TMOD LogoTMOD

Ad policy & compliance checker

11 policy checks, prohibited content, GDPR/CCPA, cookie consent, DMCA, disclosures and ad placement.

What TMOD checks

  • AdSense program policy violations and prohibited content categories, read by an AI reviewer in any language rather than matched against an English keyword list.
  • Privacy policy presence and content, tested for GDPR and CCPA vocabulary rather than just a page existing at /privacy.
  • Cookie consent implementation, detected heuristically from known consent platforms first and confirmed by the AI reviewer when the heuristic is inconclusive.
  • Terms of service and DMCA pages, located by an AI classifier that recognises them in any language.
  • Age-restricted content screening, affiliate and sponsored disclosure, intrusive pop-ups and interstitials, and ad density and placement balance.
  • Copyright and intellectual-property risk across the crawled pages.
A bar chart comparing the five audits by how many of the 45 checks each runs. This audit runs 11: 11 policy.

Every check, explained

11 checks run in this audit. 2 of them have a page of their own with the exact threshold and how to fix it.

Why it matters

Policy failures are the fastest route to rejection and the least negotiable. Content quality is a judgement call with a broad middle ground; a prohibited-content category or a missing privacy policy is a straightforward no, and no amount of good writing compensates.

Several of these are also legal requirements independent of AdSense. A site serving EU visitors needs a working consent mechanism and a GDPR-compliant privacy policy whether or not it runs ads, and the exposure there is considerably larger than a rejected application.

The checks that matter most are the ones people assume they have passed. Almost every site has a page at /privacy, far fewer have one that actually names what data is collected, who processes it, and how a visitor exercises their rights. We check for the substance, not the URL.

How to fix it

01Write a privacy policy that describes your actual site

A generic template that mentions services you do not use and omits the ones you do is a compliance problem, not a solution. Name the analytics, the ad networks, the embeds and the hosting. Say what is retained and for how long. If AdSense is the goal, it must disclose third-party ad cookies.

02Implement consent before the tags fire

A consent banner that appears while tracking scripts have already loaded does not comply with anything. Consent must gate the scripts. Most consent platforms support this properly; the common failure is installing the banner and never wiring it to the tag manager.

03Disclose affiliate and sponsored content clearly

The disclosure needs to be visible before the link, not buried in a footer or a separate page. This is both an AdSense expectation and, in most jurisdictions, a legal requirement with a regulator attached.

04Remove interstitials that block the first view

A full-screen overlay before a visitor can read anything is flagged as an intrusive interstitial. Consent notices and age gates where legally required are the exception; newsletter modals and app-install prompts on arrival are not.

The policies people trip over without meaning to

Almost nobody applying to AdSense is running prohibited content deliberately. The failures come from ordinary sites brushing against a category they did not think about. A gaming site covering weapons in detail. A health site making treatment claims. A deals site whose affiliate relationships are never stated. A news aggregator republishing other outlets' articles in full, which is a copyright problem before it is a content problem.

Images are the quietest one. Pictures pulled from search results, stock photography used outside its licence, and screenshots of other people's work republished without context all create intellectual-property exposure that nothing on the page announces. It is invisible to you and entirely visible to whoever owns the image.

The other blind spot is where traffic comes from. Bought traffic, incentivised clicks and exchange schemes are against the program rules regardless of how good the site is, and they are checked after approval rather than before, which makes them the expensive kind of mistake. If any part of your growth plan involves paying for visits that are not real interest, resolve that before the application rather than after.

The policies publishers trip over without meaning to. Most breaches are unintentional and structural, not deliberate. Usually fine: Reporting on a difficult subject; Affiliate links that are disclosed; Reader comments, moderated; Quoting a source with attribution. Usually a problem: Ads placed to be mistaken for content; Affiliate links with no disclosure anywhere; Republished articles with no licence; Adult or medical claims without qualification.

