banner uses. Those rows go straight into the document, grouped exactly as a reader would expect to find them. The services the scan recognised are pre-ticked in the third-party question, and the longest cookie lifetime it saw is offered as the default duration.
The wizards are conditional rather than fixed. Say that GDPR applies and the cookie policy grows the rights section that goes with it; say it does not and that section is never written. Answer no to international data transfers and you are not asked which safeguards you rely on, because the question no longer has a point. The privacy policy wizard is the deepest of the three: it covers GDPR, CCPA, UK GDPR, PIPEDA and POPIA, and has 15 conditional sections that appear or disappear as you answer.
Defaults are visible in the field, on the step where they matter, and every one of them can be overruled before you move on. Nothing is decided for you behind a screen you never see. You are also shown the finished document in full before it goes anywhere, which is the point at which most people spot the one answer they got wrong.
A cookie table row
The document does not arrive as a file you then have to find a home for. It is published by Kukie at its own address, and you point at that address from wherever the document needs to appear.
The wizard moves one section at a time and tells you which step you are on. Questions that no longer apply are skipped rather than shown greyed out, so the run is as short as your answers allow.
The last step is the finished document, rendered in full, cookie tables and all. Go back a step, change an answer, and it is rebuilt. This is the version to send to whoever reviews it for you.
A draft is private and keeps your answers, which is what you want while a review is outstanding. Publishing asks you to acknowledge that the document is not legal advice first, and only then makes it public.
Link the published address from your footer and from the policy link in your consent banner, or copy a one line snippet that embeds the document inside a page of your own. Republishing an updated version refreshes every place it is used.
What the published address looks like
app.kukie.io/legal/<your site key>/cookie-policy
The same pattern gives you privacy-policy and terms-conditions. Nothing has to be pasted into your content management system, which means nothing has to be pasted in again the next time the document changes. If you would rather serve it inside your own layout, the raw HTML can be copied out in one click and dropped into a page you control.
Any site with a cookie banner needs a document behind it. These are the situations where generating one beats every other option available to you.
Your first scan found more than you expected
This is the common one. A site picks up cookies from a chat widget, an embedded video and an old campaign pixel, and nobody has the full list. Generating the policy from the scan is the fastest way to turn that list into something a visitor can read.
Your visitors are in several jurisdictions
The rights an EU visitor has are not the rights a Californian visitor has, and a policy that describes only one of them is incomplete for the other. Tell the wizard which regimes you have decided apply, and the matching sections are written in. Which banner each region sees is a separate setting, covered on geo-targeting.
Legal budget is the constraint
Review is cheaper than drafting. Arriving with a complete document, an accurate cookie table and a list of the decisions you have already made changes what you are buying from a lawyer, and it is the difference between an afternoon and a project for most small organisations.
You maintain sites for other people
Every site gets its own documents, generated from its own scan, published at its own address. Nobody has to remember which client got which template, and handing a site over means handing over answers that are still stored, not a paragraph somebody wrote once.
The three generators are part of every plan, free included, and every site you add gets its own set. Compare plans if you need more sites or more scanned pages, or read the global compliance overview if you are still working out which regimes apply to you.
A generated policy is only as good as the data behind it, and only useful if something links to it.
Find every cookie automatically
The right banner in every region
Layouts, categories and consent modes
Background reading on what a cookie policy, a privacy policy and a set of terms are each expected to say.
Compliance
March 24, 2026 · 8 min read
A cookie policy tells visitors exactly which cookies your website sets, what data those cookies coll...
Read more →
Privacy
March 19, 2026 · 6 min read
A compliant cookie policy does more than just list trackers. It must explain who sets them, why they...
Read more →
Privacy
March 19, 2026 · 9 min read
A privacy policy is not a formality - it is a legal requirement under nearly every data protection l...
Read more →
Compliance
March 19, 2026 · 5 min read
A terms and conditions agreement acts as the legal backbone of your website. Learn which specific cl...
Read more →What site owners ask before they generate a document, and what they ask again when the site changes.
Free plan, no card required. Scan the site, answer the questions, publish the document.
Quick Profiles
Adjustments
Settings are saved in your browser only. Accessibility Statement