Consentry
Nothing loads until the visitor says yes.
A consent platform written for KVKK, Turkey's data protection law, rather than translated from GDPR. A site adds one script tag. No tracker runs until the visitor decides, and every decision is kept as evidence, tied to the exact banner wording they saw.
- What it is
- Cookie consent for Turkish websites
- Status
- In production, first pilot done
- Started
- July 2026
The problem
Turkish websites need explicit consent before they load analytics or ad cookies, and they need to be able to prove it. In practice, many banners ask for consent while Google Analytics is already running, and many make Accept bright and Reject faint.
The established tools are built around GDPR, priced per site, and treat KVKK as a translation.
How it works
Trackers move out of the site's HTML and into Consentry. The script injects them only after the visitor agrees, so the consent log is a record of decisions that were actually honoured, not a list kept next to scripts that fired anyway.
Each decision is stored on the server, linked to the exact version of the banner the visitor saw. If the API is slow or down, a built-in fallback banner still appears and nothing loads. A failure never quietly becomes a yes.
Site owners manage everything from a Turkish-first dashboard with a live preview, a version history and a full consent log.
Try it: press any button on the banner.
Çerez tercihleriniz
Siteyi geliştirmek için analitik çerezleri kullanmak istiyoruz. Onay vermediğiniz sürece hiçbiri yüklenmez.
Waiting for a decision. Nothing has loaded yet.
Under the hood
A fingerprint for what was asked. Every config edit is saved as a new version that can't be changed later. A SHA-256 hash covers only the fields that change what the visitor is agreeing to, so wording changes re-prompt everyone and cosmetic ones re-prompt nobody.
Isolation, checked twice. Every admin query names its owner, and composite foreign keys make it impossible for a consent to point at another customer's site or config. A Testcontainers suite runs every admin read and write against two customers on real Postgres 17.
Consent rules tested in a browser. Playwright measures the three buttons, counts requests to the tracker before consent (zero), checks cookie flags, and confirms a fresh banner can't be dismissed with Escape. Each assertion was first shown to fail against a deliberately broken script.
Proof survives failure. The consent log is append-only, timestamps come from the database clock, and a consent sent during a redeploy is still written. The rule in the codebase: losing proof is worse than losing a link.
The admin API stays off the internet. The public host answers three paths: the script, the config and the consent endpoint. The admin API, the sign-in service and Keycloak are reachable only inside the private network; the dashboard sits behind an access gate and holds tokens server-side.
Where it stands
Deployed to production on Hetzner in the EU. On 30 September 2026 it went live on its first real site and passed the full end-to-end check: no analytics cookie before a choice, none after Reject, and the analytics cookie only after Accept.
That site has since dropped Google Analytics altogether, so today Consentry has no live site. Next: a backup and restore drill, external uptime checks, and self-serve sign-up. Until then, new sites are set up by hand.
Pace. Commits per week since December 2025. The quiet weeks are real too.
Consentry97 commits
Built with: Vanilla JavaScript, Java 21, Spring Boot, Spring Cloud Gateway, Keycloak, PostgreSQL 17, Next.js 16, Dokploy, Hetzner, Cloudflare