This conversation started on someone else’s podcast. In July, Jake, John, and Hans Skillrud spent two episodes of Josh Hall’s Buy or Sell series talking about buying and selling web design businesses. At the end of the second one, Jake invited Hans onto Slow & Steady on-air.
Here’s why. Hans ran a 12-person web design agency in downtown Chicago for seven years. While running it, he started dating a privacy attorney. Over dinner one night, he admitted that his clients’ privacy policies were a Google-and-copy-paste situation.
Her response: “You realize how bad of an idea that is, right?”
That person is now his wife and co-founder. Hans sold the agency in 2019 and went all in on Termageddon, an auto-updating website policies and consent solution that now has over 10,000 agency partners. In this episode, he explains why the wild west era of the web is ending, what a cookie banner actually does, and why the scariest legal threat to your website is a 30-year-old California wiretap law.
Key Takeaways
- If your website has a contact form, you’re collecting data. If it runs Google Analytics, you’re collecting data and sharing it with Google.
- Privacy laws protect people, not places. A small business site in Nebraska can owe disclosures to a visitor from California or the EU.
- Step one is finding out which laws apply to you. Each law dictates exactly what your policies must say and what consent you need. A GDPR policy alone doesn’t cover the rest.
- A consent banner with one giant OK button is non-compliant with every consent law on the planet. A real banner blocks third-party trackers until the visitor says yes.
- A privacy policy explains what data you collect and who you share it with. Terms of service is, in Hans’s words, a laundry list of reasons people can’t sue you. Most sites need both.
- Done thoughtfully, privacy builds trust. Visitors interact with consent banners more every year, and they use them to judge how legitimate a business is.
Episode at a Glance
Hans walks through the dinner confession that became a company, the state of privacy law in 2026, and the wave of demand letters hitting small websites that load trackers without consent. Then the conversation turns optimistic: what respecting visitor privacy actually earns you, and why Hans answers support tickets so thoroughly he was twenty minutes late to this recording.
Action step: Open your website in a fresh incognito window. Right click, Inspect, go to the Network tab, and watch what loads before anyone clicks accept. That’s the exact check the demand-letter attorneys run.
Main idea: Privacy laws protect people, not places. If your website collects data from someone, their laws can apply to you. Finding out which laws apply is step one, because that dictates everything else.
Why it matters: Opportunistic attorneys are sending thousands of demand letters to ordinary websites, asking tens of thousands of dollars for loading what we all thought were free technologies. The exposure is real, and so is the upside: visitors trust sites that handle their data with care.
Quick tool: The five-minute exposure check: incognito window, Inspect, Network tab. And enforcementtracker.com, where you can browse every GDPR fine ever issued, including ones against one-person website owners.
Listen & Subscribe
Podcast page: https://artillerymedia.com/podcast/
Apple Podcasts: https://podcasts.apple.com/us/podcast/slow-steady-a-podcast-by-artillery/id1840249614
Spotify: https://open.spotify.com/show/37ZzVcI8N7xnEDqkap2vCW?si=70b138e65b8c42ca
Follow along:
Instagram: https://www.instagram.com/artillery_media/?hl=en
Jake on X: https://x.com/jakekramer15?lang=en
Facebook: https://www.facebook.com/artillerymedia
Contact us: https://artillerymedia.com/contact/
About Hans Skillrud
Hans is the co-founder and Vice President of Termageddon, an auto-updating website policies and consent solution. Before Termageddon, he ran a 12-person web design agency in downtown Chicago for seven years, then sold it in March 2019 to focus on Termageddon exclusively.
- Co-founded Termageddon in 2016 with his wife, a privacy attorney
- Grew it to over 10,000 agency partners
- One price, $119 a year, for all policies and consent tools, auto-updated whenever privacy laws change
- Oversees sales and operations, and still personally answers support tickets
- Moving to Lithuania, his wife’s home country, to build a farm (while keeping US hours)
His definition of slow and steady: “Managing growth! I never want to lose the level of customer service we provide.”
Termageddon: https://termageddon.com
Highlights & Timestamps
00:00–05:12: The Guest Who Was Late to Slow & Steady
How the Buy or Sell series led here, Hans’s twenty-minutes-late apology, and the dinner confession to a privacy attorney that started Termageddon.
05:12–11:59: The Wild West Is Getting Fences
Contact forms count as data collection, GDPR and Quebec Law 25, fifty states doing their own thing, and the 30-year-old wiretap law (SIPA) fueling thousands of demand letters.
11:59–16:56: What a Cookie Banner Actually Does
Blocking trackers until explicit consent, why step one is always finding out which laws apply, and the giant OK button that complies with nothing.
16:56–23:32: Privacy Policy vs. Terms, in Plain English
One explains the data you collect. The other is a laundry list of reasons people can’t sue you. Plus how Termageddon’s 500-question conditional questionnaire works.
23:32–29:09: The Optimistic Case for the Annoying Banner
Giving people their data back, the trust it builds, and the website-as-town analogy: consent is your immigration policy, terms is your constitution.
29:09–33:23: Slow and Steady Means Managing Growth
The support ticket that made Hans late, rude customers who turn 180 degrees, and never losing sight of treating humans like human beings.
