Calucon Third-Party Embed Gate — Showcase

Every provider Calucon Third-Party Embed Gate recognises — 36 of them, all demonstrated below, 30 of them wired to live content. Nothing on this page contacts a third party until you press a button.

Diese Seite auf Deutsch

Check it yourself: developer tools → Network → tick “Disable cache” → reload, and sort by Domain. Nothing below has loaded; press one button and exactly one provider appears.

One honest caveat: the site sits behind Cloudflare, which injects its own analytics beacon (static.cloudflareinsights.com) into every page at the edge — after WordPress has finished, out of reach of any plugin, and not an embed. It is cookieless and it is disclosed in the privacy policy. Everything else in that list is calucon.de.


The providers

Open a group to see its embeds. Whose content is it? The provider’s own example where one exists, my own work where I have it, and museum or design-institution material otherwise — nobody’s personal post is here by accident.

One rule decided most of this page: nothing is embedded unless it is plainly the uploader’s to publish. That rules out more than it sounds like. The Dailymotion sample this page started with — inherited from the plugin’s own test fixtures — was a 45-minute television series re-uploaded by a stranger. Two providers below are empty for the same reason: Scribd and Imgur expose no uploader, so there is nothing to check.

Six are marked stand-in: the panel is real, the target is not, and there are three separate reasons. Google Forms and Calendly have no vendor demo, and a real one would send your answers into a stranger’s form or book time in their calendar. Instagram and Facebook point at Meta’s own documented example posts, both since deleted — kept, because a provider failing after consent is worth seeing. Scribd and Imgur are empty on the copyright rule above.

Video

6 providers

YouTube

Pasted as youtube.com; loads back as youtube-nocookie.com. Measured: 6 cookies on the first, 0 on the second.

Loading this video contacts YouTube (Google), which receives your IP address and which page you are on, and sets cookies.

Open on YouTube

YouTube privacy policy

Vimeo

Loads back with dnt=1, which suppresses Vimeo’s analytics.

Loading this video contacts Vimeo, which receives your IP address and which page you are on, and may set cookies.

Open on Vimeo

Vimeo privacy policy

Dailymotion

VernissageTV’s tour of Making Africa at the Vitra Design Museum.

Loading this video contacts Dailymotion, which receives your IP address and which page you are on, and sets cookies.

Open on Dailymotion

Dailymotion privacy policy

TED

Loading this video contacts TED, which receives your IP address and which page you are on, and may set cookies.

Open on TED

TED privacy policy

VideoPress

An iframe and a companion script. One button releases both — the script waits in a hidden marker rather than growing a second panel.

Loading this video contacts VideoPress (Automattic), which receives your IP address and which page you are on, and may set cookies.

Open on VideoPress

VideoPress privacy policy

TikTok

TikTok’s own documentation example. The blockquote and embed.js form TikTok also publishes rendered nothing here, with or without a gate in the way.

Loading this video contacts TikTok, which receives your IP address and which page you are on, and sets cookies.

Open on TikTok

TikTok privacy policy

Audio and podcasts

5 providers

Spotify

Loading this player contacts Spotify, which receives your IP address and which page you are on, and sets cookies.

Open on Spotify

Spotify privacy policy

SoundCloud

Loading this player contacts SoundCloud, which receives your IP address and which page you are on, and may set cookies.

Open on SoundCloud

SoundCloud privacy policy

Apple Music

Carries a sandbox attribute — preserved exactly when the embed is rebuilt, never widened.

Loading this player contacts Apple, which receives your IP address and which page you are on.

Open on Apple Music

Apple Music privacy policy

Mixcloud

Loading this player contacts Mixcloud, which receives your IP address and which page you are on, and may set cookies.

Open on Mixcloud

Mixcloud privacy policy

Pocket Casts

Loading this player contacts Pocket Casts (Automattic), which receives your IP address and which page you are on, and may set cookies.

Open on Pocket Casts

Pocket Casts privacy policy

Social posts

8 providers, 6 live

Strava

Script-based, not an iframe: the loader is what gets held back. On a page with several activities one press loads them all, because Strava’s single script renders every placeholder at once.

Loading this activity contacts Strava, which receives your IP address and which page you are on, and sets cookies.

Open on Strava

Strava privacy policy

X (Twitter)

Loading this post contacts X (Twitter), which receives your IP address and which page you are on, and sets cookies.

Open on X (Twitter)

X (Twitter) privacy policy

Bluesky

The quoted text is the provider’s own fallback, and it is still here with the script held back. Not every embed degrades this gracefully.

Bluesky is an open social network that gives creators independence from platforms, developers the freedom to build, and users a choice in their experience.

— Bluesky (@bsky.app)

Loading this post contacts Bluesky, which receives your IP address and which page you are on, and may set cookies.

