CNFans Sheet Path
← IndexReviewed

Privacy: what is stored, and what never leaves your browser

This is a static site. There is no account system, no server-side database and no place for a form to write to, which removes most of the usual reasons a policy is long. What remains is worth stating precisely: a small amount of data stays in your browser so tools remember what you typed, and images are loaded from the catalogue’s own domain, which necessarily sees the request.

What this policy covers

This policy describes what happens to information when someone opens a page on this site. It covers the pages, the browser tools and the outbound links, and it is written against how the site is actually built rather than against a template: the pages are pre-built files served from an edge network, there is no account system, no server-side database and no form that writes anywhere. Almost every question a privacy policy normally answers is therefore settled by architecture, and what remains is worth stating precisely.

The site is published in English and served worldwide. Nothing here is directed at a specific country’s requirements, and no attempt is made to build a profile of a reader, because the site has no mechanism that could. If a sentence below ever stops matching what the site does, the policy is wrong and should be treated as wrong; the correction route is at the end of this page and in /brief.

What is not collected

No name, postal address, email address, telephone number, payment detail or government identifier is collected by this site, because there is nowhere for such a value to be entered. There is no registration, no login, no comment facility, no newsletter and no contact form; the only way to send something to the desk is to write an email, which means a reply address exists only if the sender chooses to provide one. No behavioural profile is assembled, no advertising identifier is created, and no data is sold, rented or shared for marketing.

Location is not requested. The browser’s geolocation permission is explicitly disabled by the site’s own response headers, alongside camera and microphone, so no page can prompt for them. Currency and weight figures entered into a tool are not transmitted, because the tools compute inside the page. Nothing typed into any tool on this site leaves the browser tab it was typed in unless the reader copies it out deliberately.

What the network sees when a page is requested

Serving a page requires a request, and any request carries the address asked for, an internet protocol address, a time and a description of the browser. Those values are handled by the hosting and edge network that delivers these files; this site does not run its own log collection and its pages contain no analytics code. The desk does not use provider records to identify, single out or profile a reader, and it has no interest in who is reading which page.

Where the provider keeps such records, their retention and handling fall under the provider’s own terms rather than this policy, and the desk cannot change them. Readers who wish to reduce what any server sees can use a browser configured to block third-party requests or a privacy-preserving network; the pages are static and remain fully readable in that configuration, because no part of the content depends on tracking or on scripts from another origin.

Local storage: what stays in your browser

One class of data is stored in the reader’s own browser: the tick state of the checklists that appear on step and tool pages. The keys used for this begin with csp:checklist:, followed by the name of the page, and each key holds nothing more than a short list of true and false values describing which boxes were ticked. No identifier, timestamp or page history accompanies them, and the values are never sent anywhere; they exist so that a half-finished checklist survives a reload.

Values typed into a workbench tool are held in the page for as long as that page is open and are not written to storage, so reloading a tool restores its defaults. Clearing site data, or using a private window, removes the checklist keys immediately and permanently, and the checklists simply start empty. Should a tool ever remember an input between visits, it would use the same csp: prefix, and the change would be recorded here with a new effective date.

Catalogue images and other third-party requests

Listing images shown in the sample table and on some note pages are loaded from the catalogue’s own image host rather than from this site, so opening a page that displays them causes a request to that host. As with any image embedded from another domain, the operator of that host can see the request, including the internet protocol address it came from, the time, the browser description and the fact that the image was requested.

The site-wide referrer setting sends only this site’s origin with such requests, not the address of the page being read, so the image host learns which site is displaying the image rather than which article. The desk receives no report of those requests and cannot see them. Everything else a page needs, including styles, scripts and icons, is served from this site’s own origin, and no font, advertising frame or analytics beacon is fetched from anywhere else.

Cookies

This site sets no advertising cookies and no analytics cookies, and it loads no advertising or analytics service that could set them. The content security policy in force permits scripts from this site’s own origin only, which is a stronger statement than a promise: a third-party tracking script could not execute on these pages even if one were added by mistake. Browsers report the site’s own cookie storage as empty on a fresh visit.

The hosting and edge network that delivers the files may set a short-lived security cookie of its own as part of filtering abusive traffic. That cookie is set by the infrastructure provider, is not read or used by the desk, and can be blocked without affecting any page or tool. Readers who block all cookies will find every page, calculator and checklist working normally, because none of them depends on a cookie being present.

Retention and deletion

There is no server-side account or record to delete, so deletion is a browser action rather than a request: clearing site data for this domain removes the checklist keys described above, and clearing the whole browser store removes everything else this site ever placed there. Because tool values are never written to storage, there is nothing further to remove on that side.

Correspondence is the one exception. An email sent to the desk exists in an inbox and is kept while the correction or question is being handled, together with the reply. A sender who wants that correspondence deleted can ask for it in a follow-up message, and the message and its replies are removed once the matter is closed. Senders who prefer not to leave a permanent reply address can write from an address they are willing to discard.

Children

This site is written for adults arranging their own purchases and is not directed at children. It collects nothing from anyone, so there is no separate category of children’s data held here, and no feature that would attract a young reader: no games, no accounts, no social functions and no messaging. The subject matter concerns import charges, customs paperwork and shipping rates, which are adult concerns.

If a parent or guardian believes that a child has sent correspondence to the desk, a message to the address at the end of this page will have it deleted without further questions. No verification of age is performed anywhere on the site, because no feature requires it; a reader of any age can open every page, and nothing about the visit is recorded by the desk.

Readers outside the country where the site is served

The files are served from an edge network, which means a copy may be delivered from a location near the reader rather than from one fixed country. Caching of that kind reduces the distance a request travels but does not change what the request contains. Email sent to the desk passes through the mail providers of both the sender and the recipient, so correspondence may be stored or processed in a country other than the sender’s own.

No transfer of personal data for commercial purposes takes place, because no personal data is gathered in the first place. Readers subject to regimes that grant rights of access, correction, portability or objection over personal data should note that this site holds no personal data about them to which those rights could attach; the only data that exists is inside their own browser or their own mailbox. Questions about that position are welcome at the address below.

Changes, effective date and contact

This policy takes effect on 2026-09-29 and is reviewed on the same weekly cycle as the rest of the site. A change that affects what is stored, what is requested or who can see it is published here with a new effective date and entered in the change log at the foot of /ledger, so a reader can see what moved rather than discovering a silent rewrite. Wording changes that do not alter behaviour are made without a version note.

Questions about this policy, requests to delete correspondence, and reports of anything here that does not match what the site actually does can all be sent to [email protected]. A reply is promised within seven days. The method behind the site’s figures, including the labels used for values that could not be confirmed, is described in /brief, and the way outbound links work is described in /disclosure.