33:23–36:31: Q4 Releases and a Farm in Lithuania
What’s next for Termageddon, and the move Hans is most excited about.
The Dinner Confession
Hans thought he was alone in it.
Seven years running an agency, and every client site got the same treatment: find a privacy policy somewhere on the internet, copy it, paste it, move on. Then he started dating a privacy attorney and made the mistake of telling her.
His defense was the one every agency owner reaches for: his clients could never afford $5,000 attorney-drafted policies. Her point stood anyway. A copied policy makes promises about data practices that aren’t yours, under laws that may not even apply to you.
Termageddon was built to be the middle ground: real policies based on the laws that actually apply to your website, at $119 a year, updated automatically when the laws change. And when Hans tells the copy-paste story to other web professionals, he doesn’t see shock. He sees head nods.
The whole industry was doing it. He just happened to confess to a privacy attorney first.
The Wild West Is Getting Fences
Jake and John have said it on this show for years: the internet has been the wild west. Anyone can grab a domain. No zoning, no inspections, no rules.
That era is closing. GDPR set the tone in 2018, and it’s broad reaching: if your site can get traffic from Europe and uses tracking technologies, it can apply to you. Hans has seen GDPR fines issued to one-person website owners, and you can browse them all at enforcementtracker.com. Canada added Quebec Law 25. And America did, in Hans’s words, the most American thing ever: no federal law, fifty states writing their own. Connecticut updated its privacy law between the day this recording was scheduled and the day it happened.
The sharpest edge right now is SIPA, the California Invasion of Privacy Act. It’s a 30-year-old law written to stop third parties from eavesdropping on phone calls, older than Google itself. Opportunistic attorneys are arguing it applies to websites that load trackers before consent, and they’re sending thousands of demand letters asking for $30,000 in damages, then settling for five or ten grand because nobody wants to go to court. Judges are split roughly 50-50 on whether the cases hold.
Finding a target takes five minutes: incognito window, right click, Inspect, Network tab. “We see code as developers, they see money.”
Hans’s company name was meant to be a joke. It’s getting less funny every quarter.
Step One Is Always the Same: What Laws Apply
Here’s the mistake Hans sees most: grabbing a template, or asking ChatGPT, or installing the first cookie plugin in the WordPress repository, and hoping it covers you.
It works in the wrong order. Different laws require different disclosures and different types of consent. So the sequence is: find out which laws apply to your website first, because that dictates exactly what your policies must say and what your banner must do. Even the “just get a GDPR policy, it’s the most comprehensive” shortcut fails. GDPR doesn’t require you to disclose whether you sell data. Other laws do.
And the banner itself has to actually work. The ones that say “by visiting this website you’re cool with cookies” over a giant OK button are non-compliant with every consent law on the planet. A properly implemented banner keeps third-party trackers off by default and only loads them after the visitor clicks accept.
While we had him, we asked Hans to untangle the two documents in plain English. A privacy policy explains what information your website collects, how, what you do with it, and who you share it with. Terms of service covers the rules of using the site, which mostly means a laundry list of reasons people can’t sue you, and it becomes genuinely necessary once you take payments online.
Order of operations matters. Laws first, then policies, then the banner.
The Optimistic Case for the Annoying Banner
Jake pushed Hans to make the case beyond fear, and it turned out to be the question he’d never been asked.
His answer: every one of us hates spam calls, spam texts, and being hunted around the internet by our own data. Then we go run websites that do the exact same thing to our visitors. “You can give privacy to every single person who visits your website.” Trackers off by default, analytics from the people who opt in, and nothing siphoned off behind the scenes.
The behavior data backs him up. Five years ago, everyone clicked accept-all without thinking. Now visitors interact with banners more every year, checking what technologies a site loads and using that as a gauge for how legitimate the company is. A sketchy-feeling website loses the sale the same way an unprofessional one does.
We’ve described a website as a town on this show before, and Hans upgraded the analogy on the spot. The consent banner is your immigration policy: here’s what I collect when you come in. The terms are your constitution: here’s how things work while you’re here.
Compliance avoids the lawsuit. Trust is what it earns.
Slow and Steady Means Managing Growth
Hans was twenty minutes late to this recording. The reason is the whole episode in miniature: he was answering a support ticket and lost track of time.
His definition of slow and steady is managing growth so the level of customer service never slips. It comes from his agency days: “I fell in love with vendors that gave me great support. And I fell out of love with people who treated me like a number.” So even with SIPA demand letters flooding Termageddon with new customers, every ticket gets a real read and a real answer.
Including the rude ones. Hans tells his team that a hostile first message usually reflects the last support experience that person had, two hours on hold with the electric company. Meet it with patience and 99 times out of 100 they turn completely around. Every person writing in is scared of getting sued and trying to do things right. The job is to get them through it.
He’d rather grow slower than treat people like numbers.
Sounds familiar.
Call to Action
Want to make sure your website is working for your business, and protected while it does?
Start here: https://artillerymedia.com/contact/
Show Credits
Hosts: Jake Kramer & John Wooten
Guest: Hans Skillrud (Termageddon, https://termageddon.com)
Produced by: ARTILLERY, Lincoln, Nebraska
Slow & Steady — A Podcast by ARTILLERY 🎧
https://artillerymedia.com/podcast/