Big players, but real vulnerable spots.
hCaptcha and Google reCAPTCHA are established bot-protection tools, but both can involve privacy, accessibility, and compliance trade-offs.
A new way to do bot protection
Friendly CAPTCHA uses a combination of invisible proof-of-work and risk signals, so it never displays image or audio challenges. This makes it a genuinely invisible CAPTCHA.
Technologies that should be improved
hCaptcha is best known for image challenges, while reCAPTCHA v3 is usually invisible, but may fall back to manual challenges and relies on cookies.
Friendly Captcha rivals both hCaptcha and reCAPTCHA
For organizations prioritizing a frictionless, accessible, and privacy-focused experience, Friendly Captcha is the strongest fit. Try out now ›
CAPTCHAs help protect websites from automated spam, abuse, and malicious bots, making online services more secure. They are commonly used on contact forms, login pages, and registration forms.
Traditional CAPTCHA tests ask visitors to complete a manual task, such as selecting images containing a specific object or entering letters displayed in a distorted image. Newer CAPTCHA alternatives can operate invisibly in the background, reducing friction for legitimate users.
Choosing the right CAPTCHA technology is an important consideration for security-conscious organizations. An effective CAPTCHA solution should be accessible to all users, provide a seamless experience by minimizing or eliminating visible challenges, and protect personally identifiable information (PII). It should also support compliance with relevant privacy and security requirements, such as the GDPR, CCPA, and HIPAA, where applicable.
Two of the best-known CAPTCHA providers are hCaptcha and Google reCAPTCHA. This article provides a detailed hCaptcha vs reCAPTCHA comparison, examining the way they work, as well as accessibility, privacy, and security considerations. It also introduces Friendly Captcha as a privacy-focused alternative designed to overcome common limitations of traditional CAPTCHA technologies while delivering an accessible, frictionless user experience.
What Is Google reCAPTCHA?
Google reCAPTCHA is a widely used CAPTCHA solution. It’s a service provided by Google in a free tier for lower-volume websites and applications, as well as through reCAPTCHA Enterprise, a paid, usage-based offering for larger organizations.
reCAPTCHA uses different methods to distinguish legitimate visitors from automated traffic: reCAPTCHA v2 may ask users to tick a checkbox or complete an image challenge, while reCAPTCHA v3 assesses common, ordinary activity invisibly in the background and returns a risk score.
Visit our reCAPTCHA hub to see all content related to reCAPTCHA.
How does Google’s reCAPTCHA work?
Google reCAPTCHA works by tracking and collecting as much information about user behavior as possible. Google reCAPTCHA may take a full snapshot of your browser window, your browser plug-ins, your mouse movements, your keystrokes, the websites you previously visited, your IP address, your cookies, and more [1].
By combining all this information, reCAPTCHA can make an educated guess about malicious bot activity or human behavior. In cases where reCAPTCHA can’t collect enough information to tell if a user is a bot, it requires the user to manually solve a puzzle. reCAPTCHA does not disclose in its privacy policy what exactly it does with the data it collects [2].
reCAPTCHA shares cookies with other Google services belonging to the google.com domain. Embedding reCAPTCHA into your website requires you to load the JavaScript code from the google.com domain.
Effective 2 April 2026, Google changed its role in reCAPTCHA data processing. Website operators are now the sole data controllers for reCAPTCHA Customer Data, while Google acts as a data processor under the Google Cloud terms and Data Processing Addendum. Read our post about this reCAPTCHA news.
Is Google reCAPTCHA GDPR compliant?
Google reCAPTCHA’s General Data Protection Regulation (GDPR) compliance is a subject of constant critical evaluation by privacy experts. By embedding reCAPTCHA into your website, you will inevitably be transferring personal data about your European users to servers in the United States. You must inform your users about how this data is processed and obtain any necessary user consent, otherwise you are in the breach of GDPR.
Failure to comply with GDPR rules when using Google’s reCAPTCHA has resulted in lawsuits and fines. For example, in the case of NS Cards, the French data protection commission CNIL fined the website owner more than €100,000 for failing to obtain consent for the use of reCAPTCHA.
