got pixels?
Audit Complete
Website: https://www.nature.com/
Consent Flow: Composer:Pixels
Post-Consent Flow: Reload only
Pages visited: 4
Agent: browser-use (7 steps)
Location: Pennsylvania (US-PA)
Completed: 2026-09-14T18:08:02.897789+00:00
Checkpoints: 3 phases captured
Pixel Litigation Assessment
Pennsylvania WESCA Matrix
| Category | Result | Risk | Evidence & Authority |
|---|---|---|---|
| All-party consent | Elevated | High | The Initial Cookie Banner Visual Check was Yes, but the PA test did not accept; it selected “Reject optional cookies.” The initial-before-scroll and post-scroll privacy-interface screenshots show a prominent choice interface, not prior assent, while Google advertising requests continued after rejection. WESCA’s pertinent private-party consent exception requires prior consent of all parties; 18 Pa. C.S. §§ 5703, 5704(4), 5725. Popa v. Harriet Carter leaves notice/implied-consent adequacy fact dependent rather than automatic. |
| Contents interception | Elevated | High | Following rejection, Google ad requests contemporaneously carried the searched phrase “climate change” in the search URL and prev_scp, then carried the visited article URL, DOI, subject/keyword fields, and referrer path. Those are stronger “contents” facts than bare device telemetry, although this run did not establish keystroke capture or full session replay. Popa treats device-assisted acquisition of website communications as potentially actionable under WESCA and rejects a broad private direct-party carveout. |
| Civil private right of action / damages | Elevated | High | If a factfinder found an unlawful interception, disclosure, use, or procurement, § 5725 provides a private claim for actual damages or at least $100 per day/$1,000, plus potential punitive damages, fees, and costs. The exposure signal is meaningful because the challenged Google flows appeared both before any choice and after reject-all, but liability still turns on interception, Pennsylvania nexus, and consent proof. 18 Pa. C.S. § 5725. |
ECPA Wiretap Matrix
| Category | Result | Risk | Evidence & Authority |
|---|---|---|---|
| Contents interception in transit | Elevated | High | The Google /gampad/ads request was sent during the search/article journey and included the search phrase, URL, article DOI, and contextual keyword fields. That supports an argument that substantive communication content, rather than only routing data, was acquired contemporaneously. 18 U.S.C. § 2510 defines interception and contents; the Third Circuit has held URL information can constitute contents in a Wiretap Act analysis. |
| Party vs third-party interceptor | Limited | Medium | The strongest ECPA defense is that the browser sent the ad request directly to Google’s servers, making Google an intended recipient/party to that specific transmission. That framing is materially different from a script duplicating a user-to-site communication for an undisclosed recipient. In re Google Cookie Placement applied § 2511(2)(d) where browsers directly sent GET requests to the trackers. |
| One-party consent | Mixed | Medium | The user did not accept the displayed optional-cookie choices and expressly rejected them; that weakens a consent narrative. But § 2511(2)(d) separately protects a private interceptor that is itself a party to the communication, so one-party consent is not the only defense in play. 18 U.S.C. § 2511(2)(d). |
| Crime-tort exception § 2511(2)(d) | Unclear | Medium | The post-rejection transmission of search and article-context data could invite an argument that commercial tracking was undertaken for an independently tortious purpose, but this record does not identify or prove a separate predicate crime or tort. Courts are divided on how marketing purpose interacts with § 2511(2)(d), so neither the exception nor the party defense is automatic. In re Google Cookie Placement describes the independent-tort requirement applied in that line of cases. |
| Contents vs metadata | Elevated | High | Viewport dimensions, scroll coordinates, timing, and ad-slot IDs look metadata-like; “climate change,” the search URL, article URL, DOI, and article keywords carry the substance of what the visitor sought and read. The theory is therefore not confined to ordinary ad-delivery metadata. 18 U.S.C. § 2510(8); see also In re Google Cookie Placement. |
VPPA Video Privacy Matrix
| Category | Result | Risk | Evidence & Authority |
|---|---|---|---|
| Video tape service provider | Mixed | Medium | The banner states that optional cookies may allow “video information” to be shared, but this tested flow searched articles, opened an Open Access article, and visited a subject page; it did not request or play video. Whether the operator is a video tape service provider is therefore fact-pattern dependent and not established by this run. 18 U.S.C. § 2710(a)(4). |
| Consumer / subscriber relationship | Limited | Low | The tested visitor was not logged in, did not subscribe, did not sign up for a newsletter, and did not provide account information. A first-party UUID alone does not establish the renter/purchaser/subscriber relationship required by the statute. Salazar v. NBA illustrates that a separate newsletter exchange can support subscriber status; no comparable exchange occurred here. |
| Knowing PII disclosure tying a person to specific video material | Limited | Low | The Google requests disclosed search and article-context fields after rejection, but the run found no Facebook ID or comparable person-linked identifier, no requested or obtained video title/URL, and no video playback. This is materially short of the classic pixel allegation tying an identifiable account to a specific video. 18 U.S.C. § 2710(a)(3), (b)(1). |
| Written consent (cookie banner is not VPPA consent) | Limited | Low | No VPPA-triggering video disclosure was evidenced in this flow. If one were later shown, the general banner would be vulnerable as VPPA consent: the visitor rejected optional cookies, and the interface is not evidence of the statute’s informed, written, separate consent for disclosure of particular video-viewing information. 18 U.S.C. § 2710(b)(2)(B). |
Key Takeaway
For this Pennsylvania rejected-consent article-search flow, the live issue is WESCA rather than VPPA: Google ad-tech requests continued after rejection and carried the visitor’s search term plus article-level context. ECPA exposure is more constrained because the records depict direct browser-to-Google requests, but that defense does not erase the evidentiary significance of the transmitted contents.
