Draft

Unreviewed draft. The technical facts below are checkable and we have checked them. Whether they fully discharge the consent obligation, rather than merely reduce it, is a question for counsel and is not settled.

Legal · cookies

There is no banner because there is nothing to consent to.

This site sets no cookies of any kind and makes no requests to any other host. Not fewer than usual. None. The rest of this page is the detail, because “we respect your privacy” is what every cookie banner says.


01 — The inventory

Every category, and the answer for each.

Strictly necessary cookiesNoneThere is no login, no session, no basket and no server-side state. Nothing on this site requires a cookie to work.
Preference cookiesNoneNo stored theme, no dismissed banners, no remembered language. If you reload, the page does not know you were here before.
Analytics cookiesNoneNo analytics service is loaded at all, cookie-based or otherwise. No page views are counted by us, no events are recorded, no session is reconstructed.
Advertising or tracking cookiesNoneNo advertising network, no conversion pixel, no remarketing tag, no identity graph, no fingerprinting script.
Local storage, session storage, IndexedDBUnusedThe site writes nothing to browser storage. This is worth listing separately because a page can track you perfectly well without a cookie, and a policy that only mentions cookies is answering the wrong question.
Third-party requestsNoneEvery stylesheet, script, font and image is served from this origin. Nothing is fetched from any content delivery network, font service, video host or social platform.
Embedded contentNoneNo video players, no maps, no social widgets, no comment systems, no chat bubbles — the usual routes by which a site that sets no cookies of its own lets somebody else set theirs.
02 — Two things worth knowing

Where this could have gone wrong, and did once.

The fonts used to be somebody else's

This site's typefaces were originally loaded from a large third-party font service. That is the ordinary way to do it and it is what most sites do. It also handed that company the address, browser and referring page of every single visitor — on a website whose subject is not creating records.

The fonts are now served from this origin. The licence text ships alongside them, because retaining it is a condition of the open font licence rather than a courtesy. We mention the mistake rather than quietly presenting the fix, because it is a good example of how a privacy leak arrives: not through a decision to track anybody, but through a default nobody examined.

How you can confirm all of this

Open your browser's developer tools, load any page on this site, and look at the network panel and the storage panel. Every request should be to avano.app and the cookie store should be empty. You do not have to take our word for it and this is one of the very few claims we make where checking takes under a minute.

There is also a structural backstop: the site is served with a content security policy of default-src 'self', which means the browser refuses to load anything from another host. If somebody on our side ever added a third-party script by accident, the page would visibly break rather than quietly start leaking. That is deliberate — we would rather a mistake be loud.

03 — The one thing the site does collect

An email address, if you type one in.

The early-access form on this site sends the address you enter to us, and we keep it for one purpose: sending you builds. It is not a cookie and it is not tracking — it is a list you deliberately joined. It is also the only genuine record about a person that exists anywhere in this project, which is why it appears in the data inventory and in the law-enforcement policy.

If you would rather not be on a list at all, do not use the form. Write to hello@avano.app instead, or simply come back later.