Open on Bluesky

Bluesky privacy policy

Tumblr

View this post on Tumblr

Loading this post contacts Tumblr (Automattic), which receives your IP address and which page you are on, and may set cookies.

Open on Tumblr

Tumblr privacy policy

Pinterest

Loading this pin contacts Pinterest, which receives your IP address and which page you are on, and may set cookies.

Open on Pinterest

Pinterest privacy policy

Instagram stand-in target

The post in Meta’s own oEmbed documentation, which has since been deleted — so Instagram answers with “Page isn’t available”. Left as it is: the gate’s job ends at the request, and what a provider does with it afterwards is worth seeing too.

Loading this post contacts Instagram (Meta), which receives your IP address and which page you are on, and sets cookies.

Open on Instagram

Instagram privacy policy

Facebook stand-in target

The post in Meta’s own embedded-posts documentation, by Facebook’s own page. It now answers 400. Meta’s two published examples are the only ones on this page that no longer exist.

Loading this content contacts Facebook (Meta), which receives your IP address and which page you are on, and sets cookies.

Open on Facebook

Facebook privacy policy

Reddit

An announcement from r/reddit, Reddit’s own account.

Loading this post contacts Reddit, which receives your IP address and which page you are on, and sets cookies.

Open on Reddit

Reddit privacy policy

Documents and presentations

5 providers, 4 live

Scribd stand-in target

Scribd publishes uploads and names no uploader on the embed, so there is no way to tell from here whether a given document was its poster’s to post. Not worth guessing on someone else’s copyright.

Loading this content connects your browser to www.scribd.com, which receives your IP address and which page you are on, and may set cookies.

Open on www.scribd.com

Speaker Deck

Loading this presentation contacts Speaker Deck, which receives your IP address and which page you are on, and sets cookies.

Open on Speaker Deck

Speaker Deck privacy policy

Issuu

Loading this publication contacts Issuu, which receives your IP address and which page you are on, and may set cookies.

Open on Issuu

Issuu privacy policy

Wolfram Cloud

Loading this notebook contacts Wolfram, which receives your IP address and which page you are on, and sets cookies.

Open on Wolfram Cloud

Wolfram Cloud privacy policy

Amazon Kindle

Loading this preview contacts Amazon, which receives your IP address and which page you are on, and sets cookies.

Open on Amazon Kindle

Amazon Kindle privacy policy

Maps and 3D

4 providers

Google Maps

Loading this map contacts Google Maps, which receives your IP address and which page you are on, and sets cookies.

Open on Google Maps

Google Maps privacy policy

OpenStreetMap

The privacy-friendlier alternative — still a third party, still gated.

Loading this map contacts OpenStreetMap, which receives your IP address and which page you are on.

Open on OpenStreetMap

OpenStreetMap privacy policy

Matterport

Loading this tour contacts Matterport, which receives your IP address and which page you are on.

Open on Matterport

Matterport privacy policy

Sketchfab

The British Museum’s scan of the Rosetta Stone.

Loading this model contacts Sketchfab, which receives your IP address and which page you are on.

Open on Sketchfab

Sketchfab privacy policy

Forms, polls and scheduling

5 providers, 3 live

Crowdsignal

The same poll the plugin’s fixtures use, via poll.fm rather than the loader script. That script calls document.write, which only does anything while a document is still parsing — which is exactly what this URL gives it.

Loading this poll contacts Crowdsignal (Automattic), which receives your IP address and which page you are on, and may set cookies.

Open on Crowdsignal

Crowdsignal privacy policy

Google Calendar

Loading this calendar contacts Google, which receives your IP address and which page you are on, and sets cookies.

Open on Google Calendar

Google Calendar privacy policy

Google Forms stand-in target

Loading this form contacts Google, which receives your IP address and which page you are on, and sets cookies.

Open on Google Forms

Google Forms privacy policy

Typeform

One of Typeform’s own forms. Load it and it shows you a cookie banner of its own — a fair reminder that the gate stops the request, and what happens after you allow it is the provider’s business.

Loading this form contacts Typeform, which receives your IP address and which page you are on, and sets cookies.

Open on Typeform

Typeform privacy policy

Calendly stand-in target

Loading this scheduler contacts Calendly, which receives your IP address and which page you are on, and sets cookies.

Open on Calendly

Calendly privacy policy

Images and everything else

3 providers, 2 live

Imgur stand-in target

Same reasoning as Scribd. Imgur albums carry no attribution in the embed, so provenance cannot be established without leaving the page.

View post on imgur.com

Loading this post contacts Imgur, which receives your IP address and which page you are on, and may set cookies.

Open on Imgur

Imgur privacy policy

GIPHY

Oskar Schlemmer’s Bauhaus logo, animated.

Loading this image contacts GIPHY, which receives your IP address and which page you are on.

