Skip to main content
Privacy & compliance

Verify humans. Not track them.

Most CAPTCHA vendors ask a visitor to trust a third party with cookies, device fingerprints, and cross-site behavior just to prove they're not a bot. MTCaptcha verifies the same thing without collecting any of it, which is the difference between passing a privacy review and stalling in one.

yoursite.eu/signup

For more themes and CSS style customization,

see MTCaptcha's Code Builder

Built for screen readers

MTCaptcha works with assistive technology out of the box, no special setup required.

  • , Play the audio challenge
  • ? Refresh the challenge

MTCaptcha is WCAG 2.1 AAA, EAA and accessibility compliant. For more details and supported audio languages,

see MTCaptcha's Accessibility FAQ

Turn this on to simulate automated QA and CI pipelines without solving a real challenge.

Test Mode Enabled, try entering '11111111' into the captcha text field to complete the captcha.

For more details on how to enable Test Mode and automated UX unit testing,

see our Developer Guide
Demo Sign in

This is the real widget, live, not an illustration. Try it above the way a visitor to yoursite.eu would.

Why the CAPTCHA itself became a privacy question

The most widely used CAPTCHA on the web also happens to be run by the company with the largest advertising-tracking network on the web, and it doesn't verify a visitor in isolation, it scores them using signals gathered across other sites they use the same tracking cookie on. For a lot of legal and privacy teams, that's no longer an acceptable trade for spam protection.

GDPR, CCPA, and a growing list of regional privacy laws don't ban CAPTCHAs, but they do require being able to explain what data is collected, why, and where it goes, and "a black-box third party scores it somehow" is not an answer that clears a procurement review.

What's actually at stake in the switch

Regulatory exposure is real, not theoretical

A verification tool that collects more data than it needs to is exactly the kind of finding a GDPR/CCPA audit is designed to catch.

Consent banners get more complicated, not less

A tracking-based CAPTCHA adds another third party to disclose and get consent for, on every page it protects.

User trust erodes quietly

Visitors increasingly notice and object to cross-site tracking, a CAPTCHA is a strange place to lose that trust over something incidental to the actual product.

Some sites carry a higher duty of care than others

Government, healthcare, financial services, and platforms built for younger users don't get to treat privacy as a nice-to-have, it's the baseline the rest of the product has to clear.

How MTCaptcha verifies without the trade-off

The privacy answer isn't a policy page, it's the absence of the thing that would need explaining.

GDPR-compliant by design

Built to verify a visitor without cross-site tracking or unnecessary data collection, so there's no invasive behavior to disclose in the first place.

Data Privacy Framework certified

Self-certified to the U.S. Department of Commerce under the EU-U.S., UK, and Swiss-U.S. Data Privacy Framework, the actual legal mechanism that makes moving data across the Atlantic defensible, checkable on the government's own registry, not just claimed on this page.

No invasive tracking

Doesn't build a profile of the visitor across other sites to make its decision, the risk signal comes from the request itself.

WCAG 2.1 AAA-conformant

Privacy and accessibility compliance overlap in procurement review more often than either gets credit for, this clears both bars at once.

SOC 2 Type II attested

Independent, third-party-audited proof of how data is actually handled, not a self-issued claim.

Proven to work in China

For teams whose compliance question isn't just "what data do you collect" but "where does verification even work": confirmed reliable there, not a capability claim untested at scale.

Deployed in the wild

State government (public benefits)

On: Citizen login for a benefits-enrollment portal

Protects: Verification on a service handling sensitive citizen data

Consumer gaming (virtual world for teens)

On: Account sign-up

Protects: Signup on a platform where user privacy carries an especially high bar

Real deployments, industry and mechanism only, no company names, by design.

Seen in the wild

State governmentKids' platformsPublic sector
SOC 2 Type II attested
WCAG 2.1 AAA AAA accessibility
GDPR EU data protection
DPF EU, UK & Swiss
CCPA CA privacy

Talk to us before your next privacy review

Tell us what's driving the switch, an audit, a procurement review, or a policy change.

By clicking “Accept”, you agree to our use of cookies, including analytics cookies that help us understand how the site is used. Cookies essential to the captcha widget are always on. Cookie policy