Privacy
What trsf.it collects and why. Last reviewed: .
First-party cookies only
trsf.it uses a small number of first-party cookies that are strictly necessary for the site to work and to improve it. We do not use third-party cookies, advertising trackers, or fingerprinting scripts.
- ab_hero_cta — remembers which A/B test variant you saw on the homepage so the page does not flicker when you load it. It is a server-side,
httpOnlycookie and expires after 30 days. - auth_email — set only if you choose to sign in. It stores the email address from the identity provider you used. No password or profile data is stored on our servers.
- auth_state, auth_nonce, auth_verifier — temporary, short-lived cookies used only during the OAuth sign-in flow to prevent CSRF and enable the exchange.
First-party analytics
We measure our homepage A/B test with our own POST /api/events endpoint. Events are sent with navigator.sendBeacon and stored in our own first-party database. They contain only the event type, variant, timestamp, and basic request metadata. We do not send any data to Google Analytics, Tag Manager, or other third-party analytics services.
Why there is no consent banner
Because every cookie and analytics event is first-party, necessary for the site to function or to improve it, and never shared with third parties, we do not show a separate consent banner. You can delete or block these cookies in your browser at any time; some features (like signing in or A/B variant consistency) may then stop working smoothly.
What we do not do
- No third-party advertising or tracking cookies.
- No Google Analytics, Tag Manager, or similar third-party analytics.
- No sale or sharing of personal data with third parties.
- No server-side storage of files transferred with the QR tool; the relay only sees opaque encrypted chunks.