Almost every one of these letters makes the same argument in the same order: a third-party script on your website received the contents of a visitor's interaction while it was happening, the visitor never agreed to that, and California's wiretapping statute treats that as an interception. Everything else in the letter — the damages arithmetic, the deadline, the settlement figure — hangs off that one claim.
The short answer
Understanding the structure is useful for a practical reason: parts of the claim are legal questions you cannot answer, and parts are factual questions about your own website that you can settle in an afternoon. Separating them is the most productive thing you can do before you talk to a lawyer, because it turns "they say we wiretapped people" into a short list of verifiable statements about what your site loaded and when.
This page decodes the standard claims. It is not legal advice and it is not a response strategy — for the sequence of what to do after a letter arrives, see our walkthrough of what happens next, and talk to a qualified attorney about your specific letter.
The letters are near-identical because the theory is. A named individual says they visited your website. The letter identifies one or more third-party tools by name — a session recorder, a chat widget, an advertising pixel. It asserts that those tools captured what the visitor did and sent it to the vendor in real time, without consent. It then cites the statutory damages provision, multiplies it by an implied number of affected visits, and proposes a settlement below that number.
What it usually does not contain is evidence specific to you beyond a scan of your homepage — which is why the technical facts are worth establishing yourself.
Work through the letter with a highlighter. You are sorting every assertion into one of two buckets: legal questions for your attorney, and factual questions about your website that you can answer today.
What a healthy result looks like: You end with two lists: verified technical facts about your own site, and legal assertions for counsel. Do not respond to the sender yourself, and do not delete evidence in a way that looks like you are hiding what was running.
The core theory. Your visitor is communicating with your website; a script from another company — the recorder, the chat vendor, the pixel — receives that interaction at the same time. The letter argues that company is an uninvited party to the conversation. Note who is being described as the eavesdropper: not you, the vendor. The claim against you is generally framed as aiding that interception.
§ 631 speaks to reading or learning the contents of a communication "while the same is in transit or passing over any wire, line, or cable". This is why real-time streaming tools — session replay, chat, live event pixels — anchor these letters, and why "we only look at aggregate reports later" is not the answer people expect it to be.
California is an all-party-consent state, so the letter argues that consent from you is not enough — the visitor had to agree too, before the transmission. This is the claim your consent banner is supposed to address, and it is the reason a banner that displays but does not block changes nothing about the argument.
§ 637.2 creates a private right of action with statutory damages of five thousand dollars per violation, or three times actual damages, whichever is greater. Plaintiffs argue each affected visit is a separate violation. That multiplication is where the intimidating headline number comes from; whether it survives contact with a court is a different question entirely.
The operative language of Penal Code § 631(a) covers any person who, "willfully and without the consent of all parties to the communication, or in any unauthorized manner, reads, or attempts to read, or to learn the contents or meaning of any message, report, or communication while the same is in transit or passing over any wire, line, or cable, or is being sent from, or received at any place within this state" — and, separately, anyone who "aids, agrees with, employs, or conspires with any person" to do so. That second clause is the one that reaches website operators.
The statute dates from 1967 and was written about telephone lines. Applying it to a script tag is a live legal argument, not a settled fact, and courts have not been uniform about it. Some letters also invoke § 638.51, which prohibits installing or using a pen register or trap and trace device without a court order — a theory built on the idea that tracking scripts capture identifying routing data. It is newer and less settled still.
The practical point stands regardless of how those arguments resolve: the letters are generated from automated scans that look for one specific, observable pattern. A site that does not exhibit the pattern is a much less attractive target than one that does.
Terminology bridge
The umbrella term for this litigation is the website wiretapping or CIPA wave; the specific theory is the third-party eavesdropper theory, and the counter-argument you will hear from counsel is the party exception — the idea that a vendor acting purely as your tool is not a separate party at all. The newer theory built on § 638.51 is the pen register or trap and trace theory. What the plaintiff-side scanners are measuring, in our vocabulary, is a consent gap: a third-party transmission that happens before the visitor answers.
Be clear about what a scan is and is not. It establishes which third-party servers your site contacted, and when, relative to the consent interaction. It cannot tell you whether the party exception applies, whether the plaintiff has standing, whether the visit happened as alleged, or what any of it is worth. Those are legal judgments, and nothing on this page is legal advice — it is a description of a common document so you can read yours with less fog.
RegSentry loads your site in a real browser, records when each third-party tracker first contacts its server, and flags everything that fires before consent — with the fix for each one. Continuous monitoring re-runs it and emails you when something new appears.
Free real-browser scan
See every pre-consent tracker on your site — free, 30 seconds, no signup.
Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.