For companies based in European countries, as well as international companies targeting EU users, extensive safety measures are essential to ensure that reCAPTCHA complies with GDPR regulations and meet the requirements of data protection authorities.
Benefits of reCAPTCHA
-
Free version for non-entreprise customers: Google Cloud reCAPTCHA includes up to 10,000 assessments per month at no cost. Billing must be enabled for higher volumes.
-
Low-friction for v3 option: in most cases, reCAPTCHA v3 runs in the background and assigns each visitor a risk score without requiring direct user interaction, such as image recognition task. Website operators can use that score to determine the appropriate response.
-
Widely used bot protection: reCAPTCHA is an established and widely used solution for protecting websites against common spam and automated abuse. However, compared to more advanced reCAPTCHA alternatives, it only provides basic protection against simple bots.
Weaknesses of Google reCAPTCHA
- Not accessible to all users: reCAPTCHA v2 requires users to solve visual puzzles to prove they are human. These challenges can be difficult to complete and may exclude people with visual impairments, including blind users or the elderly. reCAPTCHA v3 is mostly invisible and relies more heavily on data collection. However, in fallback cases, users may still need to complete manual challenges, creating accessibility issues. Full WCAG compliance can therefore be difficult to achieve with reCAPTCHA.
- Processing large amounts of user data: Google’s advertising business relies on user data, cookies, and local storage to track user activity. Google reCAPTCHA depends on collecting extensive information to assess whether a visitor is human, which raises privacy concerns. Achieving GDPR compliance with Google reCAPTCHA can therefore be challenging.
- Lack of transparency in data processing and storage: Google does not clearly disclose exactly what data reCAPTCHA collects, why it collects it, or how it is processed. reCAPTCHA customers must demonstrate lawful use as required by the GDPR. This lack of transparency can make it difficult to provide the required information about data collection, cookies, data use, and third parties involved.
- Sharing cookies within the Google ecosystem: The code website owners embed to use reCAPTCHA is served from the google.com domain. This means that cookies associated with that domain may be available to other Google services, such as Google Analytics. As a result, website owners using reCAPTCHA may contribute to Google’s broader tracking ecosystem.
-
Subject to U.S. privacy regulations: As a U.S. company, Google is subject to U.S. surveillance and privacy laws. Websites targeting European users must comply with GDPR requirements and may require additional safeguards when transferring personal data to U.S. companies. Using Google reCAPTCHA can therefore involve a potentially critical international data transfer.
-
False positives for privacy-conscious users: Users who use tracking blockers, VPNs, or are not logged in to Google may have to solve reCAPTCHA challenges more often. Without information from Google cookies and other risk signals, reCAPTCHA may have more difficulty distinguishing humans from bots. This can result in false positives and lock out legitimate users. Visitors with visual impairments who rely on accessibility tools, such as screen readers, may be similarly affected.
hCaptcha: The Image Classification Task-Based CAPTCHA Solution
hCaptcha is a US-based alternative to reCAPTCHA that targets both small website owners and corporate customers. hCaptcha requires website visitors to label images as part of its business model: hCaptcha’s parent company, Intuition Machines Inc., focuses on machine learning for image recognition and offers image labeling services. The labeled data from the hCaptcha widget is sold to data companies [3].
hCaptcha offers a similar experience to Google’s reCAPTCHA v2. Unlike reCAPTCHA v3, due to its business model, the provider is more focused on manual image recognition challenges. It is a image classification task based CAPTCHA provider employing visual challenges like identifying objects.
Because of these manual CAPTCHA challenges, hCaptcha needs less data than Google to operate its service. In return, it misses out on a good user experience.
Nevertheless, hCaptcha uses cookies to provide its service and paid enterprise features such as its passive CAPTCHA. One of these cookies stores a unique identifier for each user, potentially allowing hCaptcha to track users across websites that use hCaptcha.
How does hCaptcha work?
For regular users, hCaptcha requires each website user to manually solve visual challenges based on a set of images. Even for users without disabilities, hCaptcha challenges can be challenging, especially since the visual labeling challenges of hCaptcha tend to be more complex than those of reCAPTCHA.
