Privacy Notice

Beta · last updated 6 October 2026

⚠️ A plain-language template, not lawyer-drafted. It describes what this software actually does — that part is accurate and verifiable, and you can check it in the network tab of your browser. The legal framing has not been reviewed by a solicitor; have it reviewed before this is offered commercially.

The short version

This website sets one cookie, and only after you click something, and it is the record of that click. There is no analytics, no advertising, no tracking pixel, no social embed, and no font or script loaded from anyone else. You can verify all of that in your browser's network tab, and we would rather you did than took our word for it.

What this website does

ThingDo we do it?
Third-party analyticsNo
Advertising or tracking pixelsNo
Social media embedsNo
Web fonts from a CDNNo — system fonts only
Cookies before you chooseNone
Cookies after you chooseOne: your consent choice, stored on your device
Server logsHost-level request logs (IP, URL, user agent) kept by the hosting provider for security and abuse prevention

What we collect when you run a scan

Rate limiting uses a keyed hash of the requesting address, truncated. It is enough to count requests and not enough to recover an address from. We do not store raw IP addresses alongside scan results.

Consent receipts

When the consent banner is installed on a site, it can send a signed record of the choice a browser made. That record contains the categories chosen, the time, the method (banner, settings, or a browser privacy signal), the policy version, and the site it came from. It does not contain the visitor's name, email, or raw IP address, and it is not linked to an identity.

Each receipt is signed with HMAC-SHA256 so that altering it after the fact is detectable. A receipt is evidence that a browser reported a choice. It is not proof that a person understood anything, and it is not a legal certificate.

Legal bases

Sharing

We do not sell or share data with advertisers or data brokers. Data is processed by our hosting provider on our behalf, and that is the extent of it. If that ever changes, this page changes first.

Retention

Scan results and consent receipts are kept while the beta operates, so that reports stay shareable and receipts remain verifiable. You can ask for anything relating to you to be deleted using the address below.

Your rights

Under UK GDPR and EU GDPR you have the right to access, correct, delete, restrict or object to processing of your personal data, and to data portability. Because we hold very little that is personal, most requests are answered quickly. Write to the address below and we will tell you honestly whether we hold anything about you — including if the answer is no.

Security

The Service refuses to scan private, loopback and internal network addresses, and applies its own target checks to every redirect hop, so it cannot be turned into a way to reach someone else's internal systems. The operator surface is token-gated and, without a token, answers only to the local machine. Passwords are not collected because there are no accounts.

If you find a security problem, please tell us before telling anyone else. We will confirm it, fix it, and say so.

Changes

Material changes to this notice will change the date at the top. The beta is small and the notice is short, and we would rather keep it readable than comprehensive-looking.

Contact

hello@fixmycookies.com — it reaches a person. If you are in the UK or EU and are unhappy with our response you have the right to complain to your data protection authority.