Legal
Cookie policy.
The complete list. Four small things, all of them there to make the site work or to remember a preference you set — no advertising, no analytics, nothing that follows you anywhere else.
What a cookie is
A cookie is a small text file a website asks your browser to keep and send back on the next request. It is how a site can tell that two page loads came from the same person — which is what makes staying signed in possible, and what makes tracking possible too. The difference is entirely in what the site does with it.
We use cookies only for the first kind of thing.
Every cookie we set
| Name | What it does | How long | Type |
|---|---|---|---|
sessionid |
Keeps you signed in as you move between pages. Only set once you log in. | 14 days, or until you log out | Strictly necessary |
csrftoken |
Proves a form was submitted from our page and not forged by another site. | 1 year | Strictly necessary |
messages |
Carries a one-off confirmation like “message sent” across a redirect, then deletes itself. | Until the message is shown | Strictly necessary |
All three are first-party — set by this site, readable only by this site, never sent to anyone else. None of them contain your name, your email address or anything about what you looked at.
Things stored in your browser
Two preferences are kept in your browser's local storage rather than in a cookie. The difference matters: local storage is never sent to our server, so these stay entirely on your own machine and we cannot read them.
| Name | What it does | How long |
|---|---|---|
kk-theme |
Remembers whether you chose the light or dark theme. | Until you clear your browser data |
kk-cookie-notice |
Remembers that you have seen the notice at the bottom of the page, so it stops appearing. | Until you clear your browser data |
Why we do not ask permission
You have probably noticed that the notice at the bottom of the page has one button and no choices. That is deliberate.
The law requires consent for cookies that are not strictly necessary — analytics, advertising, anything that profiles you. Cookies that are needed to deliver a service you asked for do not need consent, and everything in the table above is in that category: without the session cookie you cannot log in, and without the CSRF cookie no form on the site can be submitted safely.
So a banner asking you to accept or reject them would be offering a choice that does not exist — reject them and the site stops working. Rather than perform that, we tell you what is there and let you get on with it. If we ever add anything non-essential, this page will change and you will be asked properly, with a real choice and a real refusal.
Third parties
No third party sets a cookie on this site. There is no analytics, no tag manager, no advertising pixel, no social button, no embedded video and no chat widget.
One third party is nevertheless involved in loading a page: our typefaces come from Google Fonts, so your browser fetches those files from Google and Google sees your IP address in the process. No cookie is set by it, and nothing else is shared, but it is a request that leaves our server, so we say so here and on the privacy page.
Turning them off
Every browser lets you block or delete cookies, usually under Settings → Privacy. You can also browse in a private window, which throws everything away when you close it.
Blocking cookies on this site is entirely allowed and most of it will work fine — you can read every public page. What will not work is logging in, and any form that needs to prove it came from us. That is a consequence of how the web works, not of anything we have done.
Changes
If the cookies change, this page changes with them and the notice at the bottom of the site reappears so you are told rather than left to notice. The date at the top says when it last happened.