Cookie policy
Updated 29 September 2026Cookie policy
What a cookie is
A cookie is a small file a website asks your browser to keep and hand back on your next visit. Related technologies do the same job by other means, including local storage, session storage, and tracking pixels. Dutch and EU law treats them the same way, so everything below applies to all of them.
Your choice
The first time you visit a public page, a banner asks whether you accept analytics. Until you answer, and after you reject, Google Analytics does not load and your browser makes no request to Google at all.
- Reject and accept are the same size and the same style, and each is a single click.
- Rejecting leaves the whole site working. Nothing is withheld.
- We ask again after twelve months rather than lean on an old answer.
- You can change your mind at any time from Cookie settings in the footer of every public page, or with the button below.
Withdrawing consent stops analytics straight away and deletes the Google Analytics cookies from your browser. Data already sent before you withdrew stays with Google until its retention period ends, which the privacy policy states.
Every cookie and what it does
Strictly necessary
These need no consent under Article 11.7a of the Dutch Telecommunications Act, because each one does only what you asked for.
unfckd_consentremembers whether you accepted or rejected analytics, so the banner does not ask on every page. It holds the word granted or denied and nothing else. Set by unfckd.dev when you answer, kept for twelve months.unfckd.session_tokenkeeps you signed in to the dashboard. On unfckd.dev it is named__Secure-unfckd.session_token, a prefix that tells browsers to send it over HTTPS only. It holds a random session identifier, carries no personal data itself, and is marked HttpOnly and SameSite so scripts cannot read it and other sites cannot send it. Set when you sign in, cleared when you sign out, and kept for at most 30 days.themein local storage remembers whether you picked the light, dark or system theme in the dashboard. It is written only when you pick one, and stays until you clear your browser storage.
Analytics, only with your consent
Set by Google Analytics on unfckd.dev, and only after you accept. Neither is set on any dashboard page.
_gaholds a random identifier so Google Analytics can tell one browser from another across visits. It does not hold your name, email or account. Kept for 13 months from your last visit, which we set shorter than Google's default of two years._ga_followed by our measurement ID keeps track of the current visit, such as how many pages it has covered. Kept for 13 months from your last visit.
Google signals and advertising features are switched off, so these cookies are not linked to your Google account and are not used for ads. No other Google cookie is set by this site.
Where analytics does not run
The dashboard runs no analytics at all, whatever you chose in the banner. Its pages carry the names of your servers and other details that are yours, and none of that is sent to Google. Signing in loads the dashboard fresh, so an analytics script from a public page is not carried across.
The fonts are compiled into the site when it is built and served from unfckd.dev, so your browser never contacts Google Fonts.
Our host sets no cookies
The site is hosted on Vercel. Vercel sets no cookies on unfckd.dev. It does record standard server logs when it serves you a page, including your IP address. That happens at the server rather than on your device, so it is not cookie access and it needs no consent. It is still personal data, and the privacy policy explains the legal basis for it and what your rights are.
unfckd-lite uses no cookies
unfckd-lite is a program you run on your own machine, not a website. It has no browser, sets no cookies, and makes no network request to us.
If you follow a link away from here
The site links to GitHub and Discord. Those services set their own cookies once you arrive, and their own policies govern that. Nothing is set until you choose to click.
What would change with a CDN
If we put Cloudflare in front of the site, its bot protection sets a cookie named __cf_bm, and its challenge system can set cf_clearance. Both are there to tell humans from automated traffic. They are generally treated as strictly necessary for security, so they would not sit behind the consent banner, but we would list them here with their purpose and lifetime before switching Cloudflare on.
If the dashboard later needs another cookie, it goes in the list above before it ships.
Controlling cookies yourself
Every major browser lets you block or delete cookies from its settings or privacy menu. Blocking them leaves the public pages working exactly as before. It will stop you signing in to the dashboard, since staying signed in is what the session cookie does, and the banner will ask again on each visit because it cannot remember your answer.
Changes
The date at the top of this page shows the last substantive change. If we ever set a cookie that is not listed above, this page will say so before it happens rather than after.
