Install StrongPrivacy on any website.

Use the property-specific v1 runtime, make optional scripts inert, and provide a permanent way to reopen consent preferences.

Installing a managed property?

Verify domain authorization and complete reviewed activation before a new managed property can serve its configuration. Follow the managed-service handoff, then return here for your platform’s installation steps. Installation status alone is not a live verification result.

Add the runtime

Create the property first so its configured origin, public site key, and published consent configuration are available to the runtime.

  1. 1

    Select the property

    Open Integrations → Custom sites and select the destination property. Every property has a different site identifier.
  2. 2

    Copy the generated snippet

    Use the Copy snippet action after confirming the selected property name and hostname.
  3. 3

    Place it before optional vendors

    Add the runtime to the document head before analytics, advertising, personalization, or other optional scripts.

Example only

<script
  src="http://localhost:3210/embed/v1.js"
  data-site-id="site_abc123"
  data-api-base="http://localhost:3210"
  data-privacy-url="/privacy"
  data-platform="custom"
  defer
></script>

Use the dashboard-generated values

The hostname, application URL, and property ID above are placeholders. Do not copy the example into production. The Integrations screen now updates the snippet when you select a different property.

Gate optional scripts

A normal script or iframe can contact a vendor before the consent runtime makes a decision. Convert optional resources into inert declarations.

Declarative script gating

<script
  type="text/plain"
  data-strongprivacy-id="site-analytics"
  data-strongprivacy-category="analytics"
  data-strongprivacy-src="https://analytics.example.com/analytics.js"
></script>
CategoryUse for
necessaryCore security and requested service functions. Never optional.
functionalPreferences, chat, and enhanced site features.
analyticsAnalytics, performance measurement, and attribution.
marketingAdvertising, retargeting, and cross-site profiling.
mediaEmbedded video, maps, and third-party media players.

For dynamic single-page applications, use StrongPrivacy.registerScript().

Consent-gated iframe

<iframe
  title="Product video"
  data-strongprivacy-category="media"
  data-strongprivacy-src="https://www.youtube-nocookie.com/embed/VIDEO_ID"
  width="560"
  height="315"
></iframe>

Do not use src on optional iframes

Put the URL in data-strongprivacy-src. A normal src can start a network request before the runtime has a chance to block it.

Add a permanent privacy control

Visitors must be able to revise or withdraw a choice as easily as they made it.

Add a visible Privacy choices control in the site footer or privacy page. The runtime connects this attribute automatically, including buttons added during client-side navigation. A built-in persistent control is also available after a choice.

<button type="button" data-strongprivacy-preferences>Privacy choices</button>

In the configuration editor, add optional custom categories, complete reviewed language variants, and choose spacing and preferences text. Use the displayed custom_ key when assigning a script or media element. Set data-language on the runtime to use an explicit language; otherwise supported browser languages are matched.

Full installation acceptance checklist →

Production checklist

Test a production-like page with storage cleared and the browser network panel open.

  • The exact page origin is registered on the selected property.
  • The runtime loads once and reports no origin or configuration error.
  • Optional requests remain absent before an allowed choice.
  • Reject optional does not load functional, analytics, marketing, or media resources.
  • Reloading preserves the decision, and Privacy choices reopens the dialog.
  • Your Content Security Policy permits the app origin and approved vendors.