How we grade the web, in full.
Every grade on our dashboard comes from measurements anyone could repeat. This page is what we measure, how it becomes a score, and what we can't see.5,800 sites · 25 industries · weekly · 17 consent signals · 4 tracking tiers · current as of August 2026
A real browser, a first-time U.S. visitor, no interaction
The crawler drives a real Chrome browser from a U.S. vantage point across the index, weekly. It loads each homepage, waits while scripts fire, and scrolls once. What it records:
- every network request the page makes
- the consent banner and its buttons, if one appears
- the consent interfaces the page exposes to the browser
- the cookies that get set
- the policy links in the footer
It never interacts with a consent banner. Everything we record is the site's default behavior: what happens to a visitor who hasn't said yes or no. Most U.S. sites track by default and wait to be told no, so the default state is what most visitors get.
Failed measurements are withheld, not graded. Two things exclude a site for the week: a near-empty capture, or a visit turned away by a bot wall. Either is a failed measurement, not a clean site: we publish no grade rather than one we can't stand behind. A site that loads and genuinely does little is kept and graded as the quiet site it is.
Did the site build you a real choice?
A score from 0 to 100 for the consent machinery a site has built or bought. We measure by function, not brand: a site that builds its own consent system scores the same as one that buys a well-known consent platform, because we detect what the machinery does.
| Group | Signal | What we look for | Points |
|---|---|---|---|
| Interface | Reject control | The banner lets you say no, not just OK | 10 |
| Consent banner | A visible notice appears | 8 | |
| Manage control | You can choose category by category | 7 | |
| Standards (capped at 20) | TCF interface | The EU-standard consent interface is live in the page | 10 |
| US Privacy interface | The original California opt-out interface, now legacy | 8 | |
| GPP interface | The current multi-state U.S. opt-out interface | 8 | |
| Google Consent Mode | Consent is wired into the site's Google tags | 6 | |
| Consent string on the wire | The consent signal is attached to the site's outgoing requests | 3 | |
| Opt-out, operating | "Your Privacy Choices" link | The standing opt-out link is present in the footer | 12 |
| Consent cookie set | A consent mechanism is running, not just installed | 8 | |
| Cookie-preferences link | A standing "Cookie Settings" link, so you can change your mind later | 6 | |
| Recognized consent platform | The site runs consent tooling we can identify | 5 | |
| Disclosure | Privacy policy | Baseline transparency | 6 |
| Health-data policy | Washington My Health My Data disclosure | 5 | |
| Cookie policy | Cookie-specific disclosure | 4 | |
| Voluntary restraint | Ad tags default to denied | The site tells Google to treat you as opted out before you've done anything | 8 |
| Analytics default to denied | The same opt-out-by-default discipline, applied to analytics storage | 4 |
Why the standards group is capped: the consent standards partly supersede one another, and the industry retired the US Privacy interface in favor of GPP in 2024, so stacking every standard at once isn't extra effort. The group contributes at most 20 points, and the score is rescaled so 100 means everything a well-advised U.S. site would reasonably build, and stays reachable.
What this axis does not claim: it measures what's built, not whether it's honored. Testing whether a site respects your no means comparing crawls with and without an opt-out asserted. That measurement is in development and will be reported separately when it ships.
How much does the site hold back?
A score from 0 to 100 for how much a site holds back from handing your visit to third-party trackers. 100 means almost nothing reaches a tracker by default. Low scores mean many different trackers are contacted the moment the page loads.
Behind the score is a count of the distinct third-party trackers a site connects you to by default, weighted by how consequential each kind is and adjusted for site size. We count breadth, how many different trackers, rather than volume, how many requests: volume measures how chatty a site's engineering is; breadth measures how widely your visit is distributed.
| Severity | Who's counted | Weight |
|---|---|---|
| Tier 3 | Identity and audience brokers, retargeters, ad-conversion pixels, real-time bidding. Companies whose business is recognizing you across sites. | 4 |
| Tier 2 | Social-platform widgets and web-to-app identity bridges. Your visit phones home to one platform. | 2 |
| Tier 1 | Operational vendors: ad delivery, affiliates, email tooling, generic personalization, session replay. | 1 |
| Tier 0 | Infrastructure, first-party services, consent tooling itself. | 0 |
Behavior outranks labels. If any tracker is observed performing cross-site identity syncing, through cookie-matching endpoints or ID-bridge calls, or hiding behind a disguised first-party subdomain, it counts as Tier 3 for that site, whatever its category says. Tier 3 is the ceiling.
