Skip to content

Legal

Cookie Policy

Every cookie and storage key the site sets, and how to change your choice.

Last updated 28 July 2026

1. What this covers

1.1

"Cookie" is used broadly here. It covers any mechanism that writes something to your device or reads something back: cookies, localStorage, sessionStorage, cached identifiers and anything equivalent. The test is not the technology but whether something is stored on, or read from, your equipment. That is why this Policy exists even though this site writes no cookie of its own.

1.2

This Policy is about your own device, as someone reading this site. If you are here because a report names you, it is not the document you need: you have stored nothing on any device by being named in a report, and nothing in this Policy speaks for you or limits what you can ask of us.

What we hold about you, where it came from, and how to object to it, correct it, or ask us not to produce a report about you, is in the notice written for people a report names, called If a Report Names You, and in our Privacy Policy. You need no account, no form and no particular form of words, and there is no charge. If either of those pages does not open for you, write to [email protected] with the name that appears in the report and we will answer on exactly the same terms.

1.3

This Policy covers the pages of this site. It does not govern another company's site you reach from a link here, and it will not govern a payment page hosted on a payment provider's own domain. Section 7 says what changes when a checkout exists.

1.4

Nothing in this Policy reduces a right you have under data protection or consumer law. Where this Policy and those rights point in different directions, those rights apply.

1.5

Where this Policy states a fact about what this site stores on your device, that statement is meant to be relied on. Nothing elsewhere in our documents is intended to stop you relying on it.

2. What the site stores today

2.1

This site writes no cookie of its own. No analytics cookie, no advertising cookie, no cross-site identifier, no tag manager, no session recording or heatmaps, and no third-party script, embed, widget or font host on any page you can reach. Typefaces are served from our own servers, so loading a page here does not disclose your address to a font host. Nothing on this site today builds a device fingerprint, or any other value derived from your browser or your connection that would let us recognise you across visits.

2.2

One qualification, because a claim is only as good as the way it was checked. This site is delivered through the network and security provider named in our Sub-processors list, which sits in front of our servers. A provider of that kind is capable of setting a cookie on this domain for bot detection or traffic management without any code of ours being involved, and a cookie set that way is still a cookie set on this site. We do not describe it as somebody else's. The table in section 2.3 lists everything found on this site, whoever set it, as at the date at the head of this Policy. If your browser holds something from this site that the table does not list, the table is wrong rather than your browser, and we would like to hear about it at the address in section 9.2.

2.3

One item of browser storage is written by this site, and only after you have used the Cookie Settings control yourself. It is the record of your own choice.

NameTypeCategoryPurposeWhat is in itDuration
ll.consentlocalStorageStrictly necessaryRecords the choice you made about optional storage, including a refusal, so you are not asked again on every pageA version number, the moment you chose, and one true-or-false value for each optional category. Nothing elseNo expiry of its own. It stays until you clear it, until the version changes, or until you withdraw. See section 3

2.4

The record holds no name, no email address, no network address, and no identifier we assigned you. It holds your choice, a version number, and the moment you made it. That moment is recorded to the millisecond, so we will not tell you the record is incapable of telling one browser from another: treat it as a value that can. What we say instead is narrower and is something we can be held to. We never read it on our servers. It is never sent to us or to anyone else. We do not use it to recognise you, and nothing that would is being built. It is not combined with anything else. It can be read by scripts served from this site's own address, of which there are none but our own, and section 2.1 is the commitment that keeps it that way. If you would rather not have it at all, section 4.3 says how to remove it.

2.5

We treat the record as strictly necessary storage, and we say why rather than only asserting it. A site that cannot remember a refusal has to ask again on every page, which is worse for you than the storage is. It is written only as the direct result of you operating the control, it holds only your own decision, and it is used for nothing else.

That is our assessment and not a ruling. If the position is that this one item needs your permission rather than being exempt, you have already given or refused it by operating the control that writes it, and nothing else on this site depends on the answer, because nothing else is stored. On whether the record is also personal data, we treat it as if it is rather than argue that it is not, and if it is, the basis on which we hold it is our legitimate interest in giving effect to your own decision and in not asking you the same question on every page. That interest is yours as much as ours. The same entry appears in the Privacy Policy processing table with that basis stated in the basis column, and not as a cross-reference back to this page.