Key Observations
- The report’s required initial-load signal is affirmative: the cookie banner was visible before scrolling; the initial and post-scroll visuals show a choice interface rather than acceptance.
- After “Reject optional cookies,” the reload still generated 179 requests, 130 tracker hits, and Google ad-tech activity.
- During the tested journey, Google received “climate change” through the search-page URL/context and later received the article URL, DOI, and keyword/subject metadata.
- The audit supports ad measurement and viewport/scroll telemetry, not a finding that Nature deployed full session replay or captured form keystrokes in this run.
Authorities & Litigation Signals
- Popa v. Harriet Carter Gifts, Inc. is the closest WESCA analogue: a Pennsylvania web user alleged vendor-assisted capture of website interactions; the Third Circuit rejected a broad private direct-party exception and treated consent as a fact-sensitive issue.
- In re Google Cookie Placement Consumer Privacy Litigation is the key ECPA calibration point: URL information may be contents, but direct browser-to-tracker GET requests supported the tracker’s § 2511(2)(d) party defense.
- Salazar v. NBA shows the modern VPPA pixel template: video title/URL plus Facebook ID and a separate subscriber relationship. Those critical facts were not tested or found here.
- Lee v. Springer Nature America, Inc. is a particularly relevant corporate-family litigation signal: a court approved a $900,000 VPPA settlement involving alleged Meta-Pixel transmission of Facebook IDs with specific Scientific American video titles/URLs, while requiring suspension of the pixel on identified video pages. This run does not establish that fact pattern on Nature.com.
Screenshots
Agent Steps
| Time | Step | Message |
|---|---|---|
| 18:08:28 | Configure geo proxy | |
| 18:08:52 | Capture the page before scrolling | |
| 18:09:18 | Check whether a cookie banner is visible | |
| 18:09:28 | Scroll to bottom (reveal footer privacy choices) | |
| 18:09:30 | Capture checkpoint 'pre consent' | |
| 18:09:37 | Look for privacy choices | |
| 18:09:46 | Click reject all button | |
| 18:10:05 | Check for internal preference modal | |
| 18:10:16 | Reload page | |
| 18:10:17 | Capture checkpoint 'post reject' | |
| 18:13:25 | Post-consent workflow step 1.1: Scroll page | |
| 18:13:25 | Post-consent workflow step 1.2: find elements | |
| 18:13:25 | Post-consent workflow step 2.1: Click element 2435 | |
| 18:13:25 | Post-consent workflow step 3.1: Fill field: climate change | |
| 18:13:25 | Post-consent workflow step 3.2: Click element 2690 | |
| 18:13:25 | Post-consent workflow step 4.1: Click element 7284 | |
| 18:13:25 | Post-consent workflow step 5.1: Scroll True | |
| 18:13:25 | Post-consent workflow step 5.2: Scroll True | |
| 18:13:25 | Post-consent workflow step 5.3: Click element 12768 | |
| 18:13:25 | Post-consent workflow step 6 | |
| 18:13:25 | Post-consent workflow step 7.1: done | |
| 18:13:26 | Capture checkpoint 'post article search journey' |
Tracking Audit Summary
Pre Consent