Poliogo

Compliance for the stack you already build on

Poliogo reads the services your product actually calls and writes the disclosures each one forces into your privacy policy, cookie policy and terms. Pick the one you use and see exactly what it changes, what it collects, and where it processes.

21 stacks covered50+ services classifiedDetected from your code
21
stacks with a page of their own
50+
services the scan classifies
3
documents generated and kept current

Why a page per service rather than one long list

Because the answer genuinely differs. A payment provider moves your Terms; an ad pixel creates an opt-out obligation; a vector database changes what deletion means.

Detected, not declared

Automatic

Each service resolves from its package, the endpoint it is called at, or the credential name in your .env.example — so an integration written as a bare fetch with no SDK is found like any other.

The same rows your documents use

The data categories, purposes, processing locations and cookie tables on these pages are read from the catalog the generator assembles real documents from. The page cannot promise a clause the product would not write.

Legal entities, not brand names

A sub-processor schedule naming “Sentry” rather than Functional Software, Inc. is the kind of thing a customer's data protection review sends straight back. Poliogo generates the entity.

Kept current after you stop looking

Drift

Later scans are diffed against the snapshot your documents were generated from, so a service added next month becomes an update you approve rather than a quiet inaccuracy.

Framework

One stack in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Next.js — Next.js is where the compliance surface and the code sit closest together: the policy pages are routes, the banner is a layout concern, and both are files a pull request can carry.

Backend

One stack in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Supabase — Supabase is database, file storage and authentication in one project, so a single dependency is simultaneously where user records live, where uploads live, and the thing setting session cookies — three disclosures from one line of your manifest.

Hosting

3 stacks in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Vercel — Vercel is a sub-processor you did not decide to add — it is where the application runs, so every visitor's IP address reaches it before a single line of your own code does.
  • ✓Netlify — Netlify sits between every visitor and your site, which makes its request log a record of who came to see you — held by a company most privacy policies never name.
  • ✓Cloudflare — Cloudflare sets a cookie on your visitors that you did not write, cannot remove and are nevertheless the one responsible for disclosing.

AI builder

2 stacks in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Lovable — Lovable writes the code, which means integrations arrive in your project without you ever typing the import — and a policy that was accurate on launch day is stale by the next prompt.
  • ✓Replit — A repl is the editor, the host and the database at once, so Replit, Inc. holds both the code you are writing and the data your visitors leave behind in it.

Payments

One stack in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Stripe — Stripe is the integration that changes your Terms of Service as well as your Privacy Policy — refunds, billing and tax are contract terms, and no amount of privacy drafting covers them.

AI

3 stacks in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓OpenAI — Sending a user's text to a model is a disclosure obligation in its own right: the EU AI Act asks you to say an AI system is in use, and GDPR Article 22 asks whether a decision was made about somebody by a machine.
  • ✓Anthropic — Claude in a product means user content leaves your infrastructure to be analysed, and the retention window is contractual rather than something your own code controls.
  • ✓Pinecone — A vector database is why “delete my data” is harder than it looks: an embedding derived from a deleted record is still derived from a person, and it does not vanish when the row does.

Authentication

2 stacks in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Clerk — Authentication is the one integration that is definitionally personal data — there is no anonymous mode, and the session cookie is set before a visitor has agreed to anything at all.
  • ✓Firebase — Firebase is Google under another name, so adding it puts Google LLC into your sub-processor schedule even in a product with no Google Analytics anywhere near it.

Analytics

3 stacks in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓PostHog — Session replay is the part that changes the legal answer: recording somebody's screen is categorically different from counting a page view, and most policies describe only the counting.
  • ✓Google Analytics — Google Analytics is the most-litigated integration on the web — data protection authorities in Austria, France, Italy and Denmark have each found a plain deployment of it unlawful on transfer grounds.
  • ✓Mixpanel — Mixpanel builds a profile per person rather than a count per page, which moves it out of analytics and into profiling — a word the GDPR defines and gives people a right to object to.

Advertising

One stack in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Meta Pixel — Under California, Colorado, Connecticut and Virginia law an advertising pixel is a sale or share of personal data — which obliges you to offer an opt-out, not merely to describe what you are doing.

Monitoring

One stack in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Sentry — Sentry is the integration that collects personal data by accident — a stack trace carries whatever happened to be in scope at the moment the code threw.

Email

One stack in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Resend — Transactional email is the integration people forget is an integration — a password reset is still a third party receiving your user's address and the contents of the message.

Commerce

2 stacks in this group. Each has a page of its own naming what it receives, where it processes, the cookies it sets and the clauses it adds to your documents.

  • ✓Shopify — A storefront collects shipping addresses, which is the one category of personal data that is unavoidable, un-minimisable and has to be retained for tax far longer than anything else in the product.
  • ✓WordPress.com — WordPress.com hosts the site and the plugins, so the list of third parties on a WordPress page is set by an admin screen rather than by anything a developer committed.

Questions people ask

How does Poliogo know which services my product uses?

It reads what is literally in your project — dependency manifests, source files, configuration, edge functions and .env.example — and matches them against a signature library of known vendors. Matching on the endpoint as well as the package name is the part that matters: an integration called with a bare fetch and no SDK installed never appears in package.json, and that is exactly the shape a vibe-coded product tends to have.

My service is not on this list. Does that mean it is not detected?

No. These pages exist for the stacks people search for by name; the catalog behind them carries far more, and the scan also reports outbound endpoints it cannot resolve to a known vendor so you can name them yourself. A host that does not resolve is offered as a question rather than asserted as a sub-processor, because a schedule naming a recipient that receives nothing is a false statement in a legal document.

Does adding a service really change my documents, or just the vendor list?

It depends on the service, which is the reason these pages are separate. A payment provider adds billing, refund and tax terms to your Terms of Service. An analytics tool moves the Cookie Policy and the banner. An advertising pixel creates a sale-or-share disclosure and an opt-out obligation under US state law. An AI provider adds training, retention and automated-decision disclosures. Each page says which of the three documents its service moves.

Is my source code sent anywhere?

The files a scan reads are processed in memory and dropped when the request ends; what is kept is the list of services it found, with the file and line each was proved from. The MCP server goes further and scans on your own machine, transmitting only the detected-service fingerprint. Two columns do hold customer files on purpose: the pre-edit original of any file a page install changed, so deleting the project can restore it, and the edited copy of a document while an update waits for your approval.

What does this cost?

Unlimited manual scans, the full Updates page and the accessibility widget with all of its tools are on every plan including Free, which covers one project with a Privacy Policy and Cookie Policy. Terms of Service, the MCP server and automatic background scanning start at Starter. The full comparison is on the pricing page.

Does any of this amount to legal advice?

No. Poliogo reads code and assembles clauses from a library built from published regulatory text; it does not weigh anybody's circumstances, and no generated document settles whether a business is compliant — that turns on how the business actually handles data. What it is for is keeping the documents describing what the software genuinely does, which is the part that goes stale on its own.

See what a scan finds in your project

Connect a repository, a host or a live address and read the list before anything is generated. Free plan, no credit card. Poliogo automates the reading and the drafting, not the judgement — it is not a law firm and this page is not legal advice.

Start free — no credit card

Poliogo is an automated code analysis and document display tool, not a law firm. Poliogo does not provide legal advice, representation, or guarantees of statutory compliance, ADA/WCAG certification, or legal immunity. Visual banners and generated documents are advisory tools and do not substitute for professional legal review.