Skip to content

Legal · Cookie policy · Version 2.0

Cookie Policy

Written as a reading rather than a promise. Here is what actually lands in your browser when you open a page here, who put it there, how long it survives, and how to be rid of it.

Effective 15 August 2026PECR / UK GDPRVersion 2.0

1. What this covers

This policy applies to volunos.uk and to nothing else. It sits alongside our privacy notice, which explains the wider question of what we do with personal data; this page deals only with what gets written to, or read from, the device you are holding.

A lab that publishes measurements ought to be able to publish this one. So rather than describing categories of cookie we might in principle use, the table at section 3 is the actual list, and you can check it yourself in a minute using the instructions at section 9.

2. What a cookie is

A cookie is a small text file a site asks your browser to keep and hand back on the next request. Some expire when you close the tab; others persist for a set period. They exist because the web itself is forgetful — each request arrives with no memory of the last — and a cookie is the usual way of giving it one.

A first-party cookie comes from the site in the address bar. A third-party one comes from another domain whose content the page has pulled in, and that is the kind used to follow people between sites. The law, and this policy, care much more about why a cookie exists than about which of those two it is.

3. The reading

Two cookies can appear on this domain, both from the network that delivers the site, and neither is placed for our benefit or read by us. There is nothing else.

Cookies observed on volunos.uk — at 15 August 2026
Name Placed by Category What it does Lifetime Consent
__cf_bm Cloudflare, Inc., which delivers and defends this site Strictly necessary Separates a person reading a page from automated traffic, so the bot defences can act on the difference. It carries nothing that identifies you and builds no profile. 30 minutes, extended while you keep reading Exempt under PECR reg. 6(4)
cf_clearance Cloudflare, Inc. Strictly necessary Appears only if a security challenge was put in front of you, and records that you passed it so the challenge is not repeated on every page. Most readers never see either the challenge or the cookie. Up to a year, depending on the configuration in force Exempt under PECR reg. 6(4)

Both belong to Cloudflare's security layer, which is not something we can switch off without taking away the protection that keeps the site reachable. Cloudflare's own documentation describes them in more detail than we can usefully add here.

4. Browser storage

Cookies are not the only way to leave something behind. localStorage, sessionStorage, IndexedDB and the cache API all persist data on your device, and all of them fall under the same rule in regulation 6 of PECR whatever they happen to be called.

Nothing on this site writes to any of them. The one script that loads handles the navigation menu and a small reveal effect as sections come into view; it keeps its state in memory for the life of the page and stores nothing. No fingerprinting technique is used here either — no canvas readback, no font enumeration, no device probing.

5. The consent test

Regulation 6 of PECR requires clear information and consent before anything is stored on or read from your device. Regulation 6(4) carves out two situations: where the storage exists solely to carry a communication, and where it is strictly necessary to provide a service you asked for.

"Strictly necessary" is a narrow test and it is meant to be. Convenient is not necessary. Useful to the site's owner is not necessary. Analytics fail it, however anonymous the vendor claims to be, which is why measurement scripts require consent everywhere and why the honest way to avoid the consent problem is to avoid the script.

Where consent genuinely is required, it has to be a real choice: unticked by default, as easy to refuse as to accept, as easy to withdraw later, and never bundled into a general acceptance of terms.

6. Why no banner appears

You will not be asked to agree to anything on arrival, and the reason is not that we have decided the rules are optional. It is that both cookies in section 3 fall inside the regulation 6(4) exemption, so there is nothing here that consent could lawfully be sought for.

A banner asking you to accept cookies that are exempt would be theatre — and worse, it would train you to click through the ones that are not.

Should anything ever be added that needs consent, a proper consent mechanism arrives with it, before it runs rather than after, and section 11 says what else changes at that point.

7. Deliberately absent

It is worth naming what a site like this would normally carry. There is no analytics platform here of any kind, first-party or otherwise. No advertising network, no remarketing tag, no conversion pixel, no data management platform. No embedded video, no social sharing widget, no comment system, no live chat, no session recording, no heatmapping, no A/B testing framework, no tag manager, and no consent management platform — which would itself need a cookie to remember your answer.

This is a straightforward trade. We know less about how the site is read than most operators do about theirs, and in exchange the page is fast, the policy is short, and this section can be verified rather than believed.

8. The typeface request

The site is set in a single serif, requested from Google Fonts at page load. Your browser fetches it from fonts.googleapis.com and fonts.gstatic.com, and making that request necessarily shows Google the address you are coming from and the user agent your browser announces.

No cookie arrives from either host, and Google's published position is that the font service does not feed advertising personalisation. It remains a request to a third party, so it belongs on this page rather than buried in a footnote. If you would rather not make it, block those two hostnames: the text reflows into a serif already installed on your machine and every link, table and section still works exactly as it did.

9. Clearing them at your end

Nothing here depends on your accepting a cookie, so you can block or delete them without breaking the site. The worst case is that Cloudflare puts a challenge in front of you slightly more often.

In Chrome, look under Settings, then Privacy and security, then Third-party cookies and Site data. In Firefox, Settings, then Privacy & Security, then Cookies and Site Data. In Safari, Preferences, then Privacy, where you can manage data by website. On Edge, Settings, then Cookies and site permissions. On a phone the same controls sit inside the browser's own settings rather than in the operating system.

To see the reading for yourself: open the developer tools, go to the storage or application panel, and look at the cookie list for this domain. It should match section 3. If it does not, we would genuinely like to know — write to research@volunos.uk and tell us what you saw.

10. Do Not Track and Global Privacy Control

Some browsers send a Do Not Track header, and some send a Global Privacy Control signal. There is no tracking here for either of them to switch off, so both are honoured by default in the only way that matters: nothing about you is collected for anybody to act on.

Were anything ever added that required consent, a Global Privacy Control signal would be read as a refusal without your having to click anything.

11. If the reading changes

This policy carries a version and a date, and the table at section 3 is checked when the site changes and at least once a year. Adding anything that stores or reads data on your device means updating the table before the change goes live, raising the version, and putting a consent mechanism in place first where the new item needs one.

12. Software we release

This policy governs the website. The lab builds tooling for its own use and may publish some of it; where that happens, whatever local storage or identifier the software uses is documented with the release and in our privacy notice, which also covers the iOS and Android store declarations that go with it.

13. Contact

Questions about this page, or about anything you found in your browser that is not in the table, go to research@volunos.uk. The wider picture — lawful bases, retention, transfers out of the United Kingdom, your rights and the route to the ICO — is in the privacy notice.