Keslo uses no advertising, and no analytics unless you say yes.
No tracking pixels, no advertising tags, no social media buttons phoning home. If you decline the banner, or never answer it, nothing on this site is requested from anybody else and none of the analytics items below is ever written. The seven items below are the complete list of what this site puts on your device.
What we store
| Name | Where | Why | How long |
|---|---|---|---|
keslo_session | Cookie Strictly necessary | Keeps you signed in as you move between pages. It holds a random token and nothing else — not your email address, not your name, and nothing about which sites you have scanned. | 30 days |
keslo-recent-scans | Local storage Strictly necessary | A short list of the reports you have opened on this device, so the start page can offer them back to you. It holds the website address and the report's reference, never the results. | 30 days, and only the last five |
keslo-theme | Local storage Strictly necessary | Remembers whether you asked for the light or the dark version of this site. It holds one word — light, dark, or nothing at all if you have left it following your device. | Until you change it or clear your browser |
__stripe_mid | Cookie Strictly necessary | Helps Stripe tell a real customer from a stolen card being tried on many sites. It holds a random identifier for this device and nothing about you or what you bought. Set by Stripe. | 12 months |
__stripe_sid | Cookie Strictly necessary | The same fraud check as above, for the few minutes you are actually on the payment form. Set by Stripe. | 30 minutes |
_ga | Cookie Analytics | Tells one returning browser apart from another, so a visit that spans several pages is counted once rather than as several strangers. It holds a random number generated on this device and nothing that identifies you. Set by Google Analytics. | 2 years |
_ga_J36M9LECDB | Cookie Analytics | Keeps track of where you are in a single visit — when it started, and how many pages in you are. It holds counters and timestamps, not a record of which pages. Set by Google Analytics. | 2 years |
“Strictly necessary” is a legal term rather than a compliment, and it is the reason neither of these asks your permission first — so it is worth saying where we have had to make a judgement about it:
keslo-recent-scans— It exists only to return you to a report you asked us to produce, in the same way a shop remembers what you put in your basket. It is not used to recognise you, to measure anything, or to build a picture of you, and clearing it is one press on the start page.keslo-theme— It is the setting itself. Without somewhere to write it down, choosing a theme would last until you opened the next page, which is the same as not offering the choice.__stripe_mid— It is part of how the payment is checked for fraud, on a page you only reach by choosing to pay. Without it Stripe would be more likely to refuse a genuine card — and we cannot take payments without a payment processor.__stripe_sid— As above, and it expires almost immediately.
If you think we have drawn that line in the wrong place, we would genuinely like to know: tell us.
What we do not
| Type | Do we use any? | Details |
|---|---|---|
| Analytics | 2 | Only if you accept the banner. Decline it and we do not know how many people read this page — which means the numbers we do have are a count of the people who agreed, and we read them that way. |
| Advertising | None | We do not advertise and we do not sell data to anyone who does. |
| Third-party requests from your browser | Only if you accept | Photographs are served from our own servers rather than fetched from an image library, so no other company is told which page you are reading. Accept the banner and your browser also loads Google Analytics; decline it and nothing is requested from Google at all. The checkout page loads Stripe either way, because a payment needs a payment processor. |
How to check for yourself
You do not have to take our word for it. Press F12to open your browser’s developer tools, then look at:
- Application → Cookies — empty until you sign in, then
keslo_session. On the checkout page you will also see Stripe’s two. If you accepted the banner, Google Analytics' two are there as well; if you declined, they are not. - Application → Local storage —
keslo-themeonce you have chosen light or dark, andkeslo-recent-scansonce you have opened a report. You can read the second one: it is a list of website addresses and report references, in plain text.keslo-consentis your answer to the banner, with the date you gave it. - Network — reload the page. Every request will be to
keslo.co.ukand nowhere else, unless you accepted analytics, in which case you will also see googletagmanager.com and google-analytics.com. This is the one worth checking if you declined: there should be nothing from Google at all.. The exception either way is the checkout page, which loads Stripe’s form.
This is the same standard we hold other people’s websites to, so it would be a poor look to fail it ourselves.
Why there is a banner
The law that governs this in the UK — the Privacy and Electronic Communications Regulations — requires your consent before a website stores anything on your device that is not strictly necessary for something you asked it to do. Most of what we store is in that exempt category and needs no permission. Analytics is not, so we ask, and we do not load it until you answer.
Two things about how we ask, both of which are the point rather than decoration. Refusing is exactly as easy as agreeing— the same size, the same colour, side by side, no second screen to go through. And closing the banner is not agreeing: there is no dismiss button, because a banner you can make go away without answering is one that collects consent from people who never gave it.
Until you answer, nothing is loaded. This is worth stating plainly because the common alternative looks the same from the outside: many sites load the analytics script immediately and merely instruct it not to store anything yet, which still tells the analytics company you are here. We do not do that. If you decline, your browser never contacts Google at all, and you can watch that for yourself in the network tab.
What would change this
One thing is coming that will affect this page, and we will update it before it arrives rather than after:
- Payments. If we use a payment provider, its checkout may set cookies of its own. Those will be listed above, with the provider named.
If we ever add analytics, a consent banner will appear and it will default to off. We will not switch tracking on and inform you afterwards.
Controlling storage anyway
The list of reports you have opened can be cleared in one press, from the start page, where it is shown. Signing out removes the login cookie.
Beyond that, every major browser lets you view and delete cookies and local storage, and block them by default, under its privacy or security settings. The ICO’s guide for the public explains how, and what cookies do generally.
For what we collect on the server side — which is a separate question from what is stored on your device — see our privacy policy.