Enterprise customers have the option of using an invisible version of the CAPTCHA, called a passive CAPTCHA. This version still requires the user to manually solve an hCaptcha challenge with images if not enough personal data could be collected to guess whether the visitor is a human or a bot.
Read our general introduction to hCaptcha to dive deeper.
Is hCaptcha GDPR compliant?
hCaptcha sets cookies in users’ web browsers. These cookies store a unique identifier for each user. The cookies allow hCaptcha to potentially track users across all websites that use hCaptcha. In addition, hCaptcha collects personal information in various ways.
Like Google, hCaptcha is a US company and not an EU CAPTCHA provider. This means that it’s impossible to guarantee that your European users’ data will never leave the EU. By embedding hCaptcha into your website, you are inevitably sending personal data about your EU web visitors to a US provider.
Unlike reCAPTCHA, hCaptcha discloses in its user privacy policy what data is collected, processed, and shared with third parties, including additional US sub-processors.
To comply with GDPR, website owners must obtain prior consent from each user, particularly for the use of cookies and the cross-border transfer of data to third parties. Without this prior consent, the use of hCaptcha may not be possible from a data protection perspective, making the practical integration of hCaptcha complex.
We explore hCaptcha GDPR compliance in our hCaptcha GDPR article.
Benefits of hCaptcha
-
Free for small website owners: hCaptcha offers a free version for small websites with limited protection, using always-on image recognition tasks to support its image labeling business. For medium to large enterprise customers, additional features like the passive CAPTCHA option, Pro and Enterprise plans are available.
-
Advanced image recognition tasks: hCaptcha’s core expertise is in image labeling tasks, and it ultimately uses these tasks for bot protection, especially as a fallback. As such, its CAPTCHA challenges become more advanced and difficult to solve to keep up with the development of AI image recognition and the rise of sophisticated bots. For example, with hCaptcha you now need to label laughing dogs instead of traffic lights as with reCAPTCHA.
-
Provides information about used data and minimizes data collection: hCaptcha provides more detailed information about the personal information used for its services, including details about the use of personally identifiable information, cookies, and U.S. sub-processors. hCaptcha tries to minimize the amount of data it collects. They allow end users to opt out of having their data used for machine learning purposes.
Weaknesses of hCaptcha
-
Data collection through cookies: Especially for its passive CAPTCHA feature, hCaptcha uses cookies and various third party services. Therefore, in order to offer the use of hCaptcha and third parties in compliance with GDPR, the user’s prior consent should be obtained.
-
Involvement of US providers and third parties for EU user data: As a US company, hCaptcha transfers personal data to its parent company Intuition Machines and to the servers of its third party US sub-processors. The GDPR applies to all website operators targeting EU users. It’s impossible for EU companies and international companies operating websites in the EU to prove that no user data leaves the EU. Therefore, international data transfers of personally identifiable information and sharing with sub-processors must be critically evaluated with appropriate security measures in mind.
-
Users with insufficient data must solve a hCaptcha challenge: hCaptcha requires hard-to-solve manual image marking tasks from legitimate website users from whom it can’t collect enough risk data. This includes site visitors who use ad blockers, screen readers, have strict privacy requirements, or connect to your site via VPN or other secure networks. For these people, hCaptcha provides an even more difficult manual CAPTCHA challenge that can take the website visitor minutes to complete.
-
Not accessible for all users: hCaptcha’s image recognition challenges can be difficult to solve even for people who are experienced in dealing with the world online. The hCaptcha challenge may be impossible for the elderly and people with disabilities or health problems. As a result, these users are denied barrier-free access and are therefore excluded from important interfaces. hCAPTCHA’s fallback options to deal with website owners’ need for WCAG compliance seem to be more of a workaround than a practical solution. Read our article about hCaptcha accessibility.
Friendly Captcha: A User Privacy-Focused, Invisible CAPTCHA Solution
Friendly Captcha is a privacy-first CAPTCHA alternative to reCAPTCHA and hCaptcha based in the EU, with a focus on security and accessibility. Friendly Captcha is a proof-of-work-based CAPTCHA solution designed to run entirely in the background. It is truly invisible, while effectively protecting websites and online forms from malicious bots and attacks.
