Methodology

How we grade the web, in full.

Every grade on our dashboard comes from measurements anyone could repeat. This page is what we measure, how it becomes a score, and what we can't see.5,800 sites · 25 industries · weekly · 17 consent signals · 4 tracking tiers · current as of August 2026

In brief
Once a week we visit the most-used U.S. consumer sites with a real browser, as a first-time visitor who touches nothing: no clicks, no cookie choices. We record every request the site makes. Each site gets two scores: how much of a real choice it builds for you, and how broadly it hands you to third-party trackers before you choose anything. The grade is the quadrant those two scores land in: A, B, C or D.
01
Measurement

A real browser, a first-time U.S. visitor, no interaction

The crawler drives a real Chrome browser from a U.S. vantage point across the index, weekly. It loads each homepage, waits while scripts fire, and scrolls once. What it records:

  • every network request the page makes
  • the consent banner and its buttons, if one appears
  • the consent interfaces the page exposes to the browser
  • the cookies that get set
  • the policy links in the footer

It never interacts with a consent banner. Everything we record is the site's default behavior: what happens to a visitor who hasn't said yes or no. Most U.S. sites track by default and wait to be told no, so the default state is what most visitors get.

Failed measurements are withheld, not graded. Two things exclude a site for the week: a near-empty capture, or a visit turned away by a bot wall. Either is a failed measurement, not a clean site: we publish no grade rather than one we can't stand behind. A site that loads and genuinely does little is kept and graded as the quiet site it is.

03
Tracking restraint

How much does the site hold back?

A score from 0 to 100 for how much a site holds back from handing your visit to third-party trackers. 100 means almost nothing reaches a tracker by default. Low scores mean many different trackers are contacted the moment the page loads.

Behind the score is a count of the distinct third-party trackers a site connects you to by default, weighted by how consequential each kind is and adjusted for site size. We count breadth, how many different trackers, rather than volume, how many requests: volume measures how chatty a site's engineering is; breadth measures how widely your visit is distributed.

SeverityWho's countedWeight
Tier 3Identity and audience brokers, retargeters, ad-conversion pixels, real-time bidding. Companies whose business is recognizing you across sites.4
Tier 2Social-platform widgets and web-to-app identity bridges. Your visit phones home to one platform.2
Tier 1Operational vendors: ad delivery, affiliates, email tooling, generic personalization, session replay.1
Tier 0Infrastructure, first-party services, consent tooling itself.0

Behavior outranks labels. If any tracker is observed performing cross-site identity syncing, through cookie-matching endpoints or ID-bridge calls, or hiding behind a disguised first-party subdomain, it counts as Tier 3 for that site, whatever its category says. Tier 3 is the ceiling.

Size-adjusted: the severity-weighted count is divided by the square root of the site's total requests, so a large, media-heavy site isn't punished for being big, only for being broad.

Expressed as restraint: the published score is that count inverted onto a 0 to 100 scale, so more sharing lowers the score and both axes read the same direction. A 100 means no cross-context tracking was observed on our visit: an observation, not a certificate.

04
The grade

Four quadrants, four grades

Each axis is published 0 to 100 with the grade divider at exactly 50, so above 50 on both is an A. The median site we measured maps to 50, and that anchor is held fixed when we revise the model, so grades stay stable week to week. Which side of each divider a site lands on places it in one of four quadrants, laid out here as they sit on the dashboard:

more tracking restraint →
C · Minimal

Little consent effort, but little tracking either.

A · Restrained

Real consent effort and a light default tracking footprint.

D · Unrestrained

Little consent effort and broad default tracking.

B · Tracks anyway

Real consent effort, yet heavy tracking still fires by default.

more consent effort →

Every weight and threshold on this page is published. Before a revision ships, we test it against a full crawl and record it in the revision log.

Limits

What we can't see

One vantage point

We crawl from the U.S. A site that behaves differently for European visitors, or gates tracking only for certain states, shows us its U.S. default and nothing else.

Restraint can be invisible

A site that blocks its tags entirely until consent shows us nothing, which looks identical to having no Google tags at all. Our "defaults to denied" signal only rewards restraint we can observe; absence is never counted against a site.

Many sites tie

A site with only a privacy policy scores exactly what every other privacy-policy-only site scores. Those are real ties, and we plot them as ties. We don't scatter them artificially to look more precise than we are.

One visit, one window

Ad markets are dynamic: the exact tracker set varies visit to visit, and movement inside a band is normal. Every site gets the same fixed observation window, so fast and slow pages have equal opportunity to show their trackers. A tracker that loads after the window closes is missed: timing can under-count, never invent.

Not everything is classifiable

A small share of tracking calls comes from companies we haven't yet identified. Unknown trackers count toward breadth only when they're observed doing identity syncing.

Some sharing is off-page

We measure what your browser does. When a site's servers pass your visit along out of the browser's view, those trackers don't appear in our count. Our numbers are a floor, not a ceiling.

Revision log

How the model changes over time

Two kinds of change land here. Universe: which sites we measure. Measurement: a new signal, or a sharper detector. Either can move grades, so every change ships as one dated row: what changed, and its measured effect on that week's grades.

EffectiveTypeChangeMeasured effect
Week of
Aug 18, 2026
Universe Measured at the listed addressAbout 1,200 of ~5,800 sites were crawled at a secondary page rather than the address the index lists. The crawl list is now built directly from the index. 31% of 1,070 comparable sites changed grade
C −4.6 pts index-wide
· new baseline week
Week of
Aug 18, 2026
Universe Unreachable sites are withheld, not gradedA visit that returns nothing now publishes no grade rather than reading as a quiet C. The standing rule lives in Measurement. 111 sites withheld
44 restated, week of Aug 7
Week of
Aug 7, 2026
Measurement Consent readings record completionUnfinished readings of a site's consent controls understated consent effort. The correction moves sites up that axis, never down; tracking restraint is untouched. 18% of 5,278 sites changed grade
D→B and C→A, up-axis only
· new baseline, consent axis
July 2026 Universe A new universe: the Consumer Web IndexThe weekly set is now every consumer destination among the most-visited U.S. sites, selected by a published rule rather than by hand. Grades are computed exactly as before. ~1,000 → ~5,800 sites, 16 → 25 industries
63% of prior list carried forward
repeat-crawl agreement 94.9%
· new baseline week

One row per change. Caveats a change doesn't resolve live in Limits; standing rules it introduces live in Measurement. A · new baseline week row means that week's counts restate: the step from earlier weeks is the revision, not the web moving.

Index provenance. The frame is the Google Chrome UX Report (chrome-ux-report), CC BY 4.0, snapshot 202605. The index we derive from it publishes under CC BY-SA 4.0. How the index is built, its selection rule, the query and snapshot checksum behind it, and the quarterly changelog publish as a public resource with the Q4 update.

Observable indicators, not legal conclusions. Grades describe measurable industry practice, what a site's machinery does for a first-time visitor. They never describe legal compliance, intent, or wrongdoing. A grade can change as a site's setup changes, and as this methodology improves.