Privacy-first CAPTCHA
Privacy Center
CaptchaFox verifies that your visitors are human without tracking them. Review our approach, data handling, and safeguards in one place.
- No cookies or tracking
- No local device storage
- Data stays in the EU

Compliance with privacy regulations
How CaptchaFox maps to the data protection laws that matter for your business.
GDPR
Cookie-free verification, EU-only processing and a DPA on every plan – how CaptchaFox meets the EU General Data Protection Regulation.
View pageCCPA / CPRA
No sale of personal information and a clear service-provider role – how CaptchaFox fits the California Consumer Privacy Act.
View pageUK GDPR
Adequacy-covered EU hosting and PECR-friendly, cookie-free verification for businesses in the United Kingdom.
View pageSwiss nFADP
Data minimization and processor guarantees aligned with Switzerland's revised Federal Act on Data Protection.
View pageLGPD
Legitimate-interest friendly bot protection with contractual transfer safeguards for Brazil's Lei Geral de Proteção de Dados.
View pageDPDPA
Processing under contract, security safeguards and unrestricted EU transfers under India's Digital Personal Data Protection Act.
View pagePDPA
Data-intermediary role and the legitimate-interests exception for security under Singapore's Personal Data Protection Act.
View pagePIPL
Entrusted-party processing and strict data minimization to keep assessments under China's PIPL as small as possible.
View pageAPPI
Entrustment without extra consent and EU hosting covered by the mutual EU–Japan adequacy arrangement.
View pagePrivacy Act (AU)
APP-aligned minimal collection and accountable cross-border disclosure for the Australian Privacy Act.
View pageCAPTCHA privacy compliance
Why a privacy-first CAPTCHA pays off
CaptchaFox blocks automated attacks without collecting more than the moment needs. Beyond staying compliant, privacy-first bot protection means:
- No consent banner required
- No cookies or trackers used
- Data used for bot detection only
- More trust from privacy-conscious users
Frequently asked questions
Everything you need to know. Can't find your answer? Contact our support team.
Is CaptchaFox a data controller or a data processor?
CaptchaFox (Scoria Labs GmbH) acts as a processor pursuant to Art. 28 GDPR. The operator of the website that embeds the widget remains the controller and stays in control of purposes and legal basis. We process data exclusively on the operator's behalf, under a Data Processing Agreement.
Do I need a cookie banner or consent for CaptchaFox?
The CaptchaFox widget does not set cookies and does not store data permanently in the browser, so it does not trigger the consent requirements that cookie-based CAPTCHAs do. Verification typically relies on the operator's legitimate interest in protecting its site (Art. 6(1)(f) GDPR).
Where is the data processed?
Exclusively in EU data centers. There are no transfers to third countries, so the transfer rules of Art. 44–49 GDPR and the questions raised by Schrems II do not come into play.
What personal data does the widget process?
Only what is needed to tell humans and bots apart: the IP address, plus other technical and usage signals such as browser and device characteristics. Identifying data such as the IP address is anonymized as early as possible and is never used for advertising or profiling.
How do I get a Data Processing Agreement (DPA)?
A DPA is available on every plan. Reach out at hello@captchafox.com and we will provide the agreement, including the current subprocessor list and technical and organizational measures.
Fight bots and protect your users' data.
Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.