Cookie notice
What this website actually stores on your device, which is close to nothing, and why there is no consent banner in front of it.
1. The short version
This website is a small set of static files. It has no accounts, no forms, no shopping basket, no analytics, no advertising and no embedded content from anyone else except two typefaces. It sets no cookies of its own. It writes nothing to local storage or session storage. There is nothing here that follows you to another website.
The only thing that can appear in your browser’s cookie list because of a visit here is a strictly necessary security cookie set by the network that serves the site, and only in the circumstances described in section 4.
2. What a cookie is, and what the law requires
A cookie is a small text file that a website asks your browser to store, and which the browser sends back on later requests. Cookies are used for many things, from keeping you signed in to counting visitors to following you around the internet for advertising.
In the United Kingdom, storing information on your device, or gaining access to information already stored on it, is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, usually called PECR. The rule is that you must be told clearly what is being stored and why, and you must give consent before it happens.
There are two exemptions in regulation 6(4). The first is where the storage is for the sole purpose of carrying out the transmission of a communication over a network. The second is where it is strictly necessary for a service that you have explicitly requested. "Strictly necessary" is a narrow test: it means the service could not work without it, not that it would be more convenient with it. Analytics does not meet that test, and neither does advertising.
Where a cookie also involves personal data, the UK GDPR applies on top, and our privacy notice explains that side of it.
3. Cookies this site sets: none
We set no first party cookies. The site is delivered as HTML, one stylesheet, one small JavaScript file and a handful of images, all served from this domain. The JavaScript does two things: it opens and closes the menu on small screens, and it fades sections in as you scroll past them. Neither of those stores anything. If you switch JavaScript off, the menu links still work and the sections are visible immediately.
To be specific about the absences, because a list of what is not there is more useful than a vague reassurance:
- No analytics of any kind, first party or third party. We cannot tell you how many people read this page.
- No advertising cookies, no advertising network code, no remarketing tag, no conversion pixel.
- No social media buttons, widgets or embeds, and therefore no cookies from any social network.
- No embedded video or map, which are the usual sources of third party cookies on a small site.
- No tag manager, no consent management platform, no chat widget, no A or B testing tool, no session recorder, no heat mapping.
- No preference cookie, because there is no preference to remember. The site has one appearance and one language.
4. The one cookie you might still meet
This site is hosted and delivered by Cloudflare. Cloudflare’s network sits in front of the site, serves the files, and protects it from attack. Where its security layer decides that a particular request looks automated or hostile, it may set a cookie in order to distinguish a real browser from a machine, or to remember that a challenge has already been passed so that you are not asked again on the next page.
| Name | Set by | Purpose | Type and duration | Consent position |
|---|---|---|---|---|
| __cf_bm | Cloudflare, as our hosting and security processor | Bot management. Distinguishes a human visitor from automated traffic so that the site can be served safely | First party, expires 30 minutes after the last request | Strictly necessary under regulation 6(4)(b) PECR. No consent required, and it is not used for analytics or advertising |
| cf_clearance | Cloudflare, as our hosting and security processor | Records that a security challenge has been completed, so that you are not challenged repeatedly. Set only if a challenge is actually presented to you | First party, duration set by the security configuration, typically up to 30 days | Strictly necessary under regulation 6(4)(b) PECR |
Most visitors will never see either of these, because they are set in response to suspicious traffic rather than on every visit. Neither contains an identifier that we can read, neither is used to build a profile of you, and neither is shared with an advertiser. We have not enabled Cloudflare’s analytics products for this site, so no analytics cookie is set.
5. Other storage: local storage, session storage and the cache
PECR covers any storage of information on your device, not only cookies, so it is worth being explicit about the rest.
- Local storage and session storage. This site writes nothing to either. You can confirm that in your browser’s developer tools under Application or Storage.
- IndexedDB and the cache storage API. Not used. There is no service worker on this site, so nothing is registered to run in the background.
- The ordinary browser cache. Your browser will keep copies of the pages, the stylesheet, the script and the images so that a second visit is faster. That is standard browser behaviour rather than something we store, it holds no information about you, and clearing your browsing data removes it.
- Fingerprinting. We do not attempt it. No canvas fingerprint, no font enumeration, no device probing.
6. Third party requests: Google Fonts
The site uses two typefaces, Fraunces and Inter, which your browser downloads from fonts.googleapis.com and fonts.gstatic.com. Google does not set a cookie for those requests, but your browser does connect to Google’s servers, and any such connection reveals your IP address and user agent to the receiving server. That is a disclosure worth telling you about even though it is not a cookie.
If you would rather that request did not happen, a content blocker or a browser setting that blocks third party requests will stop it, and the site will fall back to the typefaces already on your device. Nothing else on the page depends on it. The privacy notice describes this in section 4.
No other third party host is contacted. Our content security policy permits only this domain and those two font hosts, so a request to anywhere else would be blocked by your browser.
7. Why there is no cookie banner
A consent banner exists to obtain consent for storage that is not strictly necessary. This site has none of that storage, so a banner would be asking you to consent to nothing. It would also be the largest interactive element on a page whose whole point is that it is small and quiet.
We would rather publish this page, which tells you exactly what happens, than show a banner that most people dismiss without reading. If we ever add anything that requires consent, a banner will appear, it will ask before storing rather than after, refusing will be as easy as accepting, and this notice will be updated first.
8. How to control cookies yourself
Whatever a website says, your browser is where cookies are actually controlled. Every major browser lets you see what is stored, delete it, block third party cookies, or block cookies entirely.
- Safari: Settings, then Safari, then Privacy and Security on iOS. On macOS, Safari, then Settings, then Privacy.
- Chrome: Settings, then Privacy and security, then Third party cookies.
- Firefox: Settings, then Privacy and Security, then Enhanced Tracking Protection.
- Edge: Settings, then Cookies and site permissions.
Blocking all cookies will not break this site, because nothing here depends on one. It may mean that Cloudflare challenges you more often, since the cookie in section 4 is what records that you have already passed a challenge.
The Information Commissioner’s Office publishes plain guidance on cookies for the public at ico.org.uk, and you can complain to it if you believe we have handled this badly. Its contact details are in section 23 of the privacy notice.
9. Applications we publish
This notice is about the website. Applications do not use cookies in the browser sense, but PECR applies to any storage on your device, and the same principle holds: anything an application stores beyond what is needed to deliver the service you asked for requires your consent, asked for in the application before the storage happens.
We have not published an application. When we do, its own storage will be described in section 6 of the privacy notice and in the store’s data declaration, and the position will match this one.
10. Changes to this notice, and how to contact us
If what this site stores ever changes, this page changes first, and the effective date and version number at the top change with it. Version history: version 1.0, effective 7 August 2026, the first version of this notice.
YYY SOFTWARE LTD
Email: [email protected]
Registered office: Flat 47 Bennets Courtyard, Watermill Way, London, SW19 2RW
Registered in England and Wales, company number 16938311
If you find a cookie on this site that is not described above, tell us and we will either explain it or remove it.