Skip to main content
Umzi Labs
Legal · charter of undertakings

Cookie notice

Eleven articles on what these pages put on your device and what they ask of it. Two things reach past the page itself and both are named below rather than left to be discovered. Every undertaking here is one you can check yourself in a browser, which is the only sort worth giving.

In force from 15 August 2026 Version 2.0 PECR 2003 and the UK GDPR

1The undertaking, in one paragraph

Nothing here writes a cookie of ours to your device. No measurement runs on these pages, no advertising, no tracking pixel, no recording of what you did on screen, and no picture of you is assembled anywhere. You will meet no consent panel, for the reason Article 3 gives.

Two things nonetheless reach past the page. Our hosting provider may write a short-lived security token, and your browser fetches the lettering from Google. Article 4 handles the first and Article 6 the second. Both are visible in your browser's developer tools within about thirty seconds, and we would rather you checked than took our word.

2The rule this article answers to

A cookie is a small piece of data a site asks a browser to hold on to and hand back next time. Session storage, local storage and pixel tags accomplish the same end by other means, and the law is uninterested in the distinction: all of them are storing something on your equipment or reading something already there.

In the United Kingdom the operative provision is regulation 6 of PECR, the Privacy and Electronic Communications (EC Directive) Regulations 2003, read alongside the UK GDPR. Putting information onto a user's device, or reaching into what is already stored there, calls for clear information first and consent second.

A single narrow exemption exists at regulation 6(4). Consent falls away where the storage, or the reading, is strictly necessary to provide a service the user has actually asked for. The Information Commissioner reads that narrowly, and so do we: it reaches a security or load-balancing mechanism, and it does not stretch to cover measurement, nor to cover anything a site operator merely finds convenient.

3Why no consent panel appears

A consent panel exists to gather permission for storage that falls outside the exemption at Article 2. On these pages there is no such storage, so a panel would be collecting permission for nothing at all.

Putting one up anyway would be worse than leaving it out, for two reasons that have little to do with us. It teaches people to swat away a control that genuinely matters on other sites. And it quietly implies this site is doing something it is not, which is an odd way to open a document about candour.

Our undertaking, therefore, is conditional and worth stating precisely: should measurement or anything else outside the exemption ever be added here, we will ask before it loads, make declining exactly as easy as agreeing, and revise this page and its date in advance rather than afterwards.

4What may actually reach your device

These pages are static files and nothing more. There is no sign-in, no basket, no form posting anywhere, no session and no user account, which means there is nothing a first-party cookie could usefully remember about you between one page and the next.

Storage that may reach your device
What Written by Doing what Consent needed?
__cf_bm, or a Cloudflare token named similarly Cloudflare, our host and delivery network Bot management. Separates an automated client from a person, so the site stays reachable. Written only at the moments Cloudflare's protection actually engages. No. Strictly necessary to keeping a service you asked for both secure and reachable.
Nothing further Not applicable These pages define no cookie of their own and write nothing into local or session storage. Not applicable

Verify it rather than believe it. Open the developer tools, go to the storage panel, then load any page on this domain. You should find an empty cookie list, or a single Cloudflare entry and nothing else, with local storage empty beside it.

Its precise name and lifetime are set by Cloudflare and not by us, which is why this article describes the token by what it does instead of quoting a duration we are in no position to guarantee.

5What we undertake never to load

The following are undertakings about the future rather than descriptions of the present, and they are the reason Article 1 can be as short as it is. We will not introduce, on any page of this site:

  • measurement of any description, hosted elsewhere or run by us, including the privacy-preserving kind;
  • an advertising network, a retargeting tag or a conversion pixel;
  • social buttons, embeds or sharing widgets;
  • embedded video, mapping or a comment system;
  • device fingerprinting, session recording, heat mapping or split testing;
  • a live chat widget;
  • tracking that follows you off this domain, or any arrangement passing information about you to somebody else in exchange for anything.

Were any of that to change, Article 10 governs how you would find out, and it would not be by noticing the page had quietly grown a new script.

6The one connection that leaves

The lettering these pages are set in is fetched from Google as a page loads, so your browser opens a connection to fonts.googleapis.com for the stylesheet and then to fonts.gstatic.com for the font files themselves.

No cookie comes back from that exchange. What it does do is disclose to Google LLC the address your connection presents and the standard headers your browser sends, and because Google is outside the United Kingdom it amounts to personal data crossing a border. Google's published position is that these requests are not used to build advertising profiles. That is Google's account of Google, so we pass it on as such, tell you the connection happens, and leave the weighing to you.

The content security policy served with every page here permits those two hosts and refuses every other destination, which puts a hard ceiling on what any page on this domain is capable of requesting. It travels in the response headers, where you can read it for yourself.

Serving those files from our own domain would close the connection altogether. That is where this site is going, and when it arrives this article will be replaced by one recording that nothing outbound remains.

7Why a server log is a different thing

Handing you a page produces an entry in a log at our hosting provider. That entry lives on a server rather than on your equipment, so PECR, which is concerned with what gets placed on or read from your device, has nothing to say about it. Data protection law does, and the privacy notice undertakes accordingly.

A single line holds the shape of one request: the address your connection presented, the moment, the path, the status returned, the browser string and whichever page referred you. Such a record exists to keep the site running and to allow abuse to be investigated. It is joined to nothing else and no picture of anybody is built from it.

8What we undertake about your own controls

Nothing here needs our permission, and that is the undertaking: this site will never make a working feature contingent on your accepting storage. Any current browser will let you inspect what has been stored, block more of it and delete what is there, and the controls sit roughly where you would expect.

  • Chrome keeps them under Settings, then the privacy and security area, with per-site control a level deeper under site settings.
  • Safari keeps them under Settings, then Privacy, where website data can be reviewed and cleared, alongside the option preventing cross-site tracking.
  • Firefox keeps them under Settings, then Privacy and Security, covering both stored site data and the tracking protection level.
  • Edge keeps them under Settings, in the cookies and site permissions area.

Two practical consequences follow, and neither is a problem. Blocking the Cloudflare token may mean Cloudflare challenges you rather more often, since it can no longer see that your browser already passed a check. And an extension blocking third-party requests will stop the font fetch, at which point these pages render in your system lettering. The layout was designed to survive exactly that and remains entirely readable.

9Privacy signals your browser may send

Some browsers attach a header asking sites not to track the reader, and some send a further signal expressing a preference under privacy legislation elsewhere. No settled standard yet tells a website operator what either one obliges them to do.

Here the question never has to be reached. Nothing about you is tracked whether a signal arrives or not, so honouring one and ignoring one land in precisely the same place. The article exists so that you know the point was considered rather than overlooked.

10What we undertake if this changes

Everything above describes this site as at the date shown at the head of the page. Should anything arrive that writes to your device beyond what Article 2 exempts, three things happen in this order: this notice is revised, its date is moved, and a consent mechanism is in place before the new component loads for the first time.

The order matters more than the list. An undertaking to revise a page eventually is worth very little, so ours is to revise it first and load the thing second.

11Questions, and complaints

Write to [email protected] with "Cookies" in the subject line. Should an article here look inaccurate to you, describe what you saw and how you came to see it; the position gets checked and the page corrected where you turn out to be right, and you will be told either way.

A complaint may equally go straight to the Information Commissioner's Office, which oversees PECR and data protection across the United Kingdom, and you need not come to us first. The details:

Supervisory authority
Information Commissioner's Office
Postal address
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Telephone
0303 123 1113
Online
ico.org.uk, where the complaint form is published

Alongside this notice sit the privacy notice and the terms of use.

Back to the top