We set no cookies of our own. No advertising cookies, no tracking pixels, no analytics of ours, and no third-party script that we put in our pages. We keep three values in your browser's storage: your answer to the cookie notice, the destination of a link you clicked, and your language choice if you made one. Those three are never sent to our servers. Not everything that reaches your browser is ours, though: our hosting provider adds security, reporting and speed features of its own — one of them stores a cookie, and one of them is a measurement script that our own security policy blocks. Section 5 lists them one by one.
Contents
1. What cookies are, and what we use
A cookie is a small piece of text a site leaves in your browser that is sent back to the server on every request. That automatic return trip is what makes cookies useful for tracking people.
We do not use cookies. We use local storage and session storage instead. The difference matters: values in either store are not automatically sent to any server; they stay in your browser and are read by the page's own code. The difference between the two is how long they last: a value in session storage disappears by itself when you close the tab. Our code never transmits them anywhere.
We still publish this under the heading "Cookie Policy", because both the regulations and general expectation use that term for anything stored on your device. We are not hiding behind a technicality.
2. The three values we store
| Name | Type | Content | Purpose | Lifetime |
|---|---|---|---|---|
w0a_consent |
First-party local storage |
A version number, whether measurement was allowed, and the date of your answer | Remembering your answer to the notice so we do not keep asking | 12 months, or until you delete it — after that the notice asks again |
w0a_go |
First-party session storage |
The name of an on-page section: faq, pricing, features, download, how or main |
Carrying which section to scroll to when you move from another page to a section of the home page | Seconds: the destination page deletes it the moment it reads it, and it is gone when you close the tab |
w0a_lang |
First-party local storage |
A two-letter language code: en or tr |
Remembering your choice after you press a language button; if you never press one, this value is never written | Until you delete it |
That is all we store. We write no other value. None of the three identifies you, none contains an ID number, and none can be linked to your browsing on other sites. The only other things that can end up in your browser because of this site come from our hosting provider rather than from us, and section 5 describes them one by one.
Why the consent record carries a version number rather than a plain "yes": when we change this text, we need to know which version your consent was given against and ask again if necessary. Consent that cannot be evidenced does not legally count as given. We keep your answer rather than asking again on every visit for the same reason the notice exists at all — repeating the question would be the more intrusive option, not the safer one. The record expires by itself after 12 months: an answer given a year ago is no longer evidence of a current choice, so the notice comes back and asks once more. The record is a version number, a yes/no and a date, it never leaves your browser, and the "Reset my cookie choice" button below withdraws it in one click at any time.
3. Essential versus optional
Values that are strictly necessary for the site to work do not require explicit consent; informing you about them is still required, and this page is that information.
- Essential:
w0a_consent(the record of your choice itself),w0a_go(the destination of the link you clicked) andw0a_lang(the language you explicitly chose by pressing a language button). The consent record, a short-lived value that completes an action you asked for, and remembering a preference you yourself set are among the examples the regulations treat as strictly necessary. If you never press a language button,w0a_langis never written; the site opens in English by default, or in Turkish if that is your browser's language. - Optional: none at present. If we add measurement in future, it will run only for visitors who chose "Allow measurement".
The two buttons in the notice are deliberately the same size and the same style. Refusing must be as easy as accepting; making "Accept" large and colourful while "Reject" is a small grey link is not a valid way to obtain consent.
4. Measurement (analytics)
There is no measurement tool of ours on this site, and nothing measures your visit today. Our hosting provider does insert a measurement script of its own into some responses; our security policy blocks it, so it never loads and sends nothing — section 5 sets that out. Even if you choose "Allow measurement", nothing runs today: your permission is simply recorded.
If we later want to measure visits, we will follow these rules: measurement will run only for those who consented, no request will be sent before consent, and this page will be updated to state which tool is used, what data it processes, and how long it is retained. In the EU, the UK and Türkiye alike, analytics cookies are not treated as "essential"; they require opt-in consent.
5. Third parties
We embed no third-party content in our pages. Fonts come from your own system — we do not connect to a service such as Google Fonts, because that would send every visitor's IP address to another company. Images are either embedded in the page or served from our own domain. The site's security headers stop the page itself from loading or contacting anything outside our own domain; they cannot, and are not meant to, stop a link you choose to click from taking you somewhere else. What our hosting provider adds to the page after it leaves us is a separate matter, and it is set out immediately below.
One third party is unavoidable, and we would rather name it here than leave you to find it in a response header: this site is served through Cloudflare, our hosting and security provider, which therefore sees every request, including your IP address, and which is listed in section 8 of the Privacy Policy. Cloudflare adds features of its own to what it serves. We did not write them and cannot switch them off page by page; here is each one we have found, and what it means for your browser.