Instead of requiring website visitors to manually solve an image recognition challenge, Friendly Captcha generates an invisible, cryptographic puzzle that is solved by the user’s device in the background. Based on technical signals, the difficulty of the invisible puzzle can be scaled to make it even harder for suspected bots and risky actors to get through.
How does Friendly Captcha work?
Friendly Captcha uses a combination of cryptographic proof-of-work and risk signals to protect website interactions from automated spam, malicious bots, and other forms of automated abuse.
When a user visits a protected page, Friendly Captcha creates a unique, invisible cryptographic puzzle that is solved by the user’s device in the background, without requiring manual interaction. The process typically takes only a few seconds and can run while the user completes an action, such as filling out a registration or login form. In many cases, the work is completed before the user submits the form.
The difficulty of the puzzle, and therefore the time and computing resources needed to solve it, is automatically scaled based on risk signals. This helps protect against advanced bots without presenting users with visual, audio, or other manual CAPTCHA challenges. Read our article about CAPTCHA security to learn more.
By eliminating manual challenges, Friendly Captcha minimizes friction and avoids common accessibility barriers associated with traditional CAPTCHAs. At the same time, it helps protect websites from unwanted spam submissions, bot traffic, and automated attacks.
Is Friendly Captcha GDPR compliant?
Friendly Captcha is fully GDPR compliant. It is transparent about the information it processes and minimizes data collection.
Friendly Captcha does not use any HTTP cookies nor persistent browser storage (such as LocalStorage or IndexedDB) to track users, and does not store personal data. Therefore, website owners do not need to obtain prior user consent. By informing your users in your privacy policy, you can easily use Friendly Captcha in a GDPR compliant way.
Friendly Captcha is an EU CAPTCHA provider, built in Germany and adheres to the highest European data protection standards. It does not use third parties outside the EU to process EU users’ data. This means that your EU users’ data is never transferred outside the European Union, while your website and forms are protected from bots and spam.
For EU website owners and international enterprises targeting EU users, Friendly Captcha offers a dedicated EU endpoint to ensure that the personal data of your European website visitors never leaves the EU. This helps you comply with GDPR requirements.
Benefits of Friendly Captcha
-
User-friendliness by design: Friendly Captcha technology never requires users to manually solve any visual challenges, audio challenges, or image recognition challenges. As seen with reCAPTCHA and hCaptcha, these challenges detract from the user experience. Friendly Captcha uses a fundamentally new CAPTCHA technology that provides the most user-friendly way to protect against bots. As a truly invisible CAPTCHA, it will never show a human a visual CAPTCHA challenge for bot protection.
-
Accessibility for everyone: Each Friendly Captcha challenge is invisible and solved by the user’s web browser in the background. No one ever has to solve an image classification task or recognize distorted letter combinations to gain authorized access to critical web interfaces. Friendly Captcha is fully compliant with the WCAG guidelines.
-
No cookies, no tracking: Friendly Captcha does not use any HTTP cookies nor persistent browser storage. Its invisible CAPTCHA technology protects against bots without storing any personal data. No personally identifiable information is stored via cookies or persistent storage.
-
Uncompromised GDPR compliance for EU users: European data protection compliance is straightforward with Friendly Captcha. Friendly Captcha is a German company, and with its dedicated EU endpoint, no personal data of EU users leaves the EU. With European hosting providers, European end user data stays within the EU.
-
Globally compliant with privacy laws: Friendly Captcha is trusted by international enterprises and governments around the world. It complies with global privacy standards such as GDPR, CCPA and HIPAA. It collects only necessary data to protect with the highest security standards and is solely focused on its security purpose. It doesn’t use any HTTP cookies nor persistent browser storage such as LocalStorage or IndexedDB. Friendly Captcha’s modern technology is compliant with relevant international data protection and privacy laws.
Weaknesses of Friendly Captcha
-
Free only for small websites: Compared to reCAPTCHA and hCaptcha, Friendly Captcha only protects smaller websites and applications with a free plan. Since Friendly Captcha is solely focused on bot protection, it is a paid service. Depending on the features needed, it offers several self-service plans, ranging from a Starter Plan to a Growth Plan to an Advanced Plan. Enterprise customers get a customized plan with high-end security, scalability and personal support.
hCaptcha vs. reCAPTCHA vs. Friendly Captcha: Which CAPTCHA Is the Best Choice?
