Cookies only
if you say yes.
This site uses Google Analytics, but only after you have given permission. Below is what happens then, what happens without permission, and how to withdraw your choice.
Nothing is set before you say yes
This site uses Google Analytics to see which pages get read. That sets cookies, which is why a notice with a real choice appears on your first visit.
As long as you choose nothing, or decline, the script is not loaded and not a single request goes to Google. Declining costs you nothing: the site works exactly the same and no functionality disappears.
Declining is as easy as accepting, and your choice holds until you withdraw it below.
What Google Analytics sets if you accept
Cookies starting with _ga. They contain a randomly generated number that lets Google recognise a repeat visit from the same device. There is no name, email address or other directly identifying detail in them.
What gets recorded: which pages you view, for how long, which referring site you arrived from, and roughly which country and what kind of device. Your IP address is processed in truncated form.
Google is the processor for this data. I do not use it for advertising, do not combine it with other data and do not sell it.
Change your choice
Below you can see what you chose earlier and withdraw that choice. The notice then appears again and you decide afresh.
What is stored even without consent
Two things, both only on your own device. Your preference for the light or dark theme, in localStorage under the key 'theme'. And your answer to the consent question, under 'wf-analytics-consent', because otherwise I would have to ask again on every page.
Neither is a cookie: they are not sent to the server and I cannot reach them. Under the ePrivacy rules this counts as strictly necessary, functional storage that needs no consent. Want them gone? Clear the site data in your browser.
Fonts, video and third parties
The fonts are served from this site itself, not from Google Fonts. So no request carrying your IP address goes to an external party.
The intro video sits on this site rather than on YouTube or Vimeo. Those platforms set cookies as soon as a video comes into view; that does not happen here.
There are no embedded maps, chat widgets or like buttons. A strict Content Security Policy blocks requests to third-party domains, with Google Analytics as the only allowed exception.
Server logs
The hosting provider keeps technical logs needed to serve and secure the site: IP address, timestamp, page requested and browser type. That happens on every website and is not a cookie.
Those logs are not used to track visitors or build profiles, and are deleted automatically after a short time.
Cookies in software I build for you
If I build an application with logins, a session cookie is necessary to keep you signed in. That counts as a functional cookie and needs no consent.
If you want analytics or ad tracking in your project, I build the same mechanism you see here: load nothing before someone has said yes, and let them withdraw it at any time.
Questions about this? Email bas@webframer.nl. I am a developer, not a lawyer: for a watertight policy, legal advice remains sensible.