PrivCaptcha.com

PrivCaptcha, the modern privacy-first captcha built for GDPR

A fast, private, accessible puzzle in place of reCAPTCHA. No tracking, no Google, no ad-tech, and risky traffic simply gets a harder puzzle.

5-minute setup Built for GDPR & CCPA 10,000 verifications/month free
PrivCaptcha the captcha everything else orbits
Credential stuffing Scraping Fake signups Spam comments Account takeover Click fraud Card testing Giveaway abuse Ticket scalping Inventory hoarding

How PrivCaptcha sizes every challenge to the risk

PrivCaptcha doesn't care who your visitors are, only whether the request looks automated. Risk scoring from request signals picks a difficulty from 1 to 5. Everyone solves a puzzle, and a suspicious client has to solve a much harder one.

Example decision Scoring from request signals
Signals in

Only what the request itself reveals. No tracking cookies, no fingerprint resale, and no IP address kept afterwards.

One score

A single risk number, computed on the server and never accepted from the client. There is no rule file to keep current.

Difficulty out

The score picks a level from 1 to 5. Every request is challenged, and a client that looks automated gets a much harder one.

Designed for privacy from day one

No tracking cookies, no fingerprint resale, no ad-tech. We never store your visitors' IP addresses, and we minimise everything else we touch. Built for GDPR and CCPA obligations rather than around them.

GDPR CCPA IP addresses Tracking cookies Fingerprinting

PrivCaptcha features that stop bots without profiling people

Event log EXAMPLE
verified slider · difficulty 1 siteverify ok
solved no-visual challenge · keyboard proof-of-work ok
failed rotate · difficulty 5 · off by 41° retry issued
served pick · difficulty 4 · 10 shapes awaiting solve

Risk scoring from request signals

Every request is scored from what the request itself reveals, and the score picks the puzzle difficulty. Headless browsers and automation frameworks land at the top of the range.

Difficulty that scales with the request

The server picks one of five levels from the risk score and never accepts one from the client. Tolerances tighten and the proof-of-work gets heavier as a request looks more automated, so there is nothing for you to configure and no threshold to keep current.

±20° rotate
±12px slider
5 shapes

Chosen per request from the risk score.

<!-- swap two lines, done -->
<script src="https://privcaptcha.com/1/api.js" async defer></script>
<div class="privcaptcha" data-sitekey="your-site-key"></div>

Drop-in replacement

Swap the script tag and sitekey, keep your backend flow. Our endpoint speaks both the reCAPTCHA and the hCaptcha siteverify shape, so existing verification code keeps working unchanged.

reCAPTCHA siteverify hCaptcha siteverify
Server SDKs

An accessible challenge, not an apology

Screen-reader and keyboard users get a non-visual challenge that is a first-class path, not a broken fallback. Most competitors still send those visitors to an audio clip or a dead end.

No-visual challenge
Keyboard operable · no image, no audio CAPTCHA
screen readers keyboard only no colour cues
One visitorone puzzle, one proof
Bot at 10k attempts10k proofs

Proof-of-work priced against scale

Each challenge carries a small computation the client has to finish. A person pays it once and never notices. A farm hitting your signup form thousands of times a minute pays it every single time.

Privacy by design

No tracking cookies, no fingerprint resale, no ad-tech. We never store your visitors' IP addresses, and your users' data is never the product.

What is kept
A truncated HMAC of the IP, under a salt that rotates daily
Solve and failure counts, expiring after 24 hours
What is never touched
Raw IP addresses
Cookies of any kind
Device fingerprints
Anything sold or shared

No Google dependency, works everywhere

Nothing loads from a Google domain, so the widget behaves the same wherever your visitors are and whatever browser they hardened.

Per-site dashboard

Served, solved, failed and verified, per site and per day. That is the whole telemetry surface; there is nothing about the visitor to show you.

served solved failed verified
Illustrative shape only, not real traffic.

Who uses PrivCaptcha?

One integration, whatever you are protecting. The same widget, the same siteverify call and the same privacy guarantees, whether it sits on a checkout, a login or a public form.

Checkout, signup and gift-card forms

Card testing, gift-card draining and inventory hoarding all arrive at the same handful of endpoints, and all three are volume games: the attacker needs thousands of attempts for the numbers to work. A proof-of-work challenge on every attempt turns a free script into a metered one, while a real buyer solves a slider once and carries on to the payment step.

Where the widget goes
  • Checkout and payment
  • Gift-card balance check
  • Account registration

Login, onboarding and password reset

A captcha on a banking login sees every customer who ever signs in, which makes it the worst place on the site to hand a third party a profile of that person. PrivCaptcha never stores a visitor's IP address and loads nothing from an ad network, so adding friction for credential stuffing does not mean adding a data-sharing relationship you then have to disclose.

