COOKIE POLICY · UPDATED 1 OCTOBER 2026
Cookie policy
The current application has no advertising pixels, third-party analytics or session-replay scripts. It uses first-party cookies for requested report access and sign-in.
Privacy contact · Make a privacy complaint · Complain to the ICO
Guest reports: gf_guest
Provider: GDPRFix, on the hostname you are using. Purpose: links your browser to the private scans you request without an account. Set when you request a scan, not simply when you read the homepage. Lifetime: up to 30 days. It is HTTP-only, SameSite=Lax and marked Secure in production. Its purpose is access to your requested reports, not advertising or cross-site tracking.
Account sign-in: gf_session
Provider: GDPRFix. Purpose: authenticates your account after a valid one-time sign-in link. Lifetime: up to seven days; signing out removes it and invalidates the session. It is HTTP-only, SameSite=Lax and marked Secure in production. Authentication tokens are stored as hashes on the server.
Google reCAPTCHA on the contact form
Where enabled, selecting Load security check loads Google reCAPTCHA. It can use Google cookies, including a security cookie named _GRECAPTCHA, and process browser and network information to assess whether the interaction is automated. We do not load it simply because you visit a page. The form links to Google’s privacy notice and terms before loading the check. You can email us directly instead. Google controls its cookie lifetimes and may use existing Google cookies; your browser’s site-data settings show the cookies actually stored.
Why we have no banner
Our first-party cookies support functions you explicitly request: private report access and account authentication. Google reCAPTCHA is loaded separately when you request the security check, as described above. We treat those uses as strictly necessary. There is currently no optional advertising or analytics category to accept or reject. If optional technology is introduced, we will assess the applicable requirements, update this policy and provide controls before using technology that requires consent.
Removing cookies
You can remove or block cookies in your browser’s site-data settings. Removing gf_guest may prevent you accessing guest reports; removing gf_session signs you out. Deleting a browser cookie does not by itself delete the server-side report or account. Use the privacy contact for a data-deletion request.
Your currency preference
The sessionStorage entry gdprfix-display-currency remembers the display currency you explicitly select for this browser tab. It lasts for the tab session and is not used for advertising or analytics. Automatic currency display can use a country code supplied by our hosting provider without setting a separate tracking cookie.
Storage and other services
The application does not use localStorage or sessionStorage for advertising or analytics. Development tooling or browser extensions can add their own activity and are not part of the production application. When enabled, checkout takes place on Stripe’s website under its own cookie disclosures. Websites being scanned run in separate worker browser sessions; their cookies are not installed in your browser.
Verification before launch
We will test the final HTTPS deployment, including logged-out browsing, a guest scan and account sign-in. Hosting tools and later integrations can change the storage footprint. This policy is not a claim that a public production self-scan has already passed.
Official guidance: Privacy information · Complaint handling · Cookies and storage