Size-adjusted: the severity-weighted count is divided by the square root of the site's total requests, so a large, media-heavy site isn't punished for being big, only for being broad.
Expressed as restraint: the published score is that count inverted onto a 0 to 100 scale, so more sharing lowers the score and both axes read the same direction. A 100 means no cross-context tracking was observed on our visit: an observation, not a certificate.
Four quadrants, four grades
Each axis is published 0 to 100 with the grade divider at exactly 50, so above 50 on both is an A. The median site we measured maps to 50, and that anchor is held fixed when we revise the model, so grades stay stable week to week. Which side of each divider a site lands on places it in one of four quadrants, laid out here as they sit on the dashboard:
Little consent effort, but little tracking either.
Real consent effort and a light default tracking footprint.
Little consent effort and broad default tracking.
Real consent effort, yet heavy tracking still fires by default.
Every weight and threshold on this page is published. Before a revision ships, we test it against a full crawl and record it in the revision log.
What we can't see
One vantage point
We crawl from the U.S. A site that behaves differently for European visitors, or gates tracking only for certain states, shows us its U.S. default and nothing else.
Restraint can be invisible
A site that blocks its tags entirely until consent shows us nothing, which looks identical to having no Google tags at all. Our "defaults to denied" signal only rewards restraint we can observe; absence is never counted against a site.
Many sites tie
A site with only a privacy policy scores exactly what every other privacy-policy-only site scores. Those are real ties, and we plot them as ties. We don't scatter them artificially to look more precise than we are.
One visit, one window
Ad markets are dynamic: the exact tracker set varies visit to visit, and movement inside a band is normal. Every site gets the same fixed observation window, so fast and slow pages have equal opportunity to show their trackers. A tracker that loads after the window closes is missed: timing can under-count, never invent.
Not everything is classifiable
A small share of tracking calls comes from companies we haven't yet identified. Unknown trackers count toward breadth only when they're observed doing identity syncing.
Some sharing is off-page
We measure what your browser does. When a site's servers pass your visit along out of the browser's view, those trackers don't appear in our count. Our numbers are a floor, not a ceiling.
How the model changes over time
Two kinds of change land here. Universe: which sites we measure. Measurement: a new signal, or a sharper detector. Either can move grades, so every change ships as one dated row: what changed, and its measured effect on that week's grades.
| Effective | Type | Change | Measured effect |
|---|---|---|---|
| Week of Aug 18, 2026 |
Universe | Measured at the listed addressAbout 1,200 of ~5,800 sites were crawled at a secondary page rather than the address the index lists. The crawl list is now built directly from the index. | 31% of 1,070 comparable sites changed grade C −4.6 pts index-wide · new baseline week |
| Week of Aug 18, 2026 |
Universe | Unreachable sites are withheld, not gradedA visit that returns nothing now publishes no grade rather than reading as a quiet C. The standing rule lives in Measurement. | 111 sites withheld 44 restated, week of Aug 7 |
| Week of Aug 7, 2026 |
Measurement | Consent readings record completionUnfinished readings of a site's consent controls understated consent effort. The correction moves sites up that axis, never down; tracking restraint is untouched. | 18% of 5,278 sites changed grade D→B and C→A, up-axis only · new baseline, consent axis |
| July 2026 | Universe | A new universe: the Consumer Web IndexThe weekly set is now every consumer destination among the most-visited U.S. sites, selected by a published rule rather than by hand. Grades are computed exactly as before. | ~1,000 → ~5,800 sites, 16 → 25 industries 63% of prior list carried forward repeat-crawl agreement 94.9% · new baseline week |
One row per change. Caveats a change doesn't resolve live in Limits; standing rules it introduces live in Measurement. A · new baseline week row means that week's counts restate: the step from earlier weeks is the revision, not the web moving.
Index provenance. The frame is the Google Chrome UX Report (chrome-ux-report), CC BY 4.0, snapshot 202605. The index we derive from it publishes under CC BY-SA 4.0. How the index is built, its selection rule, the query and snapshot checksum behind it, and the quarterly changelog publish as a public resource with the Q4 update.