Skip to content
thinkpod studios

Legal

Cookie Policy

Revision 2.0 — in force 5 August 2026, last revised the same day

What gets stored on your device when you read thinkpodstudios.co.uk, the reasoning behind it, and the switches you hold. Put briefly: no measurement cookie and no advertising cookie is set anywhere here, and the only ones you might meet are security cookies our host needs to serve the pages safely.

It sits alongside our Privacy Policy and our Terms.

1. What cookies and similar technologies are

A cookie is a scrap of text handed to your browser for keeping, which the browser then returns whenever it next calls on the site that issued it. That round trip is the whole mechanism by which a website remembers anything between one page and the next.

The phrase "similar technologies" sweeps in every other route to writing on, or reading off, the machine in front of you:

  • Local storage — roomier than a cookie and it survives until something clears it; unlike a cookie it does not ride along with every request. Session storage behaves the same way but empties the instant the tab shuts.
  • IndexedDB and the Cache API — structured stores that web applications lean on so they keep working when the network drops out.
  • Pixels and tracking beacons — a one-pixel image or a scrap of script fetched from another company's server for no purpose beyond reporting back that you opened a page.
  • Device fingerprinting — assembling enough small details about your browser and hardware to pick you out again later, having written nothing down at all.

Which of these is in play makes no difference to the legislation. What triggers it is the act itself: putting information onto your device, or lifting information off it, by whatever means.

2. How cookies are categorised

  • Strictly necessary — carrying the load for something you actually asked for, such as a security check or traffic being balanced. Nothing is asked of you.
  • Functional or preference — holding onto a choice like language or a colour scheme. Handy rather than essential, so agreement is owed.
  • Analytics or performance — counting how the site gets used. Agreement is owed; being first-party or privacy-minded buys no exemption.
  • Advertising and tracking — assembling a picture of you across separate sites in order to aim advertising. Agreement is owed.

Two further splits run across those four: whose server issued the thing (first-party or third-party), and whether it outlives the browser being closed (session or persistent).

Two statutes have to be read together.

One regulation controls this: PECR — the Privacy and Electronic Communications (EC Directive) Regulations 2003 — at its regulation 6. The gate swings open only where the purpose was explained to you plainly and in full, and you then agreed. Two carve-outs exist — the storage is doing nothing beyond carrying a transmission across a network, or it is strictly necessary for a service you yourself requested. Regulators read that second phrase tightly: the site has to need it, not merely profit from it.

The bar for that agreement is set by the UK GDPR: given freely, aimed at something specific, made in full knowledge, incapable of being misread, and shown through an act on your part rather than through silence. Day to day that means anything non-essential stays dark until you switch it on; boxes may not arrive pre-ticked, carrying on reading is not agreement, and a line claiming that use of the site implies acceptance is worth nothing; walking away has to be as easy as saying yes; and a yes has to stay revocable afterwards.

PECR bites whether or not the thing stored amounts to personal data. Once it is personal data — and an identifier tucked inside a cookie generally is — the UK GDPR governs everything that happens to it afterwards, which is our Privacy Policy's territory.

4. Our position on tracking

Not one measurement cookie, advertising cookie or third-party tracking cookie is set anywhere on this site. You are not counted as an individual, not profiled, not watched by a pixel or a beacon, not fingerprinted, and nothing about your visit is handed to an advertiser or a data broker.

There is no web analytics product running here of any description — nothing bought in, nothing self-hosted — and therefore no dashboard for anybody at the studio to open. What we can see is the aggregate traffic and security summary our host produces as a by-product of serving the pages. That was a decision rather than an oversight, and it is written down because the sentence "we value your privacy" turns up most often on sites doing the reverse.

5. What this site actually uses

The whole inventory follows. Cloudflare serves and shields these pages, and its security layer is the one thing capable of setting a cookie here — the first row on most requests, the second only where a challenge has been put in front of you.

NameProviderPurposeTypeDuration
__cf_bm Cloudflare, Inc. (third-party, set on our domain) Bot management — separates real readers from automated attack traffic, so hostile requests are dropped before they ever reach these pages. Strictly necessary — HTTP cookie Up to 30 minutes from your most recent request
cf_clearance Cloudflare, Inc. (third-party, set on our domain) Marks that you already cleared a Cloudflare challenge, which spares you being asked again. Written only where a challenge was shown to you. Strictly necessary — HTTP cookie Up to 1 year, in practice far shorter under how we have it configured
Local and session storage — None. Nothing on these pages writes to either one. Not used —
IndexedDB, Cache API, service worker — None. What gets served is static HTML and CSS, plus one small navigation script that keeps no state. Not used —
Analytics, advertising, social pixels — None. No measurement tag, no advertising tag, no share button, no embedded widget belonging to anybody else. Not used —

Both Cloudflare entries land inside that PECR carve-out for strict necessity: they do nothing except deliver these pages safely in answer to a request you made, so nothing is asked of you. Block them and the site still works — you may simply meet a challenge rather more often.

6. Third-party requests: web fonts

One item belongs here despite not being a cookie at all. The lettering on these pages is fetched from Google Fonts. Nothing comes back to be stored, but any request to an outside server discloses something: your IP address, your user agent and the page you were reading reach Google, which handles them under a policy of its own.

