FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. hCaptcha
h

hCaptcha

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does hCaptcha do?

hCaptcha is a privacy-focused CAPTCHA service by Intuition Machines designed as a GDPR-friendly alternative to Google reCAPTCHA. Unlike reCAPTCHA, hCaptcha does not share challenge data with Google for advertising purposes, provides clear GDPR contractual terms, and offers a privacy-pass mode that minimises data processing. Legitimate interest supports its use for bot prevention without requiring consent. It is a drop-in reCAPTCHA replacement widely used by privacy-conscious organisations.

What is hCaptcha?

hCaptcha is a CAPTCHA service developed by Intuition Machines as a privacy-focused alternative to Google reCAPTCHA. Like reCAPTCHA, it presents visual challenges (image selection grids) or invisible challenges to verify users are human. Unlike reCAPTCHA, hCaptcha does not share challenge or risk data with Google for advertising purposes. It processes the minimum data necessary for bot detection and provides clearer GDPR contractual terms.

Why hCaptcha is more GDPR-friendly than reCAPTCHA

The primary GDPR concern with Google reCAPTCHA is that challenge data may be used by Google for advertising and profiling purposes beyond bot detection. hCaptcha contractually commits to using challenge data only for security purposes. It provides a GDPR-compliant DPA, offers a privacy-pass mode that reduces data collection further, and does not read or influence existing Google account cookies. Legitimate interest is a more supportable legal basis for hCaptcha than for reCAPTCHA precisely because of this narrower data use.

Drop-in reCAPTCHA replacement

hCaptcha provides a drop-in replacement for Google reCAPTCHA v2 with a compatible JavaScript API. Replacing reCAPTCHA with hCaptcha typically requires only a script URL change and a new site key. The visual challenge interface is similar to reCAPTCHA v2. For invisible verification (reCAPTCHA v3 equivalent), hCaptcha''s Enterprise tier provides score-based invisible challenges.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Practical compliance steps

Sign the hCaptcha DPA and accept US data transfer under SCCs. Replace Google reCAPTCHA script tags with hCaptcha equivalents. Document the legitimate interest basis for bot prevention in your RoPA. Disclose hCaptcha in your privacy policy: bot prevention service, US data transfer, SCCs, and minimal data processing scope.

GDPR consent category

Essential

Websites using hCaptcha must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR) for bot prevention and security. hCaptcha is designed to minimise personal data collection. Unlike Google reCAPTCHA, hCaptcha does not share challenge data with advertising platforms. The privacy-first design supports a legitimate interest basis without consent.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, SCCs for US transfers. hCaptcha provides a GDPR-compliant DPA and is designed as a privacy-respecting reCAPTCHA alternative.

DPIA considerations

A DPIA is generally not required for hCaptcha standard deployments. Its privacy-minimising design and absence of advertising data sharing significantly reduce privacy risk compared to Google reCAPTCHA.

Sample consent text

This website uses hCaptcha to protect forms from spam and bots. hCaptcha processes minimal technical data for security purposes under legitimate interest. Data is processed in the US under Standard Contractual Clauses. See hCaptcha's privacy policy for details.

Technical details

Tracking methodCAPTCHA challenge widget, privacy-focused bot detection, no Google data sharing, first-party data processing, proof of work challenges
Server locationUnited States (Intuition Machines, Inc. / hCaptcha infrastructure)
Cookieless tracking availableYes
Data transferred outside the EUhCaptcha is operated by Intuition Machines Inc. (US). Challenge data and risk signals are processed on US infrastructure. EU personal data transfers require Standard Contractual Clauses. However, hCaptcha is explicitly designed to minimise personal data collection and provides a GDPR-compliant DPA.

Third-party domains contacted

hcaptcha.comnewassets.hcaptcha.com

Cookies placed

NameTypeDurationPurpose
hmt_idsessionSessionhCaptcha session identifier maintaining challenge state during bot verification — minimal data footprint

hCaptcha is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Why is hCaptcha more GDPR-friendly than Google reCAPTCHA?

hCaptcha contractually restricts data use to security purposes only — it does not share challenge data with advertising platforms. reCAPTCHA data may be used by Google for advertising. This makes legitimate interest more defensible for hCaptcha and reduces the privacy risk profile significantly.

Does hCaptcha require consent?

Generally no. hCaptcha's data processing for bot prevention can be justified under legitimate interest (Art. 6(1)(f)) as a necessary security measure. The legitimate interest balancing test supports bot prevention as proportionate to the security benefit. No consent banner is typically needed for hCaptcha.

Does hCaptcha transfer data outside the EU?

Yes. hCaptcha is operated by Intuition Machines (US). Challenge data is processed on US infrastructure. SCCs are required. Sign the hCaptcha DPA. Disclose the US transfer in your privacy policy.

What cookies does hCaptcha set?

hCaptcha sets hmt_id (session identifier) for maintaining the challenge state. Unlike reCAPTCHA, hCaptcha does not set long-lasting tracking cookies or read existing Google account cookies. The data footprint is minimal.

Is hCaptcha a drop-in replacement for Google reCAPTCHA?

For reCAPTCHA v2, yes. hCaptcha provides a compatible JavaScript API and visual widget. Replacing reCAPTCHA v2 with hCaptcha typically requires only changing the script URL and site key. For reCAPTCHA v3 (invisible, score-based), hCaptcha Enterprise provides equivalent invisible challenge capabilities.

Does hCaptcha offer an accessibility-friendly option?

Yes. hCaptcha provides a "privacy pass" mode that allows users who have previously verified to bypass the visual challenge, and audio challenges for visually impaired users. Accessibility was specifically designed into the challenge system.

How do I disclose hCaptcha in my privacy policy?

State: that forms are protected by hCaptcha for bot prevention, that hCaptcha processes minimal technical data (browser fingerprint, IP, challenge interaction) for security analysis, that this is processed under legitimate interest, that data is transferred to Intuition Machines in the US under SCCs, and link to hCaptcha's privacy policy.

What other CAPTCHA alternatives exist besides hCaptcha?

Cloudflare Turnstile: CAPTCHA-free, minimal data, free, strong privacy design. Arkose Labs: enterprise-level bot protection. Friendly Captcha: EU-hosted (Germany), proof-of-work based, no data sent to third parties. For maximum GDPR simplicity, Friendly Captcha (EU-hosted) or Cloudflare Turnstile are the strongest alternatives.