CIPA / ECPA / VPPA / WESCA / FSCA

got pixels?

Test the journey behind the allegation.

For pixel litigation defense, describe the site, consent choice, and user path. Got Pixels builds the browser tests, follows the journey, and records requests, payloads, and screenshots at the steps that matter.

Try it yourself. Open the app.

byPapaya Privacy Co.Evidence technology, not legal advice.
Example journey test

After rejecting cookies and reaching checkout, did cart details reach a third party?

JourneyProduct, cart, checkout
Consent stateEssential cookies only
RecipientThird-party analytics endpoints
ContentsProduct + size + cart value
EvidenceRequests + screenshots

How it works

From journey to evidence.

Describe the disputed user path. Composer builds the browser tests, runs the journey, and records what happened at each step. Reuse the workflow when the site changes.

Illustrative workflow
Composer

What do you want to audit?

Audit example.com for CIPA exposure from California. Test the checkout journey after rejecting cookies.

Describe the site, law, consent path, and journey.

Step 1 of 4: Describe the journey

Evidence record

Beyond page load.

A homepage check cannot show what fired after a visitor searched, watched a video, submitted a form, or checked out. Got Pixels ties requests and screenshots to those actions and the consent path. Counsel applies the law.

View sample report

Jurisdiction + consent

Location, banner state, consent choice, GPC, and when consent changed

Communication + journey

Video, search, chat, checkout, or form actions behind the disputed event

Timing + initiator

When the request fired relative to the user action, and which script initiated it

Recipient + identifiers

Third-party endpoints, cookies, identifiers, and the request chain

Contents + payload

URLs, events, search terms, form values, video data, and request parameters

Visual + repeatable record

Screenshots, agent steps, network logs, and rerunnable journeys

Pixel litigation landscape

One pixel. Different legal questions.

One browser request can raise different legal questions. Got Pixels preserves the facts counsel needs to assess each theory.

Read the pixel litigation evidence guide

CIPA

Cal. Penal Code §§ 631, 632, 638.51

Interception, confidential communications, and pen-register theories

Consent state, in-transit timing, third-party role, request data, addressing signals

ECPA

18 U.S.C. §§ 2511, 2520

Interception, use, or disclosure of electronic communications

Contents, contemporaneous acquisition, recipient, consent, party and service-provider facts

VPPA

18 U.S.C. § 2710

Disclosure of video-viewing information tied to a consumer

Video title or URL, watch event, user or device identifier, recipient, consent record

WESCA

18 Pa.C.S. § 5703

Interception, disclosure, or use of electronic communications

Pennsylvania user context, contents, timing, consent, tracker and website roles

FSCA

Fla. Stat. §§ 934.03, 934.10

Interception of electronic communications and substantive contents

Searches, health details, form fields, chat text, consent state, third-party requests

STATE + HEALTH

MD, WA, IL, MA and other statutes

State interception, health-data, privacy, and consumer-protection theories

Jurisdiction, data sensitivity, authorization, custom events, identifiers, disclosed recipients

Scope, defenses, standing, remedies, and statutory definitions vary by jurisdiction and current case law. Got Pixels captures evidence for counsel to review. It does not determine liability.

Audit method

Pressure-test the facts, not a generic risk score.

Got Pixels turns each legal question into a repeatable browser test with preserved evidence.

01

What communication occurred?

A video watch, search, chat, checkout, or form entry can create a different record.

02

When was it acquired?

Compare before consent, after accept or reject, and with GPC. Match each request to the user action.

03

What left the browser?

Inspect URLs, events, identifiers, form values, cookies, payloads, and recipients.

04

Which legal context applies?

Record location, consent, content, and party roles so counsel can apply the relevant law.

For defense teams

Client sites or your own.

Open the app

Outside counsel and defense consultants

Test a client's disputed journey.

Describe the alleged consent path and user flow without scripting every click. Review what was sent, who received it, when it fired, and what remains unknown.

In-house defense teams

Recheck your own site after changes.

Rerun the saved journey after a site or tag change. Compare consent states, then share the evidence with outside counsel.

Questions about the software

What defense counsel needs to know.

Got Pixels preserves the browser record. Counsel applies the law.

What does the evidence record include?

The tested jurisdiction, consent state, browser journey, requests, payloads, screenshots, recipients, and agent steps.

Can the same journey be run again?

Yes. Reuse the workflow to compare consent states or check a fix without designing the path again.

Which pixel-litigation theories can it investigate?

The record can inform CIPA, ECPA, VPPA, WESCA, FSCA, state wiretap, and health-data analysis. Counsel decides what law applies.

Does Got Pixels determine liability?

No. Got Pixels preserves technical evidence. Counsel evaluates liability under the applicable law, consent record, parties, and defenses.

What happens in a demo?

We run a scenario relevant to your work, then show how to inspect the browser evidence and report. Bring a site or use case if you have one.

Got Pixels pricing

Plans for repeat testing.

Each run tests a consent choice and user journey, with requests, screenshots, and a report for review. Plans reflect how many runs and seats you need. For a walkthrough, bring your site or legal question to a demo.

Start without a subscription

4 free runs per user.

Try a user journey before choosing a plan. Each audit execution uses one run.

01 / plan

Professional

For an individual running focused audits.

$180/ month

or $2,000 annually

  • 1 seat
  • 25 runs / month
View plan details
02 / planRecommended

Organization

For a team sharing an audit allowance.

$720/ month

or $8,000 annually

  • Unlimited seats
  • 120 shared runs / month
View plan details
03 / plan

Unlimited

For one person running tests without a run-count cap.

$2,400/ month

or $24,000 annually

  • 1 seat
  • Unlimited runs
View plan details
04 / plan

Enterprise

For organizations needing custom terms or capacity.

Custom

Monthly or annual terms by agreement

  • Custom seats
  • Custom usage
Book a demo

Accept All, Reject All, and GPC each count as a run. Paid plans include Composer, screenshots, reports, PDF and Markdown export, sharing, API and MCP access, and scheduled runs. See the app for full terms.

Got Pixels

Build and rerun journey tests.

Set the user path once, inspect what fires along the way, and reuse the workflow when the site changes. Start in the app.

  • Set a site, jurisdiction, consent choice, and journey
  • Reuse the journey across consent states and site changes
  • Inspect requests, payloads, and screenshots
  • Share the report for legal review
Open the app

Product findings support legal analysis. The software does not determine liability or compliance.

Product demo

See a full user journey tested.

Bring a site, consent path, or legal question. We'll show how Got Pixels builds the test, runs the journey, and reports the evidence.

  • A walkthrough using your site and user journey
  • The consent path, jurisdiction, and tracker you choose
  • How to inspect requests, screenshots, and limitations

got pixels?

byPapaya Privacy Co.

© 2026 Papaya Privacy Co.

Browser audit software for defense-side pixel litigation teams. Not legal advice, and no result determines liability or compliance.