FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. CopyPoison

CopyPoison

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does CopyPoison do?

Content protection and anti scraping tool that poisons copied text in the browser. It sets no cookies and tracks nothing; the only privacy point is the IP exposure if the script is loaded from the vendor domain rather than self hosted.

CopyPoison is a content protection and anti scraping tool aimed at discouraging the wholesale copying of website text. According to the available information, it works in the browser: when a visitor copies a longer passage, the script substitutes many letters with visually identical lookalike characters from other alphabets, so the pasted text looks the same to a human but is hard to reuse or index by machines.

What CopyPoison does

The tool is described as activating only on a copy event and poisoning only passages above a length threshold, leaving short snippets and code untouched. It runs as client side JavaScript and is offered for direct embedding or as a content management plugin. As a protective feature it processes the page text, not the visitor.

Cookies and tracking

From the available information, CopyPoison sets no cookies and stores no identifiers; the poisoning logic does not need to recognise individual visitors. As a cookieless functional feature it does not by itself create a consent banner obligation under the ePrivacy Directive. As always, confirm the exact behaviour of the version you deploy.

The delivery question

If the CopyPoison script is loaded from the vendor domain rather than self hosted, that request exposes the visitor IP and user agent to the vendor, in the same way any third party asset does. The vendor server location is not always published. Self hosting the script keeps the request first party and removes this exposure.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Legal basis and risk

Protecting your own content is a clear legitimate interest, and because the feature is cookieless and processes no visitor identifiers, the risk is low. If you load the script from the vendor, document that legitimate interest to cover the IP disclosure, or simply self host to keep things straightforward.

Recommendation

Self host the CopyPoison script from your own domain so no visitor IP reaches a third party, and verify in your own testing that the deployed version sets no cookies. Be aware that aggressive text poisoning can affect accessibility tools and legitimate copying, so balance protection against usability.

GDPR consent category

Essential

Websites using CopyPoison must obtain user consent under GDPR regulations.

Legal basisLegitimate Interest
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive

DPIA considerations

Based on the available information, CopyPoison runs entirely in the browser, sets no cookies and processes no identifiers, so a DPIA is not normally triggered. The only data point worth noting is that, if the script is loaded from the vendor domain rather than self hosted, the request discloses the visitor IP and user agent to the vendor. Because vendor hosting details for this kind of small tool are not always published, the prudent approach is to self host the script and document that no personal data is processed by the feature itself.

Sample consent text

This site uses a content protection feature that modifies text you copy from longer passages. It runs in your browser, sets no cookies and does not identify or track you. Where the underlying script is loaded from the provider, that provider may see your IP address as part of the standard request.

Technical details

Tracking methodNo tracking and no cookies by design. CopyPoison is a client side script that activates on a copy event and replaces longer copied passages with visually identical lookalike characters from other alphabets, so copied text is hard to reuse or index. It identifies no users and stores no identifiers. If the script is loaded from the vendor domain rather than self hosted, that request exposes the visitor IP and user agent to the vendor.
Server locationSelf hosted with the site assets, or loaded from the vendor domain (copypoison.com). Exact hosting and any CDN edge location depend on how the script is delivered.
Cookieless tracking availableYes
Data transferred outside the EUCopyPoison transfers no data itself; the poisoning runs entirely in the browser. If the script file is loaded from the vendor domain instead of being self hosted, that request reveals the visitor IP and user agent to the vendor, whose server location is not always disclosed and may sit outside the EEA. Self hosting the script removes this exposure.

Third-party domains contacted

copypoison.com

CopyPoison is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does CopyPoison set cookies?

Based on the available information, no. CopyPoison runs in the browser to modify copied text and does not need cookies or stored identifiers to do so. Always confirm the behaviour of the exact version you deploy.

Is consent required to use CopyPoison?

No prior consent is needed for the protection feature itself, since it is cookieless and processes no visitor identifiers. It does not on its own trigger an ePrivacy consent banner requirement.

What is the legal basis for CopyPoison?

Legitimate interest in protecting your own content against scraping and unauthorised reuse. If you load the script from the vendor domain, document that legitimate interest to cover the visitor IP disclosed by the request.

Does CopyPoison transfer data outside the EEA?

The feature itself transfers nothing; it runs in the browser. If the script is loaded from the vendor domain rather than self hosted, the visitor IP and user agent reach the vendor, whose server location is not always published and could be outside the EEA. Self hosting removes this.

Is a DPIA needed for CopyPoison?

No. A cookieless, client side content protection feature that processes no visitor identifiers does not meet the threshold for a DPIA. At most, note the script delivery source in your records.

How do I use CopyPoison compliantly?

Self host the script from your own domain so no visitor IP reaches a third party, test that the deployed version sets no cookies, and tune the poisoning so it does not break accessibility tools or legitimate short quotations.

What are the alternatives to CopyPoison?

Other content protection approaches include disabling right click or text selection via CSS and JavaScript, server side rate limiting and bot detection, and adding visible attribution or watermarks. None of these need cookies when self hosted.

How should I update my privacy policy for CopyPoison?

If self hosted and cookieless, you can simply note that a content protection feature is used and that it sets no cookies and does not track visitors. If you load the script from the vendor, mention that the vendor may receive your IP address.