Cookie statement
What reaches your device when you open a page here, declared field by field, with the method for checking the declaration against the site rather than taking it on trust.
1The declared position
[storage]
written_by_this_site = 0
analytics = false
pixels = false
embeds = false
scripts = 0 # the site ships no JavaScript at all
host_security_cookies = "2, conditional, see part 4"
Nothing is written to your device on this company's behalf. There is no measurement, no tag manager, no advertising pixel, no social embed, no session identifier and no attempt to fingerprint the browser. Nothing here follows you to another site, and nothing here follows you around this one either.
The single exception is not ours to set. The service that puts these files in front of you can, under narrow conditions, write a security cookie of its own. Part 4 names both of them, says when they appear and how long they last.
Back to parts2What the rule actually says
[rule]
source = "PECR 2003, regulation 6"
requires = ["clear information", "consent"]
exemptions = ["carrying the message", "strictly necessary"]
A cookie is a short piece of text a site hands to your browser and asks it to hand back on later visits. Local storage, session storage and tracking pixels achieve much the same thing through different mechanics, and the rules cover them all alike, which is why this document talks about storage rather than only about cookies.
The Privacy and Electronic Communications (EC Directive) Regulations 2003 govern the point in the United Kingdom. Their sixth regulation is the operative one: put something on somebody's device, or read something already sitting there, and you owe them a clear explanation first and their permission before you proceed, at the standard of permission the UK GDPR sets.
Two situations escape the permission requirement. One is storage that exists purely to carry a communication across the network. The other is storage without which a service the person deliberately asked for could not be delivered. Measurement never qualifies under the second limb, whatever the vendor claims: the regulator has been consistent that analytics needs permission like anything else. This site sidesteps the whole question by measuring nothing.
Back to parts3Written by this site
[first_party]
count = 0
There is nothing to tabulate here. What gets served from this domain is hand-written markup, one stylesheet, an inline drawing and a favicon. No script runs on these pages, so nothing on them is capable of writing to storage, reading from it, or reporting anywhere. Turning JavaScript off entirely changes nothing about how the site behaves, which is a fair test of the claim and takes about ten seconds to run.
Back to parts4Written by the host, in narrow cases
[host]
provider = "Cloudflare, Inc."
role = "serves the files, terminates TLS, filters abuse"
may_set = ["__cf_bm", "cf_clearance"]
purpose = "security, not measurement"
These pages are served through Cloudflare, which sits between your browser and the files, handles the encrypted connection and turns away hostile traffic. Its protective features can write a cookie. Because it does so from this domain, your browser will file it as belonging to this site even though it did not originate here.
| Name | Written by | What it does | When it appears | Lifetime | Permission |
|---|---|---|---|---|---|
__cf_bm |
Cloudflare, Inc. | Separates a person's request from an automated one, so abusive traffic can be filtered without shutting out readers. | Only where bot filtering engages for a particular request. Most visits never see it. | Half an hour at most | Strictly necessary, so the exemption in the sixth regulation applies: it exists to deliver the page you asked for, safely. |
cf_clearance |
Cloudflare, Inc. | Remembers that a security challenge was passed, so the same challenge is not put to you repeatedly. | Only if a challenge page was shown to you. | Thirty days at most | Strictly necessary, on the same exemption. |
Scrolls sideways on a narrow screen.
Neither is used for measurement, profiling or advertising, and neither carries an identifier this company can read or would know what to do with. No analytics product offered by that provider is switched on for this property, and the provider publishes its own description of both cookies for anyone who wants the mechanics.
Back to parts5The font hosts
[fonts]
faces = ["Newsreader", "JetBrains Mono"]
served_from = "Google's font hosts"
cookies_set = 0
address_seen_by_them = true
The site is set in two faces collected from Google's font infrastructure. That fetch writes no cookie, but it is still a request leaving your browser for somebody else's server, and that server necessarily sees the address it came from and the agent string attached to it. Calling that nothing would be inaccurate, so it is declared here and again in part 4 of the privacy manifest.
Blocking those hosts, at the browser or further out, leaves every page here perfectly readable. The type falls back to whatever serif and monospace your device already carries, and nothing in the layout depends on the substitution.
Back to parts6What your browser keeps on its own account
[browser_side]
http_cache = "normal, per your settings"
hsts_entry = "recorded after the first visit"
tls_session = "resumption data, per your settings"
readable_by_us = false
A few things do end up on your machine after a visit, and none of them are ours. Your browser caches the stylesheet and the fonts so a second page loads faster. It records that this domain asked to be reached over HTTPS in future, which is the strict transport policy doing its job. It may keep material that lets an encrypted connection resume without a full handshake.
All of that is the browser managing its own housekeeping under settings you control. None of it is readable by this company, none of it is sent to us, and none of it identifies you to anyone here. It is described because a storage manifest that quietly omitted it would be technically true and practically incomplete.
Back to parts7Why no banner appears
[banner]
shown = false
reason = "nothing here needs permission"
Permission is owed where something is being written or read that has no exemption behind it. Nothing on this site is in that position, so there is nothing here for you to permit and no honest question a banner could ask.
There is a second reason for leaving it out. A banner that appears where no permission is required still teaches the reader to dismiss banners without reading them, and that habit costs them elsewhere, on sites where the question is real. Adding one here would buy the appearance of diligence at somebody else's expense.
Back to parts8Checking this yourself
[verify]
tool = "the browser you already have"
panel = "Application, or Storage"
expect = "empty, or the two names in part 4"
Nothing in this document should be taken on trust, and the whole of it can be tested from the tools already sitting in your browser. Open the developer tools, find the panel called Application or Storage depending on which browser you use, and look at cookies, local storage and session storage for this domain. Everything should be empty, apart from the two host names in part 4 if your request happened to meet the conditions that produce them.
The network panel is worth a look too. It lists every request a page made, and for a page here the list should hold this domain and the two font hosts, with nothing else in it. That is a harder claim to fake than a paragraph of reassurance, which is why the instructions are printed instead of the reassurance.
Back to parts9Clearing and blocking
[controls]
clear_site_data = "browser settings, per site"
block_all = "supported, nothing here breaks"
challenge_note = "blocking may repeat a security check"
Every current browser lets you inspect what a site has stored, delete it for that site alone, or refuse storage from it entirely. The setting lives under privacy or site permissions, and it is usually reachable by clicking the padlock in the address bar and following what appears.
Refusing everything costs you nothing on this site, because nothing here depends on storage to function. The one consequence worth knowing is that if you also refuse what the host writes, and a security challenge is ever put to you, it may be put to you again on the next request, since the thing that remembered you passed it is exactly what you declined.
Back to parts10Revisions, and complaints
[revision]
current = "A"
dated = "2026-08-07"
rule = "declared here before it is deployed"
If anything on this site ever needs to write to your device beyond what is declared above, this document is amended first, the revision letter moves, and where permission is owed a proper request for it appears before the thing that needs it is deployed. The order matters: a practice does not go live and get written up afterwards.
Questions, corrections and disagreements go to [email protected]. If you think this site is storing something it has not declared, that is a report worth sending, and it will be answered on the technical merits.
The regulator for these rules is the Information Commissioner's Office, which takes complaints directly at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, on 0303 123 1113, or through ico.org.uk/make-a-complaint. Part 21 of the privacy manifest carries the same route in more detail.
Back to parts