Open on GIPHY

GIPHY privacy policy

Kickstarter

The only descriptor that ships no kind, deliberately — it gets the generic panel. Recognised by name all the same.

Loading this project contacts Kickstarter, which receives your IP address and which page you are on, and may set cookies.

Open on Kickstarter

Kickstarter privacy policy


Behaviour worth seeing

An unknown third party is gated too

The gate asks “is this host ours?”, not “do I recognise it?” — so something pasted in next year is covered without anyone editing a list.

Loading this content connects your browser to example.com, which receives your IP address and which page you are on, and may set cookies.

Open on example.com

Our own content is not gated

Same-origin iframes pass through byte-identical. This one loads immediately, with no button.

Where a provider ships both forms, the iframe is the safer paste

Many providers publish two snippets for the same content: an <iframe>, or a <blockquote> and a loader script. The gate releases either. In testing here, the script form of TikTok and Crowdsignal rendered nothing — but so did the same snippet on a page with no gate at all, which rules the gate out as the cause. Their iframe forms work, and that is what is demonstrated above; the gate recognises them by host either way. Where a provider offers both, the iframe has fewer moving parts and fails visibly rather than silently.

It works without JavaScript

Every panel carries a server-rendered link to the provider’s own site. Turn JavaScript off and the buttons stop working, but those links still go somewhere real.

Withdrawing consent

Consent memory is off here, so nothing is stored and every placeholder is active again next visit. This control is for sites that turn memory on.


Coverage

The named providers above get a recognisable label, an icon, a privacy-policy link and, where one exists, a privacy-preserving load target. The protection does not come from that list: any host that is not yours is held back, named or not. A provider nobody has heard of yet is covered without anyone editing anything.

Two providers load back somewhere different from where they were pasted: YouTube via www.youtube-nocookie.com, and Vimeo with dnt=1 merged into the query.

Detection detail

hosts, kind and method for all 36
ProviderDetected onKindMethod
YouTubeyoutube.com, www.youtube.com, m.youtube.com, youtube-nocookie.com, www.youtube-nocookie.com, youtu.bevideoiframe
Vimeoplayer.vimeo.comvideoiframe
Dailymotiongeo.dailymotion.com, www.dailymotion.com, dailymotion.comvideoiframe
TEDembed.ted.com, embed-ssl.ted.comvideoiframe
VideoPressvideo.wordpress.com, videopress.com, v0.wordpress.comvideoiframe + script
TikTokwww.tiktok.comvideoiframe + script
Spotifyopen.spotify.comaudioiframe
SoundCloudw.soundcloud.comaudioiframe
Apple Musicembed.music.apple.com, embed.podcasts.apple.comaudioiframe
Mixcloudwww.mixcloud.com, player-widget.mixcloud.comaudioiframe
Pocket Castspca.staudioiframe
Stravastrava-embeds.com, www.strava-embeds.comsocialscript
X (Twitter)platform.twitter.com, platform.x.comsocialiframe + script
Blueskyembed.bsky.appsocialiframe + script
Tumblrembed.tumblr.com, assets.tumblr.comsocialiframe + script
Pinterestassets.pinterest.comsocialiframe + script
Instagramwww.instagram.com, instagram.com, platform.instagram.comsocialiframe + script
Facebookwww.facebook.com, web.facebook.com, connect.facebook.netsocialiframe + script
Redditembed.reddit.com, www.redditmedia.com, embed.redditmedia.comsocialiframe + script
Scribdwww.scribd.com, scribd.comdocumentiframe + script
Speaker Deckspeakerdeck.comdocumentiframe + script
Issuue.issuu.comdocumentiframe
Wolfram Cloudwww.wolframcloud.com, wolframcloud.comdocumentiframe + script
Amazon Kindleread.amazon.com, read.amazon.co.uk, read.amazon.com.au, read.amazon.in, read.amazon.cndocumentiframe
Google Mapswww.google.com, google.com, maps.google.commapiframe
OpenStreetMapwww.openstreetmap.org, openstreetmap.orgmapiframe
Matterportmy.matterport.com3diframe
Sketchfabsketchfab.com3diframe
Crowdsignalpoll.fm, secure.polldaddy.com, app.crowdsignal.comformiframe + script
Google Calendarcalendar.google.comcalendariframe
Google Formsdocs.google.comformiframe
Typeformform.typeform.com, embed.typeform.comformiframe + script
Calendlycalendly.com, assets.calendly.comcalendariframe + script
Imgurimgur.com, s.imgur.comimageiframe + script
GIPHYgiphy.comimageiframe + script
Kickstarterwww.kickstarter.com, kickstarter.comgenericiframe

Not a compliance claim: the plugin stops the requests, but it cannot know a site’s processing purposes. A privacy policy still has to name its providers.