Cookies
Last updated 28 August 2026
Two cookies are needed for the site to work at all. One more is optional, off unless you turn it on, and can be turned back off here at any time.
Your choice
Turning it off also expires the cookies analytics has already set, rather than only stopping new ones.
What each cookie is for
| What | Why it exists |
|---|---|
| sf_session | Strictly necessary. Holds a session identifier so you stay signed in, and nothing else. HttpOnly, SameSite=Lax, 30 days. Not used for tracking, and there is no way to offer the site without it while signed in. |
| sf_consent | Strictly necessary. Remembers the choice on this page for six months. The cookie that records a refusal has to be exempt, or the refusal could not be honoured and you would be asked again on every page. |
| _ga, _ga_* | Optional, and the subject of the choice above. Set by Google Analytics to count visits and see which pages people arrive on. Never set unless you have allowed it. |
| Paddle's cookies | Set by Paddle, and only if you open the checkout, to run the payment and detect fraud. They are part of taking a payment you have chosen to make, and are governed by Paddle's own policy. |
What analytics is not used for
It counts visits and reports which pages were viewed and roughly where from. It is not used to build a profile of you, it is not shared with advertisers, and it is not loaded on any page whose address contains a token — a password reset or an email confirmation link — because a page-view beacon reports the address it is on, and that would hand a working credential to a third party.
Nothing on the site behaves differently depending on your answer, and nothing is withheld for saying no.