2.6

The rule is this. Nothing optional is written to your device before you have made a choice, and not making a choice counts as a refusal.

2.7

Stated precisely, because the difference is the kind a reader is entitled to. Our consent code applies that rule to everything that passes through it, and everything on this site passes through it, so nothing optional is written to your device today. One component in our codebase is capable of writing a preference without consulting the consent record. It is not rendered on any page you can reach and it writes nothing today, and it will be brought under the consent check or removed before any page uses it. We say so rather than let "the code implements it" be read as a guarantee about every line of it.

2.8

That rule is why no dialog blocks the page when you arrive. There is nothing to consent to on arrival, so a dialog would ask permission for something that is not happening and teach you to dismiss the next one that matters. That holds only while nothing optional is stored, which is true today. The moment it stops being true, the footer control alone is no longer enough: rule 1 of section 6.7 requires a first-run notice before anything optional loads, and it is written there as a condition rather than an intention.

3. How long a choice lasts

3.1

Browser storage of this kind carries no expiry date of its own, and nothing in this site deletes the record on a schedule. Stated as the mechanism works rather than as a duration we do not enforce, the record lasts until one of three things happens.

3.2

You clear it. Clearing site data removes it, as does a browser setting that discards storage on close. A private window discards it when the window closes.

3.3

We change what is being asked. The record carries a version number. That number changes, and your stored answer stops counting as an answer, in each of three cases: we add a category; we widen what an existing category covers; or a category that was empty when you answered stops being empty.

The third case is not an afterthought. A switch you turned on for a category that held nothing is not consent to whatever we later put in it, and we will not treat it as consent. Until you choose again the safe default applies, and the safe default is that nothing optional is stored. Consent you gave to one thing is never carried across to something you were not asked about.

3.4

You withdraw it. Withdrawal rewrites the record as a refusal rather than deleting it, because the refusal is the part worth remembering.

3.5

The record lives in one browser on one device. A choice made on a laptop is not a choice made on a phone. If your browser refuses storage altogether we cannot remember anything, and the consequence is the safe one: the default applies on every page.

3.6

A choice you made and forgot is not a recent choice, and we would rather ask again than rely on an answer of unknown age. Two statements, kept apart on purpose.

What is true today. The consent record does not expire by time. Sections 3.2 to 3.4 are the only three things that end it, and nothing else does. If any part of this site, including the Cookie Settings control, shows you a duration for the consent record, that display is wrong and this section is right. Tell us at the address in section 9.2 and we will correct it.

What will be true before anything optional is stored. Three things will land in the same release: this Policy will state the age at which a stored choice stops counting as a choice, the check that enforces it will be in the code, and the same figure will appear in the Cookie Settings control, taken from the same value. We publish no figure until all three exist, because a duration shown to you at the moment you are choosing that nothing enforces is a defect in the choice and not only in the notice, and we would rather show you nothing than show you that.

4. Changing or withdrawing your choice

4.1

Cookie Settings sits in the footer of every page. It opens where you already are rather than navigating away, and it lists every category, what is in each one, what you chose, and when you chose it. Section 2 is the inventory that binds us. If the control shows an entry that section 2.3 does not list, the control is wrong, nothing is being stored under it, and we will correct the control rather than the inventory. The same is true of any duration the control shows, for the reason in section 3.6.

4.2

Withdrawing is the same control, in the same place, in the same number of clicks as agreeing. No separate route, no form, no account, no email.

Your withdrawal is recorded the moment you press it, and from that moment nothing optional is loaded again on any page of this site. Anything optional already running on the page you are looking at keeps running until you reload or move to another page, and the same is true of another tab of this site that is already open. Nothing optional runs in any tab today, so today there is nothing to keep running, and this paragraph describes a mechanism rather than anything you can currently experience. Before anything optional ships, a withdrawal will stop it in the tab you are in and in every other tab of this site you have open, without you reloading anything. We will say so here when that is built, and it will be true before we say it.

4.3

You can also work outside our interface: clear site data, block storage for this site, or use your browser's privacy settings. The consent record goes with it, and the safe default applies on your next visit. Blocking storage does not break this site today, because the only thing stored is the record of your own choice. The single consequence is that we cannot remember it.