- A network-error report. Every response asks your browser to remember for seven days that if a request to this site fails at the network level, a short technical report — the address requested, the type of error, and your IP address as the recipient sees it — should be sent to Cloudflare's reporting address,
a.nel.cloudflare.com. Page loads that succeed are never reported. - A security check before our page. If Cloudflare judges a visit suspicious, it shows its own check page ("Just a moment…") first. That page is not ours: it loads code from
challenges.cloudflare.com, it requires cookies, and it stores a clearance cookie (cf_clearance) so that you are not stopped again for a while. Clearing site data as described in section 7 removes that cookie along with everything else. - Scripts our network provider can add to the page after it leaves us. Cloudflare, which delivers this site, used to append two of its own scripts to responses: a bot-detection script and a visit-measurement script loaded from
static.cloudflareinsights.com. We have switched both features off, and the measurement site behind the second one is deleted. The security policy remains as the backstop: it allows a script written into the page only if it matches a fingerprint we published in advance, and a script file only from our own domain — so even if either were ever re-added, a browser that enforces that policy would refuse to load it and nothing would be sent. What keeps measurement off this site is that rule plus the switch, not a promise. - A second, report-only security policy. On some responses Cloudflare adds a policy of its own together with a reporting address,
csp-reporting.cloudflare.com, which your browser keeps for one day. It blocks nothing; it asks your browser to tell Cloudflare when a page tries to load a script or open a connection that the policy flags. The only thing on our pages that can set off such a report is a script Cloudflare itself added, described above. - A request made in advance. Cloudflare also asks your browser to fetch a page of this site before you open it, when you look as though you are about to, so that it appears instantly. Those requests go to our own domain only, but they do mean that a page you never actually opened can still appear in the request records described in section 8 of the Privacy Policy.
None of these carries advertising and none is used to build a profile of you. They come with the hosting rather than with anything you chose on this site, and the yes/no in our notice does not govern them — we would rather write that down than let the notice look as though it covers more than it does. The security check and the reporting notes exist to deliver and protect the site, which is why we treat them as necessary rather than as something to ask you about; the measurement script is a different matter, and the answer there is that it does not run. If we ever allow it to run, this page will say so first, and it will not run for anyone who has not agreed to it.
Links that take you off this site are a separate matter. When you click to buy a plan you are taken to the page of our payment provider, Paddle, which is the merchant of record for the sale; the same is true of the link to our Discord server. Those pages are not ours, they may use their own cookies, and what happens on them is governed by their own privacy policies — Paddle's is at paddle.com/legal/privacy. Nothing is sent to either of them unless you click.
6. Changing your choice
You can change your mind at any time. The button below clears your saved choice and shows the notice again. Consent you cannot withdraw is not valid consent, which is why this button also sits in the footer of the home page.
7. Deleting from your browser
You can also remove these values from your browser's own settings. Clearing site data for this domain removes all three, and the Cloudflare clearance cookie described in section 5 with them; the site keeps working; it simply forgets your answer to the notice and your language choice and falls back to the defaults.
- Chrome / Edge: Settings → Privacy and security → Third-party cookies → See site data →
w0a.app→ Delete - Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data →
w0a.app→ Remove - Safari: Settings → Privacy → Manage Website Data →
w0a.app→ Remove
If you browse in a private window, these values are discarded when you close it anyway. The language choice is no exception; it goes too.
8. Inside the desktop app
This policy covers only the w0a.app website. The desktop application is not a browser and stores no cookies on your device; it keeps files of its own on your computer instead. Your settings, its error, crash and start-up records, your saved benchmark runs and its other working files sit under %AppData%\w0a\; the backup of every registry value it changes sits under %ProgramData%\w0a\, where a standard user account cannot alter it before an elevated revert reads it back. Those files, and the few parts of them that ever leave your device, are listed one by one in sections 3 and 5 of the Privacy Policy.
9. Your rights and changes
The three values stored on your device do not identify you and we do not use them to build any profile of you. Storing and reading information on your device is nevertheless regulated in its own right — that is precisely why this page exists and why the notice asks for your answer. Your rights regarding personal data generally, and how to exercise them, are set out in section 12 of the Privacy Policy.
Age. w0a is not directed at children under 16, and if you are under 18 you should use the site and the application with the knowledge and consent of your parent or guardian. We cannot check anyone's age from a browser and we do not try to: reading this site requires no account and no personal detail. Today the notice's only effect is to record a yes or no in your own browser — no measurement runs and nothing reaches us either way — so the choice it offers puts no data at stake at present. If we ever do add measurement, we will not rely on a consent given by a visitor we have reason to believe is a child. The age rules in full are in section 13 of the Privacy Policy and in the Terms of Service.
If we update this policy, we will change the version number. If we make a change that requires fresh consent, the notice will be shown to you again.
Related documents: Privacy Policy · Terms of Service · Refund Policy