Cookie policy
This page lists what dotvitals stores in your browser right now — not a generic template of cookies a site like this might one day use.
Last updated
There is no consent banner, and that is not an oversight
dotvitals shows no cookie banner because nothing on the site needs consent. Under the EU and UK ePrivacy rules, consent is required before storing or reading anything on your device that is not strictly necessary for a service you asked for. dotvitals sets two cookies, both strictly necessary, and runs analytics that store nothing on your device at all.
Showing a banner anyway would be worse, not better: it would ask you to make a choice that changes nothing, and it would train people to click through consent dialogs without reading them. The honest alternative is to say plainly what is set and why, which is the rest of this page.
You can check that rather than believe it. Open your browser's developer tools on any page of this site, look at storage and at the network requests, and compare what you find with the list below.
The cookies dotvitals sets
Two, both first-party, both strictly necessary, neither used for advertising or for tracking you across other sites:
- dv_sid — an anonymous session marker. It holds a random, signed value and nothing else: no name, no address, no history. It exists so rate limits apply to one browser rather than to everyone sharing your network address, and so you can return to a scan you just started. HttpOnly, SameSite=Lax, Secure, expires after 30 days.
- dv_clr — a short-lived proof that you passed a human-verification challenge, so you are not challenged again on every request. HttpOnly, SameSite=Lax, Secure, valid for 30 minutes, and shorter when the service is under load.
Blocking either is allowed and the site keeps working, but you may be challenged more often, and you will be rate limited alongside everyone else on your network rather than on your own budget.
One thing that is not a cookie
If you use the light/dark theme switch, your choice is saved in your browser's local storage under dv-theme. It never leaves your browser, is never sent to us, and holds one word. Clearing your site data removes it and the site follows your operating system's preference again.
Analytics without cookies
dotvitals measures page views, load performance and a fixed list of product events. None of it sets a cookie, reads a cookie, or writes anything to your browser's storage; none of it fingerprints your browser; and none of it can identify you or follow you between sites.
Because nothing is stored on your device and no personal data is collected, it needs no consent under the ePrivacy rules — which is the second reason there is no banner. The privacy policy lists exactly which events are recorded and what each may and may not carry: in particular, never a domain you scanned, never a full URL, and nothing whatsoever from the email header analyzer.
No advertising cookies at launch
At launch, dotvitals sets no advertising cookies. No ad script, no tracking pixel, no consent-management platform and no tag manager loads on any page.
That is a statement about the current state of the site, not a permanent promise: the about page explains the plan to fund the site with advertising once traffic supports it.
What will change when advertising is enabled
Enabling ads changes the consent position completely, and none of it will happen quietly. Before a single ad script loads:
- A certified consent mechanism will be in place. Serving personalised ads to visitors in the EEA, UK and Switzerland requires a Google-certified consent management platform integrated with the IAB Transparency and Consent Framework; a home-made banner does not satisfy that, and we will not pretend otherwise.
- No advertising cookie will be set, and no ad script will load, before you have made a choice, if you are in one of those regions.
- The dialog will offer consent, refusal and manage-options with equal prominence, and will name every third party that may receive personal data before you are asked to decide.
- A "Change your choice" link will appear in the footer and will reopen the dialog at any time, so a decision can be reversed without clearing site data. Until then, that link has nothing to open, which is why it is not there.
- Refusing will not block anything. You will still get the site and every scan; only the kind of ads changes.
- This page and the privacy policy will be updated to name the network, the consent platform and every cookie they set, before they go live rather than after.
The placement rules do not change either: no ads on loading, error or empty-state screens, none between the input box and your first result, and none at all on the email header analyzer page, which processes something too sensitive to have third-party scripts anywhere near it.
Cookies set by others
dotvitals embeds no third-party content — no videos, no social widgets, no fonts loaded from another origin — that could set a cookie on its own behalf.
Cloudflare, which serves the site and provides the human-verification challenge, may set its own cookie as part of that protection, for example to remember that a browser passed a challenge. That is necessary for the site's security and is not used for advertising.
Browser controls
You can block or delete cookies through your browser's own settings at any time, and you can use a tracker blocker on this site without anything breaking. Because the two cookies above are used for rate limiting and scan continuity, blocking them may mean more human-verification challenges.