Cookie policy
Last updated: 31 July 2026
Cookies are small files your browser stores. We keep it deliberately sparse: strictly necessary cookies are always on, everything else runs only after you agree through the cookie banner. Nothing in the “analytics” or “marketing” sections below loads until you choose “Accept all”.
Strictly necessary (always on)
| Cookie | Purpose | Retention |
|---|---|---|
| authjs.session-token | Keeps you signed in (only once you have an account) | Session |
| authjs.csrf-token | Protects sign-in and forms against cross-site request forgery | Session |
| sv_consent | Remembers your cookie choice | 1 year |
Cloudflare, which sits in front of this site for security, may also set a strictly necessary cookie to identify trusted traffic and block malicious requests.
Analytics (only after you agree)
We use Umami, which runs on our own server rather than a third party's, to see which pages and steps are used. It records page views and events without building a profile of you across other websites.
Marketing (only after you agree)
If you accept marketing cookies, two advertising services load so we can tell whether an advert led to a purchase:
| Service | Cookies | Purpose |
|---|---|---|
| Meta (Facebook/Instagram) | _fbp, _fbc | Measures whether an advert led to a purchase |
| Google Ads | _gcl_*, gtag | Conversion measurement |
Accepting marketing also allows us to send Meta a one-way (hashed) version of your email address, your IP address and your browser's user agent from our server, so a purchase can be matched to an advert even if the browser tag is blocked. Decline, and neither the browser tags nor the server-side sending happen at all. The privacy policy explains this in full.
Changing your choice
You can change your preference at any time through the “Cookie preferences” link at the bottom of every page — the banner will reappear. You can also delete cookies through your browser settings at any time.
Questions? Email [email protected]. See also our privacy policy.