It gets a section because a cookie policy confining itself to cookies can be accurate down to the last word and still leave you with the wrong impression. Move the files onto our own server and this section changes, with the outside request gone.

7. Storage in our mobile apps

Browser cookies play no part inside a mobile application, though an application still writes to your phone — preferences, whatever content you created, and the identifiers our Privacy Policy describes. All of it lives within the app's sandbox, sits behind your device encryption, and departs with the app when you remove it.

Nothing advertising-related or tracking-related is compiled into what we publish, the device advertising identifier is never read, and we do not follow you into other companies' apps or websites. Sections 29 to 36 of the Privacy Policy spell out what is held and how to clear it.

8. Why there is no consent banner

Agreement is owed under UK law for non-essential cookies and comparable storage. None are in use here, which leaves nothing to agree to and no banner to do the asking.

Requesting permission for cookies that were never set would be a performance — and the banners themselves are a well-worn vehicle for quietly planting identifiers. What the missing banner signifies is the missing thing behind it.

9. If we ever introduce anything non-essential

Should a non-essential cookie, script, pixel or storage item ever be introduced here, we undertake that before it runs we will:

  • ask you first, through a control where every non-essential category begins switched off;
  • make declining precisely as easy and as visible as agreeing — nothing buried, no pre-ticked boxes, no refusal hidden two screens down;
  • make a later withdrawal as simple as the original yes, through a control reachable from any page on the site;
  • enter it in the section 5 table — name, provider, purpose, type, duration — ahead of it ever being set;
  • revise this page and the date at its head, and store nothing whatsoever until you have said yes.

Strictly-necessary entries can shift without asking you, should our hosting or security arrangements move, but they will appear in that table regardless.

10. Controlling cookies in your browser

Every mainstream browser will show you what has been stored, block it, and delete it. Blanket-blocking breaks portions of other websites; on this one the worst that happens is meeting a security challenge more frequently.

BrowserWhere to look
Google ChromeUnder Settings, choose Privacy and security → Third-party cookies; Delete browsing data sits in the same place. For one site alone, use the icon left of the address bar → Cookies and site data.
Safari (macOS)Under Safari → Settings, choose Privacy, where Manage Website Data and Block all cookies both live. Prevent cross-site tracking arrives switched on.
Mozilla FirefoxSettings holds a Privacy & Security panel; Enhanced Tracking Protection there runs at Standard, Strict or Custom, and clearing what is stored happens through Cookies and Site Data, then Manage Data.
Microsoft EdgeOpen Settings. One entry, Cookies and site permissions, leads on to Manage and delete cookies and site data. Tracking prevention sits elsewhere, beneath Privacy, search, and services.

Close a private or incognito window and everything it stored goes with it — the plainest route to reading anything and leaving nothing behind.

11. Controlling cookies and storage on mobile

  • Safari on iOS and iPadOS: open Settings → Apps → Safari, where Block All Cookies, Prevent Cross-Site Tracking and Clear History and Website Data all sit together.
  • Chrome on Android: from ⋮ → Settings, Site settings holds Third-party cookies, while Privacy and security holds Delete browsing data.
  • Chrome on iOS: from ⋯ → Settings, open Privacy and Security → Clear Browsing Data.
  • Samsung Internet: from ☰ → Settings, Sites and downloads holds Cookies, while Personal data holds Delete browsing data.
  • Advertising identifier (a device setting, nothing to do with this site): on iOS, open Settings → Privacy & Security → Tracking and switch off Allow Apps to Request to Track. On Android, open Settings → Security & privacy → Privacy → Ads and choose Delete advertising ID.

12. Do Not Track and Global Privacy Control

Do Not Track (DNT) is a header a browser can send asking to be left alone. It never became a standard and is widely disregarded. Here it alters nothing, since readers are not tracked whether the header arrives or not.

Global Privacy Control (GPC) came later, and what it broadcasts is an objection: no selling of your personal data, no passing it onward. Certain jurisdictions give it legal force; its standing under UK law remains unsettled, though the ICO has said signals sent at browser level look a promising way for people to express a preference. Where we stand: nothing is sold or shared for anybody else's marketing and no non-essential storage is set, so a GPC header finds nothing here to act on — and were we ever running something it reached, we would respect it.

If anything non-essential does arrive under section 9, a GPC header will count both as an objection to legitimate-interests marketing and as a refusal wherever agreement is owed.

13. Changes to this policy

This page is reviewed once a year at minimum, and again whenever the site's technology moves underneath it. Any edit refreshes the version marker and the date at the top. Bringing in non-essential technology follows section 9 and needs your agreement first — quietly amending a policy is not sufficient. Earlier versions can be sent over on request.

14. Contact

Anything at all about cookies or storage on this site:

Email: studio@thinkpodstudios.co.uk
Company number: NI737566, registered in Northern Ireland

Should your browser turn up a cookie missing from the table above, tell us — we would treat that as a defect and go and fix it. The Information Commissioner's Office is open to you as well; section 28 of our Privacy Policy carries the details.

See also: Privacy Policy · Terms