4.4

Nothing stored on, or read from, your device by this site is sold, shared, or disclosed to anyone for their own purposes, and none of it reaches an advertising network, a data broker or any cross-site data-sharing arrangement. That is the whole of what this Policy can tell you, because this Policy is about your device and nothing else.

It is not a statement about our business, and we will not let it be read as one. We sell written reports, and a report about a named individual contains personal data about that person and is delivered to the buyer who paid for it. Some laws treat the supply of personal data to another party for money as a sale of that data whatever the supplier calls it. We therefore make no general claim that we do not sell personal data, here or anywhere else, and any such claim still appearing on another page of this site is withdrawn. What we do with personal data that is not stored on your device, on what basis, and what a person named in a report can require of us, is in the Privacy Policy and in If a Report Names You.

4.5

Browser opt-out signals. This site does not detect the Global Privacy Control signal today, and we would rather say so than let it be inferred. Nothing on this site is switched by it today either, because nothing optional is stored and no measurement runs. Before any optional storage or any measurement ships, this site will detect that signal and treat it as a refusal of every optional category, recorded in the same way as a refusal you made yourself, and this Policy will state the date it started doing so.

5. What withdrawal removes

5.1

A withdrawal has to undo the thing rather than record that you asked. Clearing what was stored is the difference between honouring a withdrawal and filing one.

5.2

When you withdraw, this site turns every optional category off, removes the optional storage it wrote under those categories, and keeps the consent record itself, rewritten as a refusal, so the refusal survives.

5.3

Today nothing optional is stored, so a withdrawal has nothing to remove. It records your refusal, and the refusal is what stops the question being asked again.

5.4

Withdrawal clears every optional item this site has stored on your device, whatever it is named. There is no prefix, no exception and no category it does not reach. It does not clear the consent record itself, for the reason in section 5.5.

That is a condition on shipping rather than a description of something already exercised. No optional item will be written under any name unless withdrawal already reaches it, and confirming that it does is part of building the item rather than a task that follows it. Nothing optional is written today, so today there is nothing for this to reach. The rule is stated now so that it binds the first thing there is.

5.5

Four things a withdrawal cannot do, said here because the opposite is often implied:

  1. it does not reach another browser or another device, because your choice was never stored there;
  2. it does not delete the consent record itself, which is how your refusal is remembered;
  3. it does not reach storage set by another company on that company's own domain, of which there is none today; and
  4. it does not recall information that has already reached a server. Nothing optional reaches a server today, and when measurement exists a withdrawal will stop future collection rather than erase past collection. Erasure is a separate right and it is in the Privacy Policy.

6. Categories that are empty, and why they exist

6.1

Three categories exist in the Cookie Settings control, and two of them are empty. They are published rather than hidden so you can see the day one stops being empty: a switch that appears on the same day as the thing it governs is a switch you were never really offered.

6.2

Strictly necessary. Cannot be switched off. One entry, the consent record in section 2.3. Nothing in this category tracks you across sites.

6.3

Preferences. Optional, off unless you turn it on, and empty today. It exists for a future in which the interface remembers a notice you dismissed.

Nothing is written to it today, and nothing will be until three things are true together: the key is listed in section 2.3 under the exact name the code writes, the code will not write it unless this switch is on, and withdrawal reaches it under section 5.4. All three are conditions on shipping the feature, not tasks that follow it. If you turn this category on while it is empty, that choice does not survive the day it stops being empty: the version number changes under section 3.3, you are asked again against a named inventory, and nothing is loaded until you have answered.

6.4

Analytics. Optional, off unless you turn it on, and empty today. No product analytics runs on this site, in your browser or on our servers, and no analytics provider has ever received anything from this site.

If measurement is introduced, four things will be true of it before the first event is recorded. It loads only after you turn this category on. Everything it stores on your device is listed in section 2.3 before it ships rather than after. The company that receives the data is named in our Sub-processors list, with the country it runs in, before it receives anything. And the data stays in the European Union. We do not promise that we will build it ourselves rather than buy it, and we do not describe it as first-party: our Sub-processors list already names the analytics provider we have selected and not switched on, because we would rather name it before it runs than after. What we promise is that you will know who receives it and that nobody receives anything unless you turned this switch on. If you turn this category on while it is empty, that choice does not survive the day it stops being empty, for the reason in section 3.3.

