ToolsOps

Cookie policy

Last updated: 2026-05-13

1. What are cookies?

Cookies are small text files a website stores in the visitor's browser. They are used to keep sessions, remember preferences or measure usage. Technically similar alternatives (localStorage, sessionStorage, etc.) are covered by this policy with the same safeguards as cookies.

2. Current state: technical cookies and Cloudflare Web Analytics

ToolsOps in production does not install tracking or advertising profiling cookies. In particular:

  • Analytics: the site uses Cloudflare Web Analytics to measure aggregated traffic and performance (see section 5). There is no Google Analytics, Plausible, Matomo or equivalent.
  • Advertising and monetization: not part of this analytics block. If contextual advertising or AdSense is enabled in the future, this page will document the provider, the cookies and technologies it uses, the purpose, the duration and the consent mechanism (CMP) under GDPR / ePrivacy / Spanish LSSI.
  • Newsletter / forms: none exist.
  • Tool inputs: data you enter into any tool (JSON, chmod values, etc.) is never stored in cookies or in browser local storage, and is never sent to the analytics beacon. It is processed in memory and discarded when you close the tab.

3. Strictly necessary technical cookies

The public site does notinstall session technical cookies for its operation. If any are introduced in the future (e.g., to remember the visitor's language preference) they will be documented here with name, purpose and duration. Strictly necessary technical cookies are exempt from prior consent under Spanish LSSI.

4. Cloudflare cookies in protected environments

The staging environment (not public) is protected by Cloudflare Access. This mechanism installs Cloudflare-owned cookies (CF_AppSession, CF_Authorization) in the authenticated user's browser to maintain the authentication session. These cookies only appear on staging.toolsops.dev, which is not publicly accessible. In production (toolsops.dev), Cloudflare is used solely for hosting and CDN; no Access cookies are installed on the public domain.

Cloudflare may additionally install the __cf_bm cookie for bot mitigation while delivering assets. Cloudflare classifies it as a security technical cookie. More details in Cloudflare's privacy policy.

5. Cloudflare Web Analytics

Active in production. ToolsOps uses Cloudflare Web Analytics to measure aggregated traffic and performance. The beacon served from static.cloudflareinsights.com records aggregated metrics such as page views, referrer and load timings. It does not receive the content entered into the tools, does not emit custom events and is not used to personalize advertising.

  • What is collected:aggregated metrics. According to Cloudflare's official documentation, the beacon collects only timing metrics and minimal performance information, with no visitor-identifying data.
  • What is NOT done: individual end users are not tracked across sites (Cloudflare wording: “Cloudflare does not track individual end users across our customers' Internet properties”). No custom events are emitted. Content entered into the tools is not sent. The analytics is not used to personalize advertising.
  • Cookies: Cloudflare classifies Web Analytics as privacy-first analytics without tracking cookies. This policy will be updated with a concrete cookie list if Cloudflare ever changes that documented behaviour.
  • Retention: per Cloudflare, “We retain unsampled beacon data for the past 7 days, after this point data is aggregated down to around 10%”.
  • Known limitation:“The analytics beacon is blocked by ad-blockers (including adblockplus, Brave, DuckDuckGo extension, etc)”. The stats do not represent 100% of visits.
  • Verification: open your browser DevTools on the Network tab while browsing https://toolsops.dev. You will see a request to the Cloudflare Web Analytics provider. Searching the served HTML for the beacon domain is not reliable as a check because this very page mentions it in the explanatory copy above.

Cloudflare Web Analytics is not combined with advertising or AdSense. If contextual advertising or AdSense is enabled in the future, it will follow a separate flow documented in this policy, behind a consent management platform (CMP) compatible with the TCF v2.2 framework and Google Consent Mode v2 in EEA / UK / Switzerland, under GDPR and national law. Cloudflare privacy policy: cloudflare.com/privacypolicy.

6. If we enable advertising or other providers

Before loading any advertising script or any provider that uses additional tracking cookies, this policy will be updated with:

  • Provider name (e.g., Google AdSense).
  • List of specific cookies with purpose and duration (e.g., __gads, NID, etc.).
  • Category (technical, analytics, advertising, personalization).
  • Legal basis and link to the provider's policy.

Activation will sit behind a consent management platform (CMP) compatible with TCF v2.2 + Google Consent Mode v2 in EEA / UK / Switzerland.

7. Managing your cookies

You can configure your browser to block, limit or delete cookies at any time from its preferences panel. The site will still work without them. When the consent banner is available, you will also be able to revoke your preferences from the site itself.

8. Contact

For enquiries about cookies or personal data processing, write to privacy@toolsops.dev.