Build a privacy-focused, GDPR- and CCPA-friendly static website with Publii
Static websites remove many of the components required by dynamic CMSs. A website published with Publii does not need a publicly accessible database, PHP or a public Publii admin panel. This reduces the attack surface and the number of server-side processes that could handle personal data.
A static website is not automatically free from data processing. Hosting logs, analytics, forms, embedded media and other external services may still collect data or send it to third parties. You decide which services your site uses when you configure it.
Publii includes privacy tools for managing services that require consent. Create cookie groups, block external content until a visitor gives consent and pass consent choices to supported services.
These tools can support GDPR- and CCPA-friendly workflows, but the requirements that apply to your site depend on its actual configuration.
Publii runs as a desktop app on your computer. You can manage content locally without a Publii cloud account or login.
The app does not collect telemetry or usage statistics about your work. Drafts and site data stay on your computer until you publish them or connect the project to an external service.
This gives you control over where your content is stored and when it is published.
Themes
All theme assets are served locally
Official free and premium Publii themes keep fonts, scripts, icons and CSS files on your webspace, together with images generated by Publii. These themes do not use a CDN or another third-party provider to deliver those assets.
This prevents theme assets from creating automatic connections to external providers. When assessing the privacy of the complete website, also consider your hosting, extensions and every external resource you add.
Cookies
Configure the cookie banner for your site
Use Publii's built-in cookie banner to inform visitors about cookies and request consent when required.
Choose a simple notice or configure detailed consent with multiple cookie groups. Describe each group's purpose, link to your privacy policy and provide appropriate accept and reject options. Before publishing, test that every script and service requiring consent is assigned to the correct group.
Learn more →Iframes
Consent for embedded content
Block embedded content until a visitor consents to the assigned cookie group. Publii displays a placeholder with customizable text and a button instead, so services such as YouTube or Vimeo are not loaded on the initial page view.
Learn more →Videos
Privacy settings for YouTube and Vimeo
Enable privacy-enhanced mode for YouTube and Do Not Track for Vimeo to reduce tracking by embedded videos. The player is still external content. If it should load only after consent, also assign it to the appropriate cookie group.
Learn more →Plugins & Scripts
Manage plugins and external scripts
Publii offers optional plugins for search, comments and analytics. If a plugin sets cookies or sends data to an external service, assign it to the appropriate cookie group in the app. Its script will load according to the stored consent choice. Scripts you add manually must be connected to the consent system and tested separately.
Learn more →Google Consent Mode v2
Connect Google Consent Mode v2 to the cookie banner
If you use Google Analytics 4, Google Ads or another supported Google service, connect Publii's cookie banner to Google Consent Mode v2. Set the default consent values and define which signals are sent when a visitor selects a cookie group. Consent Mode adjusts the behavior of supported Google tags based on the visitor's choice. It does not replace a cookie banner or a legal review of your configuration.
Learn more →What are you waiting for?
Start building your site today.
- 1 Download Publii
- 2 Write your content
- 3 Publish your site