Cookie policy
Last updated: 6 July 2026
This site does not track you. No analytics, no advertising cookies, no fingerprinting. We only set the few cookies the service cannot work without — here is all of them.
What a cookie is
A small text entry your browser stores and sends back to the site with each request — this is how a site can, for example, keep you logged in.
| Cookie | What it does | Type | Lifetime |
|---|---|---|---|
| operator_session | Keeps our own staff (the operator) logged in to the internal dashboard. It is only set after a login on /login — a regular visitor never receives it. | Strictly necessary | Session (expires server-side) |
| rl_<report-id> | Remembers that you entered the correct passcode for a protected client-report link (/r/…). It is only set there and is valid for that one report only. | Strictly necessary | 90 days, renewed on each view |
Bot protection (Cloudflare Turnstile)
If bot filtering is enabled on the free-audit form, Cloudflare may set its own cookie during the check, strictly to tell humans from bots. It is not usable for marketing; Cloudflare's own privacy policy governs it.
The notice itself
That you dismissed the cookie notice is remembered in your browser's localStorage (key: ave_cookie_notice) — that is not a cookie, and it is never sent to our servers.
Why we don't ask for consent
Strictly necessary cookies are exempt from the consent requirement under the GDPR and the ePrivacy rules — that is why there is no "Accept / Reject" theatre here. If we ever introduce analytics, we will ask first, and this page and the notice will change accordingly.
Questions? Write to hello@avestudio.pro. How we handle personal data is described in the privacy policy.