6.5

This category governs measurement of you as a visitor. It does not govern, and turning it off does not switch off, the records we have to keep about a purchase and its delivery. When checkout and report delivery are built, our servers will record that an order was placed, what was shown to you and confirmed by you at checkout and when, that a report was produced and made available, and that it was opened. Those records exist to supply what you bought, to issue a correct invoice, to meet our accounting and tax obligations, and to be able to answer a payment dispute or a complaint. They are not analytics, they are not behind this switch, they are not optional, and no choice you make in this control reduces them. What they contain, the basis for each and how long each is kept are in the Privacy Policy and the Data Retention notice.

6.6

Advertising and cross-site tracking. No switch, because there is nothing to switch. We do not sell advertising, we do not run advertising here, and we take part in no cross-site advertising or data-sharing network. Section 4.4 is the commitment about what happens to what is stored on your device. This category is intended to stay empty.

6.7

Three hard rules attach to section 6.4. These are rules, not preferences. A notice that appears on the same day as the thing it asks about is a first-run notice; one that appears afterwards is not.

  1. Nothing optional will be introduced on this site without a first-run notice, shown before the optional thing loads, in which refusing is one action and no harder than agreeing. The footer control in section 4 is enough only for as long as the only storage on this site is the record of your own choice.
  2. Session recording, keystroke capture, heatmaps and automatic capture of everything you click will not be introduced without a first-run consent notice that names them specifically. A general analytics switch is not consent to any of them.
  3. Measurement that stores nothing on your device and reads nothing from it is outside this Policy, because this Policy is about your device, and it is described in the Privacy Policy instead. It is not outside our rules. No such measurement will build, store or use any value that distinguishes one visitor from another across visits, whether derived from your network address, your browser's characteristics or any combination of them, without the notice in rule 1. Counting page views without identifying who made them is the whole of what this permits.

7. What is not built yet

7.1

As at the effective date at the head of this Policy, this site has no sign-in, no account, no checkout and no way to buy or receive a report. The sample reports you can read here are published pages, and reading one stores nothing on your device. Everything else in this section is in the future tense because none of it exists as at that date.

This section describes the state of this site on that date and on no other. It is not a statement that no purchase has ever been made from LeMans Labs and must not be read as one. Sections 2.3 and 7.2 to 7.4 are updated in the release that opens any surface storing something on your device, so the version of this Policy carrying the latest effective date is the one that describes the site you are using. Section 8.4 lets you see which version was in force on any date you name.

7.2

When those surfaces are built they will need storage this site does not set today: a cookie that keeps you signed in; a short-lived cookie that ties a sign-in code to the browser that asked for it; a short-lived cookie on our own pages that ties a checkout session to the browser that started it, so that the order, the confirmations you actioned and the payment can afterwards be matched to one another; a value that lets us recognise a browser you have signed in from before, so we can tell you when a new one appears; and the payment provider's own cookies on its own domain while you are paying. Each will be listed in section 2.3, with its name, purpose, category and duration, before it is set for the first time. The device-recognition value will be something we store on your device and that you can clear, not a characteristic of your device that we derive without storing anything. The commitment in section 2.1 that we do not fingerprint is what rules the second method out.

7.3

Two of those surfaces will also carry security storage set by a provider rather than by us: our payment provider's fraud-prevention storage on the checkout and billing surfaces, and a bot check on the sign-in and checkout forms operated by the network provider named in our Sub-processors list. Neither will load site-wide. Each exists so that a payment and an account can be shown to be genuine, each is treated as strictly necessary, and none is switched off by the Preferences or Analytics categories. We will not offer a switch for them, because a payment we cannot evidence and an account we cannot protect are worse for you than the storage is. None of it is used by us for advertising or to track you across other companies' sites.

7.4

There is no separate asset domain for reports. A file you export, and a report a recipient reads through a link, are served by us from this site's own domain, because every such request is checked before anything is served – that is what lets a link be revoked at all, and an address on somebody else's asset domain would outlive the revocation.

One reader here is not a customer: the person a buyer names on a link agreed to nothing with us and may never have visited this site before. We send that person the link and a code, they confirm the address before their first view, and only then does a report reach them. If serving them stores anything on their device, it is listed in section 2.3 with its name, purpose, category and duration before it is set for the first time, on the same terms as everything else in 7.2, and section 8 makes that a rule about which release it happens in.

