Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Content protection and anti scraping tool that poisons copied text in the browser. It sets no cookies and tracks nothing; the only privacy point is the IP exposure if the script is loaded from the vendor domain rather than self hosted.
CopyPoison is a content protection and anti scraping tool aimed at discouraging the wholesale copying of website text. According to the available information, it works in the browser: when a visitor copies a longer passage, the script substitutes many letters with visually identical lookalike characters from other alphabets, so the pasted text looks the same to a human but is hard to reuse or index by machines.
The tool is described as activating only on a copy event and poisoning only passages above a length threshold, leaving short snippets and code untouched. It runs as client side JavaScript and is offered for direct embedding or as a content management plugin. As a protective feature it processes the page text, not the visitor.
From the available information, CopyPoison sets no cookies and stores no identifiers; the poisoning logic does not need to recognise individual visitors. As a cookieless functional feature it does not by itself create a consent banner obligation under the ePrivacy Directive. As always, confirm the exact behaviour of the version you deploy.
If the CopyPoison script is loaded from the vendor domain rather than self hosted, that request exposes the visitor IP and user agent to the vendor, in the same way any third party asset does. The vendor server location is not always published. Self hosting the script keeps the request first party and removes this exposure.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Protecting your own content is a clear legitimate interest, and because the feature is cookieless and processes no visitor identifiers, the risk is low. If you load the script from the vendor, document that legitimate interest to cover the IP disclosure, or simply self host to keep things straightforward.
Self host the CopyPoison script from your own domain so no visitor IP reaches a third party, and verify in your own testing that the deployed version sets no cookies. Be aware that aggressive text poisoning can affect accessibility tools and legitimate copying, so balance protection against usability.
Websites using CopyPoison must obtain user consent under GDPR regulations.
DPIA considerations
Based on the available information, CopyPoison runs entirely in the browser, sets no cookies and processes no identifiers, so a DPIA is not normally triggered. The only data point worth noting is that, if the script is loaded from the vendor domain rather than self hosted, the request discloses the visitor IP and user agent to the vendor. Because vendor hosting details for this kind of small tool are not always published, the prudent approach is to self host the script and document that no personal data is processed by the feature itself.
Sample consent text
This site uses a content protection feature that modifies text you copy from longer passages. It runs in your browser, sets no cookies and does not identify or track you. Where the underlying script is loaded from the provider, that provider may see your IP address as part of the standard request.
Third-party domains contacted
copypoison.comCopyPoison is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Based on the available information, no. CopyPoison runs in the browser to modify copied text and does not need cookies or stored identifiers to do so. Always confirm the behaviour of the exact version you deploy.
No prior consent is needed for the protection feature itself, since it is cookieless and processes no visitor identifiers. It does not on its own trigger an ePrivacy consent banner requirement.
Legitimate interest in protecting your own content against scraping and unauthorised reuse. If you load the script from the vendor domain, document that legitimate interest to cover the visitor IP disclosed by the request.
The feature itself transfers nothing; it runs in the browser. If the script is loaded from the vendor domain rather than self hosted, the visitor IP and user agent reach the vendor, whose server location is not always published and could be outside the EEA. Self hosting removes this.
No. A cookieless, client side content protection feature that processes no visitor identifiers does not meet the threshold for a DPIA. At most, note the script delivery source in your records.
Self host the script from your own domain so no visitor IP reaches a third party, test that the deployed version sets no cookies, and tune the poisoning so it does not break accessibility tools or legitimate short quotations.
Other content protection approaches include disabling right click or text selection via CSS and JavaScript, server side rate limiting and bot detection, and adding visible attribution or watermarks. None of these need cookies when self hosted.
If self hosted and cookieless, you can simply note that a content protection feature is used and that it sets no cookies and does not track visitors. If you load the script from the vendor, mention that the vendor may receive your IP address.