← Back to blog

Ad+Privacy Metrics: See What Fires Before Anyone Clicks Accept

Declarations tell you who a publisher authorizes. They don’t tell you what the live homepage does to a reader: how hard it’s monetized, which trackers fire, or whether identifiers leave the page before anyone clicks Accept.

High-density ad wrappers live in that gap. So does “premium” inventory that still ships session replay, and the CMP banner that’s pure theatre. Ad+Privacy Metrics is how we close it. One lab visit (real Chrome, consent handling, scroll and dwell) produces two independent scores, ad density and privacy, plus a pre-consent vs post-consent split, so you can see what already happened while the visitor had agreed to nothing.

Two questions, two scores, one crawl

Ad density asks how hard the live page is monetized: coverage, sticky and interstitial units, chumboxes, refresh, thin copy. Grades are low / medium / high / very_high (0–100). High and very high include MFA-adjacent traits; a homepage measurement is suspicion-only and cannot reach those two grades. Privacy / tracking asks what happens to the reader: minimal through aggressive. A site can look editorial and still land heavy on tracking. Desktop and Mobile are separate crawls (US/EU or any other country), and Auto-Investigate takes the worse of the two devices when both exist.

Scan the corpus

Filter labbed hosts by ad-density grade, privacy grade, consent boundary, pre-consent trackers, session replay, identity graph, or social pixel. High / very-high density surfaces quickly that way, and so do the “respectable” domains that fire session replay before consent. Then open the row.

Ad+Privacy Metrics corpus table with filters, ad density and privacy columns
Ad+Privacy Metrics corpus table — filters, ad density + privacy columns, latest crawl per host

The host profile is the case file

Dual ad-density + privacy gauges, Ad metrics, Privacy flags, screenshots, and the HAR data evidence when it was captured. You get the whole crawl you would otherwise have to run yourself.

Ad+Privacy Metrics hostname profile with Desktop and Mobile tabs, scoring gauges, Ad metrics, Privacy flags, and Consent window
Hostname profile — Desktop/Mobile tabs, scoring gauges, Ad metrics, Privacy flags, crawl screenshots

Ad metrics. Above-the-fold and full-page ad coverage, ads in view, sticky units, interstitials, chumbox vendors, slot refresh rate, ad-related bytes, third-party domains, article vs body word count, redirect hops (including off-domain). Screenshots at pre-consent and final.

Privacy flags. Use the score to sort; the flags are what you actually work from. They’re compliance-grade facts pulled from the same crawl: pre-consent leakage, high-risk vendors, identifier sharing, surveillance breadth, transparency. Each flag carries points and a note you can drop straight into a case file.

Data evidence. When the crawl captured the network, the host profile shows Data evidence (full network capture) HAR available for this crawl. That’s the raw HAR for the same visit that produced the scores, not a summary of it.

Trackers by purpose. Advertising, analytics, session replay, social pixels, identity graphs, fingerprinting, tag managers, content recommendation, customer-data platforms, plus CMPs and ad verification (observed, but not scored as “tracking”).

Cookies and storage. We try to provide nuance and insights into the cookies being collected and used on publisher websites. We’re identifying: first- vs third-party, session vs persistent, SameSite=None, Secure, HttpOnly, cookie lifetime, cookie domains, localStorage / sessionStorage size, IndexedDB names, and user ID cookies (_ga, _fbp, UUIDs).

We extract 21 kinds of vendor account identifiers from the same visit. Click an ID to see every other labbed host that carries it. When the same pixel turns up on a “news” site and a high-density wrapper, that’s a diligence finding rather than a coincidence. Kinds are namespaced, so a numeric id on two vendors is never treated as the same account.

Before anyone clicks Accept

Most “privacy scores” are a single number taken at the end of the visit, which hides the question that matters most for GDPR diligence: what already fired while the banner was still up?

We dwell and scroll in front of the CMP, then click Accept. Cookies, fingerprinting, and network requests are snapshotted at that click and again at the end of the dwell, so all three families agree on where the boundary sits. Anything in the first window happened with no consent. Legal evidence exports use the same split: pre vs post, Desktop/Mobile, US/EU or any other country.

Each of these is counted pre-consent and for the full crawl:

Empty pre-consent columns don’t mean clean. They mean we didn’t observe a CMP accept click, usually because there was no banner, or because it was a US exit where GDPR isn’t asserted. A banner that vanished without a click may already be post-implied-consent, since some CMPs treat scroll as acceptance. We only score pre-consent leakage when the accept click was actually observed.

Pre vs post tracking — each signal counted before the CMP accept click and for the full crawl
Pre vs post tracking — each signal counted before the CMP accept click and for the full crawl

Consent window. This goes well past a yes/no banner: whether we observed a CMP accept click, how long the pre-consent window lasted, whether we scrolled in it, whether the banner vanished unclicked, plus TCF (present vs readable, GDPR applies, purposes, GVL vendor ids), GPP, US Privacy, DNT, and Global Privacy Control. A broken CMP still isn’t a clean one.

Built for investigation

The same crawls feed Auto-Investigate, the API, and MCP. Per-hostname Ad density and Privacy lookups are available on researcher and paid plans. Open Research → Ad+Privacy Metrics, or check plans if you need evidentiary exports (Desktop/Mobile, US/EU or any other country) on Legal.