8. Changes to this Policy

8.1

Sections 2 and 7 are the parts of this document that go out of date, and they are the parts that matter. The commitment is an ordering: this Policy is updated in the release that first sets a new cookie or storage item we control, or that opens a sign-in, an account or a checkout on this site, and never in a later release.

If we get that ordering wrong, we do three things and we say now what they are. We stop setting the item until section 2.3 lists it. We correct section 2.3 within five working days of finding out or being told, whichever comes first. And we record the correction in the log at section 8.5 with its date, saying what was stored, under what name, and for how long before we corrected it. We will not describe that as a routine update, and we will not date it as though the Policy had been right all along.

8.2

What that commitment covers, and what it cannot. Section 8.1 is a commitment about storage this site sets, and about storage a provider we engage has told us in advance it will set. It is not a warranty about a third party's own behaviour on its own domain. Our payment provider and our network and content delivery providers may change what they set without notice to us. Where that happens we will update section 2.3 as soon as we know and in any event within 30 days of learning of it, and section 8.5 will record that the change was made by that provider rather than by us. Promising otherwise would be promising something we are in no position to keep.

8.3

A new optional category, or a wider purpose for an existing one, does not inherit consent you gave to something else, and neither does a category that stops being empty. The version number described in section 3.3 is the mechanism that enforces it.

8.4

Every version of this Policy is kept. Each carries its own effective date. We will send you any earlier version, including the one in force on a day you name, on request to the address in section 9.2, and we will not ask you why you want it.

8.5

Change log. Material changes are listed here, newest first, with the date each took effect and one line saying what changed. A change is material if it adds a storage item, widens the purpose of an existing one, changes who can read one, or changes how long one lasts. We decide in the first instance whether a change is material, and where the question is arguable we treat it as material and list it. A change that is not listed here is not a change we will rely on against you. Where this site displays a "last updated" date generated by our publishing system, that date tells you when the page was built; this log and the effective date at the head tell you when this Policy changed, and they govern.

DateChange
[Effective date]First published.

8.6

This Policy replaces three earlier positions of ours, and records them rather than changing quietly.

First. We had decided to cover cookies inside the Privacy Policy, reasoning that a separate page would be an empty room. The room is no longer empty, because the site now writes a storage key and offers a control over it, so this Policy exists as a document of its own.

Second. We had decided not to show a first-run notice on arrival. That position stands for as long as the only thing stored is the record of your own choice, because on those facts there is nothing to ask you about when you arrive and the control that lets you decide, and change your mind, is in the footer of every page. Section 2.8 states the condition on which a first-run notice becomes required anyway, and section 6.7 is where that condition is written.

Third. An earlier version of our Privacy Policy said that we use strictly necessary cookies to keep you signed in and to protect the checkout. That was wrong in both limbs: no cookie is set, and there is no sign-in and no checkout for a cookie to protect. It is withdrawn. Where any page on this site still carries it, this Policy governs on the subject of device storage and that page is out of date. We record the withdrawal here rather than deleting the sentence quietly, because a visitor who read it and relied on it is entitled to know it was wrong and that we say so.

9. Who we are, and how to reach us

9.1

The controller of any personal data described in this Policy is LeMans Labs OÜ, a private limited company (osaühing) registered in the Republic of Estonia, Commercial Register code 16872044, registered address Valukoja 8/1, 11415 Tallinn, Estonia. Our full provider details, including the address for service of a legal notice, are in the Terms of Service and the Privacy Policy. There is no separate legal notice page; the information is in those two documents.

9.2

Questions about this Policy, or about anything stored on your device by this site:

Both addresses are read by the same people, and a message counts as received on the day it arrives at either. If either address ever fails to accept a message, that is our failure and not yours, and the date you first sent it is the date we will work from.

9.3

If you are not satisfied with how we handle a question about your data, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Our Privacy Policy sets out that route in full.


This Cookie Policy is part of the LeMans Labs legal set and is to be read with the Privacy Policy, which covers everything we do with personal data that is not stored on your device, and the Terms of Service. If a report names you, the notice written for you is If a Report Names You, and nothing in this Policy limits or qualifies it.