Cookie Policy
Effective: May 10, 2026 · Version 1.0
This Cookie Policy explains what storage technologies Loft Tools uses on your device, what they’re for, and how to control them. It supplements our Privacy Policy.
1. The short version
At launch, Loft Tools sets no cookies, runs no analytics scripts, and uses no advertising trackers.
We do use device-local storage (localStorage, IndexedDB, and a Service Worker cache) to make tools work offline and to remember your preferences. None of this data leaves your browser or is shared with us or anyone else.
We will update this page at least 14 days before that changes — for example, before we add privacy-preserving analytics or before we serve any advertising.
2. The terminology, briefly
When privacy laws (the EU ePrivacy Directive, the UK PECR, the CCPA, etc.) talk about “cookies,” they often mean any technology used to read or store information on your device. That includes:
| Technology | What it is |
|---|
| Cookies | Small text files set by a website and sent back to the server with each request. |
| localStorage | A larger key-value store kept by your browser per site. Stays until cleared. |
| sessionStorage | Like localStorage but cleared when you close the tab. |
| IndexedDB | A larger structured database kept by your browser per site. |
| Service Worker cache | Files saved by your browser so the site can work offline. |
| Pixels / web beacons | Tiny invisible images that report back when loaded. |
| Browser fingerprinting | Building a “fingerprint” from the combination of your browser settings and capabilities. |
We refer to all of these as “storage technologies” below. Where a particular law uses the word “cookies” we mean it in the broad sense.
3. What we use today
3.1 Strictly necessary device-local storage (no consent required)
We use the following storage technologies, all of which are strictly necessary to provide a function you’ve explicitly requested. Under the ePrivacy Directive (recital 25 / Art. 5(3)) and equivalent rules, strictly necessary storage does not require prior consent.
| What | Where | Purpose | Lifetime |
|---|
| App shell cache | Service Worker cache | Make the Service work offline and load fast | Until you clear browser site data, or we update the cached version |
| Tool preferences | localStorage / IndexedDB | Remember your last-used unit, theme (dark/light), most-recently-used tools, draft text in a notepad-style tool | Until you clear browser site data |
| Recent files index (where applicable) | IndexedDB | Show “recent” entries inside a tool that you reopened. Files themselves are not stored unless the tool offers an explicit “save” option. | Until you clear browser site data |
These do not identify you, are not shared with anyone, and are not used for advertising or analytics.
3.2 First-party security cookies (set automatically by our hosting provider)
Cloudflare, our hosting provider, may set the following cookies for security and abuse prevention. These are considered strictly necessary and do not require prior consent under EU/UK rules.
| Cookie | Set by | Purpose | Lifetime |
|---|
__cf_bm | Cloudflare | Bot management — distinguish humans from automated traffic | 30 minutes |
cf_clearance | Cloudflare | Records that you have passed a security challenge so you don’t have to repeat it | 30 days (only set when triggered) |
We don’t read or share these cookies. Cloudflare’s cookie policy: cloudflare.com/cookie-policy.
When you click through to a third-party donation platform (Buy Me a Coffee, Ko-fi, Stripe, GitHub Sponsors, or similar), that platform may set its own cookies on its own domain, governed by its own cookie/privacy policy. We do not see or share those cookies.
4. What we do not use
For clarity, we do not currently use:
- Google Analytics, Adobe Analytics, Mixpanel, Heap, or any similar analytics product;
- Meta Pixel, TikTok Pixel, Pinterest Tag, LinkedIn Insight Tag, X (Twitter) Pixel, or any other advertising pixel;
- Google Ads, Microsoft Ads, Meta Ads, programmatic ad networks, or any header bidding;
- A/B testing or feature-flagging tools;
- Session replay or heatmap tools (Hotjar, FullStory, LogRocket, etc.);
- Tag managers (Google Tag Manager, Adobe Launch);
- Browser fingerprinting libraries;
- Cross-site tracking of any kind.
We will update this list and section 5 before any of this changes.
5. What changes when we add analytics or ads
We expect to add the following:
5.1 Privacy-preserving analytics
We plan to add a privacy-preserving, no-cookie analytics provider — for example Plausible, Fathom, or Cloudflare Web Analytics. None of these set persistent cookies on your device, none use fingerprinting, and none track users across sites. They count page views and aggregate referrers in a way the EDPB and the ICO have generally treated as not requiring prior consent.
When this is enabled, this page will be updated to:
- name the provider,
- link to its privacy policy and the data it collects,
- describe what we look at (page views, referrers, country at the country level), and
- explain how to opt out (your “Do Not Track” or Global Privacy Control signal will be honoured even though the provider does not set cookies).
We will give at least 14 days’ notice on the site before this is enabled.
5.2 Advertising
We are honest about our roadmap: advertising is planned for free-tier surfaces (likely a small number of category and tool pages). When advertising goes live:
- this page will list the ad networks and partners we use;
- a consent banner will be shown to visitors in the EEA, UK, Switzerland, Brazil, and any other jurisdiction with a prior-consent requirement, asking for granular opt-in before any non-essential cookies are set;
- visitors in the U.S. will be able to use the Global Privacy Control (GPC) browser signal to opt out of “sale” or “sharing” of personal information, and we will provide a “Do Not Sell or Share My Personal Information” link in the site footer;
- the Privacy Policy will be updated with the categories of advertising partners and how to exercise your rights with each.
We do not plan to use any of the following: tracking children under 13, building cross-device identity graphs, retargeting based on sensitive categories (health, religion, sexual orientation, financial distress), or selling personal data for monetary consideration.
6. Your choices
You can control storage technologies through your browser. Each browser handles this slightly differently; the major ones are:
- Google Chrome — Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox — Settings → Privacy & Security → Cookies and Site Data
- Apple Safari — Settings → Privacy
- Microsoft Edge — Settings → Cookies and site permissions
- Brave — Settings → Shields & Privacy
You can also:
- Clear Loft Tools’ device-local storage at any time (which will reset preferences and the offline cache);
- Block all third-party cookies (which we recommend in general — none of our functionality depends on third-party cookies);
- Use a browser-level Do Not Track or Global Privacy Control signal (we honour GPC for U.S. opt-out purposes);
- Use a private/incognito window (which discards storage when the window closes).
If you block strictly necessary cookies (e.g., the Cloudflare bot-management cookie), parts of the Service may not work correctly.
7. Changes to this Cookie Policy
Material changes will be highlighted at the top of this page for at least 30 days, and announced via a banner on the home page. We will not enable any new tracking, analytics, or advertising technology without first updating this page and giving at least 14 days’ advance notice.
A complete change history is available on request to legal@lofttools.com.
Email: legal@lofttools.com
Mail: [OPERATOR MAILING ADDRESS]