DOC. TRS-L03 — LEGAL / COOKIE POLICY — REV 2026.08
Cookie Policy
K1Top claim: nothing here is watching you read
Claim K1. No measurement, advertising, attribution or social component runs on tresonant.co, and there is no consent banner because there is nothing to consent to.
Argument. A consent banner exists to license the non-essential. Where a site carries nothing non-essential, the banner is theatre and its absence is the honest signal. This domain carries no analytics tag, no advertising pixel, no attribution script, no embedded social widget and no fingerprinting logic. The only thing that may ever be written to your browser by this domain is a strictly necessary security token issued by our edge provider while it decides whether a request is a person or a bot — and the strictly necessary exemption, described at K3, is precisely what that token was written for.
Evidence. Read the source of any page on this domain: there is no third-party script tag to find. Your browser's storage inspector will show you the same thing from the other direction.
K2What counts as storage on your device
Claim K2. The law reaches every mechanism that writes to, or reads from, your device — not only the mechanism called a cookie.
Argument. A cookie is a short text record a site asks your browser to keep and return with later requests to the same domain. It may be issued by the site you are on or by a different domain whose content the page pulls in, and it may vanish when the tab closes or persist until an expiry date passes. Around that sits a family of equivalents that regulators treat identically: local and session storage, which hold values without attaching them to every request; IndexedDB and cache storage, larger structured stores used by offline-capable software; pixels and beacons, one-pixel images or scripts whose only job is to record that something was opened; fingerprinting, which identifies a device by assembling its characteristics and stores nothing at all; and software development kits inside mobile applications that read device identifiers. Wherever this document says cookie, read it as covering that whole family.
K3The rule that governs it
Claim K3. Two instruments apply together, and the exemption we rely on is the narrow one rather than the convenient one.
Argument. Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 says that writing to, or reading from, a user's terminal equipment requires clear information about why, plus that user's consent — unless the operation is strictly necessary to deliver a service the user explicitly asked for. Strictly necessary means the service will not work without it. It does not mean useful to the operator, and it does not stretch to measurement, however privacy-respecting the measurement claims to be. That is why analytics needs consent and a bot-detection token does not.
The UK GDPR sets the standard any such consent must meet: freely given, specific, informed, unambiguous, expressed by a positive action, as easy to withdraw as to give, and obtained before anything non-essential is written. Scrolling is not consent. A pre-ticked box is not consent. A wall that charges you your data for entry is not consent. Where device storage also involves personal data, a lawful basis under Article 6 is needed as well; for the security token described below that basis is Article 6(1)(f), our interest in a site that survives contact with automated traffic.
K4The present state of this domain
Claim K4. The full inventory of what this domain may store fits in one row.
| Item | Set by | Why it exists | Lifetime | Consent |
|---|---|---|---|---|
| Bot-management token | Cloudflare, our edge and security provider, acting as our processor | Separating human requests from automated abuse, so the site stays reachable | Session, or a short period measured in hours | Not required — strictly necessary |
Argument. That token holds an opaque value. It does not name you to us, is not read for measurement, profiling or advertising, and is not passed to anybody for a purpose other than keeping the site standing. The request data alongside it is handled as described in the website clause of our Privacy Policy, and the provider's role and location appear in the recipient table at C14 there.
What is absent, and stays absent. No analytics of any brand. No advertising or retargeting identifier. No conversion or attribution tag. No embedded video, map or social component that would set storage of its own. No cross-site profile. No sale, sharing or exchange of anything read from your device, for the plain reason that nothing is read from it.
K5Typefaces, and the one outbound request a page makes
Claim K5. A page on this site reaches out to exactly one other domain, for lettering, and we would rather say so than let you find it in a network trace.
Argument. Three families set this document — a sans for headings, a sans for body text and a monospace for the technical marks — and they are fetched from Google's font hosting when a page opens. Fetching a file from another domain is not device storage and needs no consent under Regulation 6, but it does mean your browser makes a request that provider can see: an address, a user-agent string, a referring page. Google states that its font service writes no cookie, and the request is not used to build an advertising profile. Once your browser has the files it caches them, so the request does not repeat on every page.
If you would rather it never happened, a content blocker or a strict browser mode will stop the request. The pages then render in whatever your system supplies, which changes the typography and nothing else.
K6Turning storage off in your browser
Claim K6. Control sits with you and does not depend on a preference centre we operate.
Argument. Every current browser exposes two switches in its privacy settings: one that clears what is already stored, and one that decides what may be stored in future, usually with a separate position for content loaded from other domains. Private or incognito windows discard everything at the end of the session. Extensions can go further and block requests before they leave. Because the vendors move these settings between versions, the reliable route is your browser's own help documentation rather than a screenshot in a policy that ages badly.
What it costs you here. Blocking storage on this domain removes the bot-management token. Pages continue to render normally; the security layer simply has less to work with and may occasionally interpose a challenge. Elsewhere on the web, blocking everything tends to log you out of things, so a per-site rule usually beats a global one.
K7Browser signals that ask sites not to profile you
Claim K7. Both privacy signals are moot on this site, and we say why rather than staying quiet about it.
Argument. Two headers exist for this purpose. The older one, Do Not Track, was never given a legal effect in the United Kingdom and has been withdrawn from several browsers as unenforceable. The newer one, Global Privacy Control, carries a refusal where personal information would be sold or shared onward, and it does have statutory force in several United States jurisdictions.
Neither alters anything here, because neither has a target: no profile is being assembled that you could refuse, and nothing about you is passed onward for value. Were we ever to introduce something non-essential, a Global Privacy Control header would be treated as consent withheld, and no such storage would be written for a browser announcing it.
K8On-device storage inside published applications
Claim K8. Applications we publish store what the software needs to run and nothing built for tracking.
Argument. A mobile application does not use browser cookies; it uses the operating system's own storage. Ours keep a session or authentication token so you are not asked to sign in on every launch, your local settings and cached views so the software opens where you left it, a queue of items waiting for connectivity, and a per-installation identifier used to route notifications and to hold a session together. That identifier belongs to the installation, resets when the application is removed and reinstalled, and is not the device advertising identifier.
No advertising, attribution or data-broker component is embedded. Neither Apple's Identifier for Advertisers nor the Google Advertising ID is read. Nothing follows you into other companies' apps or websites. Deleting the application clears its local storage; it does not close your account, for which see the account deletion clause at C21 of our Privacy Policy.
K9What would happen if this position changed
Claim K9. Anything non-essential would arrive with a request, not with a revision.
Argument. We have no plan to add measurement. If that ever changed — an ordinary business decision, not a scandal — the sequence would be fixed in advance. A consent mechanism would appear before anything was written, with refusal offered as prominently as acceptance and a route to withdraw afterwards that is no harder than the route in. The table at K4 would be updated to name each item, its issuer, its purpose and its lifetime, and the version block below would carry a new date. Nothing non-essential would be set for a reader who had not agreed to it, and continuing to read would never count as agreement.
K10Document control and contact
Questions about anything described here, including a request to see what your browser is holding from this domain, go to sales@tresonant.co. Complaints about device storage in the United Kingdom can also be taken to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, on 0303 123 1113.
DOC. TRS-L03 · Cookie Policy · Issue 3.0 · Effective 15 August 2026 · Supersedes issue 2.0 of 5 August 2026. Companion documents: TRS-L01 Privacy Policy and TRS-L02 Terms.