Where the widget goes
  • Login
  • KYC onboarding
  • Password reset and contact change

A drop-in for an existing reCAPTCHA or hCaptcha integration

Our siteverify endpoint answers in both the reCAPTCHA and the hCaptcha response shapes, so the verification code already running on your backend keeps working unchanged. The migration is the script tag and the sitekey; server SDKs for Go, Node, PHP and Python cover the rest, and the free tier covers most trial and contact forms outright.

Where the widget goes
  • Trial signup
  • API key request
  • Contact and demo forms

Account creation, giveaways and in-game economies

Multi-accounting and giveaway abuse scale with how cheap an account is to make. A puzzle and a proof-of-work on every registration and every entry put a real price on each one, and because the level is picked per request, the players who are not farming still get the quick version rather than a blanket lockdown.

Where the widget goes
  • Registration
  • Giveaway and drop entry
  • Trade and market listing

Public services have to work for everyone who arrives

A public form cannot quietly exclude the people who most need it. The non-visual challenge is a first-class path for screen-reader and keyboard users rather than an audio clip bolted on at the end, and nothing loads from a Google domain, so the form still works on hardened networks, on privacy browsers, and in regions where those services are unreachable.

Where the widget goes
  • Benefit and permit applications
  • Appointment booking
  • Enquiry forms

Endpoints that cost you money on every call

SMS sends, prepaid top-ups and number lookups all bill per request, so automated abuse shows up on the invoice before it shows up anywhere else. Scoring each request from what it reveals about itself sizes the puzzle per attempt instead of blocking whole carriers or regions - which matters when one mobile NAT sits in front of thousands of real subscribers.

Where the widget goes
  • SMS verification send
  • Prepaid top-up
  • Number lookup

A captcha you can put in your own privacy policy

If the promise of your product is that you do not track people, a captcha that fingerprints them undoes it on your most sensitive page. We keep a daily-rotating HMAC of the IP rather than the address itself, expire the counters after 24 hours, set no tracking cookies and sell nothing - so the paragraph you write about us is short.

Where the widget goes
  • Signup
  • Contact form
  • Newsletter subscribe

Why you should switch to PrivCaptcha today?

Every service on this list stops automated traffic, and all of them are run by people who know the problem well. The difference is what happens to your visitors on the way through: who their request is shared with, and what is kept afterwards.

Capability PrivCaptcha reCAPTCHA hCaptcha Turnstile
Stops automated traffic
Drop-in reCAPTCHA and hCaptcha siteverify
Non-visual accessible challenge Built in, keyboard operable Audio challenge Accessibility programme Not published
Never stores visitor IP addresses See their policy See their policy See their policy
Loads from a Google domain
Proof-of-work on every challenge Not published Not published Not published
Tuning required None, scales per request Score threshold Difficulty setting Widget mode
Free tier 10,000 / month See their pricing See their pricing See their pricing
Personal data points sold 0 See their terms See their terms See their terms

The privacy column is the reason to move. A captcha sits on your most sensitive forms, which makes it the last place you want a third party building a profile of the person filling them in. We never store your visitors' IP addresses, we sell nothing, and nothing loads from an ad network.

Compiled from publicly available documentation in August 2026. Where a behaviour is not published we say so rather than guess, and each vendor's current terms are the authority on their own product.

PrivCaptcha implementation - migrate in a few minutes

We answer on reCAPTCHA's and hCaptcha's own script paths and return their verify shapes, so the markup, the response field and the backend call you already have keep working. You change the script URL and the sitekey - that is the whole migration, and it is usually done inside one deploy. Turnstile needs one extra edit, and the guide below says exactly which.

Server SDKs for Go, Node, PHP and Python, or call the REST endpoint directly.

Frequently asked questions about PrivCaptcha

Straight answers on how the challenge works, what we keep, and what actually changes on your side when you switch.