Compliance is a mechanism, not a document

The common shape of a failure here is a site that has all the right pages and none of the behaviour they describe. A privacy policy listing services the site does not use, alongside an ad network it does not mention. A consent banner that appears after the tracking scripts have already run. An affiliate disclosure on a dedicated page nobody reaches, rather than beside the links it applies to.

This matters because both AdSense and every privacy regulator assess the mechanism. A policy is evidence of what you claim to do; consent gating, disclosure placement and retention practice are what you actually do, and where they disagree the document works against you rather than for you.

The practical version is short. Every service that touches visitor data is named in the policy. Non-essential tags do not fire until consent is given. Disclosures sit next to what they disclose. The pages are linked from the footer of every page and revisited whenever you add a tool. That covers the ground this audit measures, and most of the ground a regulator would.

Four findings on one affiliate site

A deals blog, sixty pages, preparing to apply for AdSense, is the site where this audit earns its keep, so here is what it typically finds there. Finding one: affiliate links throughout the content, with the only disclosure living on a dedicated /disclosure page that no reader passes on the way to a link. Disclosure has to be visible before the click it applies to, so the fix is a one-line notice at the top of every money page, plus keeping the dedicated page for the long version. An afternoon, mostly in the template.

Finding two: product descriptions copied verbatim from merchant data feeds. That reads as aggregated content with no editorial work, and it is also an intellectual-property question, since the text belongs to the merchants. The fix is the expensive one on this list: the descriptions get replaced with what the site actually knows, which deals were genuinely good, what arrived when one was ordered, which merchant honoured a price error. That is also the work that separates the site from every other feed republisher, so it pays twice.

Findings three and four are mechanical. The consent banner is present and the tags fire before it, the near-universal gating failure, fixed by routing the tags through the consent platform rather than pasting them into the head. And a newsletter modal covers the first pageview, which reads as an intrusive interstitial; moved to trigger on scroll depth or exit intent, it collects almost as many addresses and stops standing between the visitor and the first paragraph.

Notice what the list does not contain: a single judgement about writing quality. All four findings are mechanisms, which is the general character of policy failures, they are binary, they are checkable, and they are fixable in days rather than months. Once they are cleared, the policy substance and the content itself are what remain, and the full audit is the right tool for that second question, since it weighs this category alongside everything else the review considers.

Questions

I have a privacy policy but it is still flagged. Why?

The check reads the page, not just its existence. It looks for the vocabulary of an actual policy, what data is collected, the legal basis, third-party processors, retention periods, and how a visitor exercises their rights under GDPR or CCPA. A three-sentence page saying 'we respect your privacy' will be flagged, correctly.

Does this replace legal advice?

No, and it is not close. It checks for the presence and apparent substance of the documents and mechanisms that AdSense and the major privacy regimes expect. Whether your specific policy is adequate for your specific processing in your specific jurisdiction is a question for a lawyer. Treat a pass here as clearing a floor, not as compliance.

Why is my ad placement flagged when I do not run ads yet?

The ad placement and density checks look at the layout patterns that cause problems once ads are added, insufficient content between placements, layouts where an ad would land above the fold with nothing else, and elements that could be mistaken for content. On a site with no ads it is advisory, telling you where placements would be a problem later.

Does prohibited-content detection work in languages other than English?

Yes. The policy engines use an AI reviewer that reads content in any language rather than matching English keyword lists, which is why this preset includes the language-model pass. A keyword-based check on a non-English site produces almost no signal, which is worse than an honest 'we could not assess this'.

Which policy findings are hard blockers, and which are judgement calls?

Prohibited content, a failing age-restriction screen and missing privacy compliance are treated as disqualifiers: in the full AdSense audit they cap the score outright, because that is how the real review treats them, no amount of quality elsewhere trades against them. Disclosure gaps, interstitials, ad density and copyright risk signals are weighed instead, they lower the score and appear in the fix list, but a site can carry one of them and still be approved. The report orders findings that way on purpose: clear the top of the list before polishing the bottom.

Read more