Cookie Policy
The shortest day in this set of documents: one page load, traced from the moment your browser asks for a page to whatever is still on your device once you have gone.
In force from 15 August 2026 · third edition · TIMETIED LTD, Company No. NI740404
Before the request: what this page covers
This page deals with browser storage on gettimetied.it.com, published by TIMETIED LTD (company number NI740404, registered in Northern Ireland). It runs beside the Privacy Policy, which walks a whole day of using the product, and the Terms of Use, which covers the agreement between us.
The headline, before the detail: nothing on this site tallies your visits, builds a profile of you, or sells you anything. These are static files. The only items that can ever be written to your device here are security items placed by the company that serves the site, and only when its protections engage. Everything below explains that position properly and hands you the controls regardless.
The mechanism, in one paragraph
A cookie is a short scrap of text a site hands your browser with a request to hold on to it. On the next visit the browser hands it back, which is how a site recognises a continuing session, remembers a preference or tells a person apart from a script. One set by the site in your address bar is called first-party; one set by some other domain whose content is embedded in the page is third-party. A session item dies with the browser window; a persistent one sits there until its expiry date arrives, or until you sweep it away.
Several other mechanisms achieve much the same thing, and this page treats them identically: local and session storage, where a page keeps named values in the browser rather than attaching them to every request; IndexedDB, a larger in-browser database for web applications; pixels and beacons, minute images or scripts loaded for no reason except to record the fact that something was opened; and, on a phone, the storage an app keeps in its own private area, which is dealt with further down. Read "cookie" below as shorthand for the lot.
Which rules apply, and why no banner appears
Two bodies of UK law govern this. Regulation 6 of PECR — the 2003 electronic communications rules — says that putting information onto somebody's device, or reading back whatever already sits there, needs both a clear account of the purpose and that person's consent — unless what gets stored is strictly necessary for delivering a service the person actually requested. Security machinery that keeps a site on its feet sits inside that exemption. Measurement and advertising do not, ever.
Where consent is needed, the UK GDPR sets the bar it has to clear: freely given, specific, informed and unambiguous, shown through a clear affirmative act. Boxes ticked in advance, agreement inferred from scrolling, and "by continuing you accept" notices all fall short. Withdrawing must be as easy as agreeing, and refusing must be as easy as accepting.
Since the only items that can appear here are strictly necessary ones, no consent banner is required and none is shown. Interrupting your reading to collect permission for something we are not doing would be theatre. That is a description of how this site is built rather than a technicality being leaned on — the table below is what makes it true, and it is kept accurate.
The five categories, and where we stand on each
What actually lands on your device
These pages are static files delivered through Cloudflare. The site itself writes nothing to your device: the small amount of JavaScript it loads adds a hairline border to the header once you scroll and opens the menu on a narrow screen, and it touches neither cookies nor local storage nor IndexedDB. What may appear comes from Cloudflare's security layer, and only where that layer is doing something.
Cloudflare handles this material as our processor, for hosting and for security. The lawful basis and the retention behind it are set out at 06:44 in the Privacy Policy.
The one request that leaves our domain
For completeness, one part of every page is fetched from somewhere else: the display and body typefaces arrive from Google's font service — fonts.googleapis.com for the stylesheet, then fonts.gstatic.com for the files. Serving a typeface writes nothing to your device and carries no identifier from us. It does mean, as any request to any server would, that your IP address and browser string reach Google in order for the file to come back. Blocking those two hostnames — in the browser or with an extension — leaves every page here perfectly readable in whatever typeface your system falls back to.
Nothing else is embedded. No video player, no map, no social widget, no chat bubble, no comment system, no tag manager, no split-testing tool, no advertising script.
What is deliberately absent
- Measurement. No analytics runs on this website — not the well-known hosted product, not a self-hosted alternative, not one of the newer tools that advertise themselves as needing no cookies. There is no visitor dashboard here for anyone to open, and the only usage information reaching us at all is the aggregate request data Cloudflare produces as a by-product of delivering and defending the site.
- Advertising. None, anywhere. No ad network, no conversion pixel, no remarketing tag, and nothing sold or passed to advertisers or data brokers.
- Email. Our messages carry no tracking pixel, so whether you opened one is not something we are in a position to know.
The same question inside the apps
A mobile app has no browser cookies, but it does keep things on the handset, so the equivalent list belongs here. The TimeTied apps store your plans, blocks, tasks, focus sessions and settings in the app's own private area on the device; a randomly generated install identifier; a session token where you are signed in; and your preferences. None of that is an advertising identifier — neither the iOS advertising identifier nor its Android counterpart is collected, and no advertising SDK is compiled in. The full account, including a permission-by-permission table, sits at 07:30 in the Privacy Policy.
Your browser has the last word
Whatever any site does, the last word is your browser's. You can refuse cookies outright, permit them only where you choose, or clear what is already there.
Menu paths shift between versions; where one no longer matches, searching your browser's own help for "cookies" will find the current route. Clearing cookies reaches every site rather than only this one, so expect to be signed out in a few places afterwards.
Blocking everything does not break this site, because nothing here depends on it. The single practical effect is that Cloudflare's security layer may lose its record that you passed a challenge, so a check may appear more often than it otherwise would. Every page stays fully readable.
Two signals a browser can send
Do Not Track was the first of them: a header asking sites politely not to follow you about. It never hardened into an enforceable standard, and most of the web disregards it. Since no visitor here is followed to begin with, the signal finds nothing to switch off and alters none of this site's behaviour.
Global Privacy Control came later, and expresses an objection to personal information being sold or passed around. UK law puts no present obligation on a site to honour it. What it asks for is already our default: we sell nothing, we pass nothing around, and no inessential storage gets written. Should that ever shift, a GPC signal would count as a valid objection and the inessential items would stay unset.
If we ever added something
Suppose analytics started to look genuinely useful. Every one of the following would happen before a single non-essential item was written:
- a consent mechanism that asks first, with the technology inert until you agree;
- refusing made exactly as easy and as prominent as accepting, with nothing pre-ticked and no design nudging you toward yes;
- controls split by category, so agreeing to one thing never quietly agrees to the rest;
- a route to change or withdraw the answer later that is no harder than giving it;
- this page updated in the same release, with the new item added to the table at what actually lands on your device, naming who sets it, what for, of what type and for how long;
- the effective date and version at the top of this page moved to match.
Tracking will not be slipped in first and documented afterwards. This page changes when the site does or the rules do, and the dates at the top always describe the current version. Version 3.0, effective 15 August 2026, restructures this policy around a single page load and replaces the edition dated 5 August 2026.
Asking us about any of this
Questions about browser storage, or about anything written above, go to hello@gettimetied.it.com. Unhappy with the answer you get? The Information Commissioner's Office takes complaints, and its address and helpline are at the ICO section of the Privacy Policy.