Three steps, in every implementation. The page loads a widget, the visitor does something the widget can check, and the widget hands back a token. Your server then sends that token to the provider and only accepts the form if the answer comes back valid - the token is the proof, not the puzzle itself. PrivCaptcha follows exactly that shape: our script renders a puzzle, writes the token into a hidden privcaptcha-response field, and your backend verifies it server-side. What differs is the middle step. Most providers decide whether you look human from a profile of you; we score the request itself and use that only to pick how hard the puzzle is.
Every request is challenged - there is no invisible pass to aim a script at, and no allowlist that skips the check. What changes is the form the challenge takes and what it costs. The server scores each request and picks one of five difficulty levels, so an ordinary visitor gets a couple of seconds and a client that looks automated gets tight tolerances and a heavier proof-of-work. On the non-visual path, taken by screen-reader and keyboard visitors, there is no puzzle to solve at all: the proof-of-work is the whole challenge, at a fixed 22 bits.
Because at the moment the request arrives the server has no way to know that. It sees headers and an address, not a person - so most systems guess, and the guess is wrong often enough that real customers get blocked, especially on a VPN, a shared office connection or a privacy browser. PrivCaptcha does not guess at your identity. Everyone gets a puzzle, and the only thing the score changes is how hard it is - so a bad guess costs you a few extra seconds instead of your account.
Not in the sense of making a route unreachable - no captcha does that. Solver farms and automation exist, and anything a person can solve can eventually be solved for money. What a captcha really does is put a price on each attempt, so abuse that only pays at volume stops paying. PrivCaptcha is built around that honestly rather than around a claim of being unbreakable: the puzzle prices the attempt, the proof-of-work prices the scale, and a client that keeps failing pays more each time.
For the classic image grids, largely yes - picking traffic lights out of photographs is the exact task modern vision models are good at, which is why that style of challenge has been getting weaker for years. We do not claim our puzzles are unsolvable by a machine. We assume they are, and make solving them at scale expensive instead: difficulty rises with the risk score and every solve carries a proof-of-work, so the cost curve bends against the attacker even when the puzzle itself is beatable.
Not today, and that is the quiet advantage. The solving services that make bot work cheap sell turnkey support for the big names - you pay per solve and their SDK handles reCAPTCHA or hCaptcha for you, because a captcha on millions of sites is worth building against once and selling forever. Nobody ships a package for us, so an attacker has to write a custom solver, keep it running, and redo that work whenever our challenges change - real engineering time before the first request goes out, and every solve still pays the proof-of-work on top. We would rather be straight about the shape of this: it is an economic advantage, not a mathematical one. If we became the default captcha, solvers would follow. What does not change is the cost curve underneath - difficulty that rises with the risk score, and work priced per solve - which stays expensive at volume whether or not someone has packaged it.
No. An address is used for the length of one request and never written anywhere. What we keep is an HMAC of it under a salt that is random, lives only in Redis and rotates every day, so yesterday's hashes cannot be linked to today's. The counters under that hash expire after 24 hours.
No. Nothing on the widget path touches a Google domain, and the fonts on this site are self-hosted rather than fetched from Google Fonts. That is also why the widget behaves the same on hardened browsers, on privacy browsers and on networks where those services are unreachable.
It depends entirely on what leaves the page. A captcha usually sits on your login and checkout - your most sensitive forms - and most providers send the visitor's IP address and behavioural signals to a third party from there, which is a processing relationship you have to disclose and justify. PrivCaptcha is built to make that section short: we never store a raw IP address, only a truncated HMAC under a salt that rotates daily, with counters that expire after 24 hours. No cookie is set, nothing loads from an ad network, and even the fonts are served from our own domain. Your own legal review still governs how you describe us - we are a processor, and that list is what we process.
Because the answers were worth something. Those grids doubled as free labelling for the provider's own datasets - visitors were doing unpaid work on the way into a form. Our puzzles produce nothing of the sort. Rotating a disc or dragging a piece into a notch generates no dataset, trains nothing and is worth nothing to us beyond the seconds it takes; there is no second product being built out of your visitors' time.
They get a non-visual challenge as a first-class path, not an audio clip and not a dead end. It is keyboard operable, needs no image and no sound, and relies on no colour cues. A site owner can turn it off per site, but it is on by default.
The edit itself is a few minutes. Our verification endpoint answers in both the reCAPTCHA and the hCaptcha response shapes, so the code already running on your backend keeps working - you change the script tag and the sitekey, and nothing else. After that it is your normal review and deploy. Server SDKs are available for Go, Node, PHP and Python.
10,000 verifications a month are free, which covers most contact, signup and comment forms outright. Beyond that the account needs quota or credits; if both run out we stop issuing challenges and the widget shows a quiet unavailable state rather than breaking your page.
No - and not because we filter that traffic out afterwards, but because the meter never counted it. A verification is charged only when your own backend successfully verifies a token, and each token can be redeemed exactly once. Asking for challenges costs you nothing. Failing them costs nothing. Even solving one costs nothing until your server accepts it. So spending a single unit of your quota means an attacker had to pass a real challenge - a puzzle plus its proof-of-work on the visual path, or a fixed 22 bits of work on the non-visual one - and then get your backend to check the token, by which point it is a request you would have wanted verified anyway. The challenge endpoint is also rate limited to 10 requests a second per address, and once you have listed your domains, a request from any other origin is refused before a challenge is issued.
No. There is no rule file, no signature list and no score threshold to maintain. Difficulty is chosen per request from the risk score, so the protection tracks the traffic instead of a setting you chose once.

Add PrivCaptcha now, in two lines of code

Drop in the script tag and sitekey and point your existing siteverify call at us. 10,000 verifications a month are free.