2
5 Comments

Building a GDPR consent API for solo devs who can't afford OneTrust

Hi IH πŸ‘‹

Four weeks ago, I was building a small SaaS and nearly fell off my chair when I saw OneTrust's pricing β€” €100+/month. For a solo dev with zero revenue, that's a non-starter.

So I did what any sane indie hacker would do: I built my own.

ConsentKeep β€” a lightweight consent logging API for solo developers and SMEs. It records timestamp, IP hash, user agent, and generates audit-ready reports for regulators like CNIL (France) and BfDI (Germany). Flat pricing: $29/month.

What I need from you β€” roast me hard:

  1. Is the value prop clear? Does "consent logging API" make sense, or is it too technical?
  2. Pricing: $29/month after a 14-day free trial (no CC). Is this a "hell yes" or "hell no" for a solo dev?
  3. What stops you from clicking "Start Trial"? Too much friction? Missing feature? Trust issue?

Landing page: consentkeep.com

I'd rather hear it from you than from a regulator's fine notice πŸ˜„

Thanks in advance!

on July 26, 2026
  1. 1

    The interesting question is whether developers wake up because they want "consent logging" or because they fear compliance risk.

    What would convince you that the compliance-risk angle is strong enough to create urgency, rather than this becoming another tool developers postpone until they grow?

    1. 1

      Nobody wakes up excited about consent logging. Let's just be honest.

      What actually creates urgency?

      1. Your first enterprise lead says "we need a compliance review" – suddenly it's priority #1
      2. You see another startup got fined for non-compliance – nothing motivates like other people's pain
      3. Your investor asks about GDPR readiness – that's the moment you realize you should've done this months ago

      The thing is, most devs think "we'll get to it later." And later becomes never. Until it's too late.

      The only way to make people care is to make it effortless. I'm talking 5-minute setup. One API. Done. If you can do that, you don't need to convince them – they'll just do it.

      The real shift happens when companies realize that compliance isn't just a "legal problem" – it's a sales problem. When you're losing deals because you can't prove compliance, suddenly it's not about GDPR anymore. It's about revenue. And that's the kind of urgency that actually gets things done.

      1. 1

        Appreciate the context.

        Would be good to continue the conversation as you learn which triggers create the strongest pull from users.

        What's the best email to reach you on?

        1. 1

          Sure, it's support@eu.consentkeep.com.

          Quick question though – are you working on something similar, or just curious about the space? Just so I know who I'm chatting with 😊

          1. 1

            Thanks! I’ve just sent it over.

            Looking forward to hearing your thoughts whenever you have a chance.