Cookie policy
We set none. Here is exactly what that means.
1. Why there is no banner
Article 5(3) of the ePrivacy Directive requires consent before storing information on your device, unless that storage is strictly necessary to deliver the service you asked for. We do not store anything on your device at all, so there is nothing to consent to. A banner would be theatre.
2. What we do not use
- No analytics — no Google Analytics, no Plausible, no self-hosted equivalent.
- No advertising or remarketing pixels.
- No session cookies: scans need no account, so there is no session to keep.
- No local storage, session storage or fingerprinting.
- No third-party fonts or scripts. The typefaces are embedded in our own stylesheet, so your browser makes no request to anyone else.
3. The one exception: paying
If you choose to buy a report, checkout takes place on Stripe's own domain. Stripe sets cookies there that are strictly necessary to process the payment and to prevent fraud. Those cookies are set by Stripe, on Stripe's page, under Stripe's privacy policy. We neither set nor read them, and we never see your card details.
4. Your report link
Your report is reachable through an unguessable link rather than a login, which is precisely why no cookie is needed to remember who you are. Anyone holding that link can open the report, so treat it as you would a password — and ask us to delete it whenever you like.
5. How to check this yourself
Do not take our word for it. Open your browser's developer tools, look at Application → Cookies while using this site, and you will find it empty. Or scan reginspector.com with the tool itself: the ePrivacy pack reports every cookie set on first load.
6. If this changes
If we ever introduce a cookie that is not strictly necessary, we will ask for your consent before setting it, and this page will be updated first. Any such change is recorded in the version and date at the top.