Legal

Cookies

This site sets one cookie. It exists to keep you signed in and to protect forms against cross-site request forgery. There is no advertising, no analytics, no tracking pixel and no third-party script of any kind. The site's Content-Security-Policy forbids loading one.

What is stored

NamePurposeExpiresSet by
tjb Holds your sign-in session and the anti-CSRF token. Without it you cannot stay logged in or submit a form. When you close your browser This site (first-party)

Flags actually set on that cookie: HttpOnly (unreadable to JavaScript), SameSite=Lax, Secure (HTTPS only).

Your choice

The strictly necessary cookie above is set without asking, which the ePrivacy Directive and the GDPR allow: a cookie required to deliver a service you requested is exempt, and a sign-in session is the standard example. Declining it could only mean the site does not work.

Everything else is yours to decide, and nothing optional runs until you decide it. Silence counts as no. You can change your mind here at any time, and refusing is one click, exactly like accepting.

What analytics would collect, if you allow it

Nothing, today. No analytics service is configured, so allowing the category currently changes nothing and no third-party script is loaded for anyone. It is offered because that is expected to change; when it does, your recorded answer already governs it and this page will name the service.

Related storage

The site stores nothing in localStorage, sessionStorage or IndexedDB. Model previews are decrypted in memory and discarded; nothing about them is written to your device.

Signing in with Google sends you to Google, who set their own cookies under their own policy while you are on their page. We receive only your email address, name and a Google account identifier, never a Google cookie. No Google script runs on this site as part of signing in.

Paying works the same way. Checkout happens on Stripe's own pages, where Stripe sets its own cookies under its own policy, including ones it uses for fraud prevention. Card details never reach this server. We store only the identifiers Stripe gives us for your customer record and subscription, so we know what you are entitled to. No Stripe script runs on this site.

Refusing or removing it

Every browser can block or delete cookies for a single site, and doing so here is safe: you will be signed out and unable to sign back in, but nothing is lost. Browsing and previewing models works signed out.

See also Privacy · Terms · Licence