Google reCAPTCHA is widely used and offers a free option for smaller websites. reCAPTCHA v3 works largely in the background, while reCAPTCHA v2 may require users to complete a manual challenge. Google states that reCAPTCHA sets the _GRECAPTCHA cookie for risk analysis, which can create privacy and compliance considerations for website operators.
hCaptcha is best known for image-based challenges. Although it also offers invisible and passive modes, users may still be shown a manual challenge depending on the selected configuration and risk assessment. These challenges can create friction and accessibility barriers for some users, particularly when image-selection tasks are required.
Both hCaptcha and reCAPTCHA rely on technical and risk-related signals to detect bots. Their use of cookies, browser storage, and international data transfers should be assessed by the website operator. As both providers are U.S.-based, organizations subject to the GDPR should review their specific processing and transfer arrangements.
Friendly Captcha offers a different approach: invisible proof-of-work challenges are solved by the user’s device in the background, without manual image or audio tasks. Friendly Captcha is designed around privacy, accessibility, and usability. It operates without HTTP cookies or persistent browser storage and offers a dedicated EU endpoint for processing requests within the European Union.
For organizations that prioritize invisible bot protection, a frictionless user experience, cookie-free operation, and EU-based data processing, Friendly Captcha is the strongest choice in this comparison.
Try the live demo or create a free trial account to see Friendly Captcha in action.
FAQ
reCAPTCHA and hCaptcha are similar in the way they work. With hCaptcha, especially in the free plan, users are still faced with image marking tasks, which leads to accessibility issues. When it comes to protecting personal information, reCAPTCHA is not transparent about its use of data. As both tools are using cookies and transfer data to the US, they are critical in terms of GDPR compliance and difficult to use for EU companies and websites targeting EU users. Friendly Captcha offers a different technical approach that is more privacy-friendly and accessible. With Friendly Captcha, European users’ data never leaves the EU. If you are looking for a CAPTCHA service that offers a great UX, is fully accessible and offers GDPR compliance out of the box, choose Friendly Captcha.
A CAPTCHA protects websites against spam and bots. Most people know this essential cybersecurity measure as the “I’m not a robot” test. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. To determine whether a request is coming from a human or a bot, users are typically presented with a task.
There are several types and providers of CAPTCHAs. While some “I’m not a robot” tests require manual input from the user, such as clicking on cars or traffic lights, others run completely in the background and are therefore invisible. Friendly Captcha is a provider of an invisible CAPTCHA that is fully accessible and user-friendly.
In the free plan there is not too much difference between reCAPTCHA and hCaptcha. hCaptcha uses image recognition like reCAPTCHA v2. With some of its paid plans, hCaptcha offers a so called passive CAPTCHA and reCAPTCHA v3 offers an invisible CAPTCHA feature.
However, in order to provide the more or less invisible versions of reCAPTCHA and hCaptcha, website owners have to use cookies for risk analysis. This raises privacy concerns. In addition, both CAPTCHAs are not very accessible for people with disabilities.
CAPTCHA is a general term for traditional tests that distinguish between humans and bots, often using distorted text or image-based challenges. reCAPTCHA, developed by Google, offers supposedly easier challenges like “I’m not a robot” checkboxes or background analysis of user behavior. Upon closer inspection, neither approach is convincing.
reCAPTCHA has been part of the CAPTCHA market since the beginning and is therefore widely used. However, website owners implementing it pay with their customers’ data. This can create a negative image, a lack of security and privacy issues. A professional alternative to reCAPTCHA is Friendly Captcha, which protects against sophisticated bots without manual tasks and full privacy compliance.
No, Google doesn’t own hCaptcha. It is a product from the US image labeling company Intuition Machines, Inc. They started to label images for machine learning purposes. As a data vendor, other companies pay hCaptcha to have their images displayed and deciphered by website visitors. This tagged data from the widget is then bought back by the data vendors. The fact that you also get bot protection is more of a nice side effect.