Legal

Cookie Policy

A short list, because it is a short list. One cookie keeps you signed in. Two analytics tools run, and you can turn them off in section 4 — after which neither script is loaded. There are no advertising trackers on this site.

Last updated 29 August 2026

1. What a cookie is here

A cookie is a small file a site stores in your browser. We also use two things that are not strictly cookies but do a similar job — browser storage set by our analytics provider, and the script that records how pages are used. This page covers all of them.

2. What we set

NameSet byWhat it doesLasts
fos_sessionFounders 8 (first-party)Keeps you signed in and records which step of setup you are on. Signed and HTTP-only, so scripts cannot read it. Without it the app cannot work.7 days
_clckMicrosoft ClarityTies this browser to a Clarity user id so repeat visits are not counted as new people. Only set if you allow analytics.1 year
_clskMicrosoft ClarityJoins the pages you view into a single session recording. Not set once you turn analytics off.1 day
_gaGoogle AnalyticsDistinguishes one browser from another so visits are counted once. Not set once you turn analytics off.2 years
_ga_<id>Google AnalyticsHolds the session state for this property. Not set once you turn analytics off.2 years

3. Strictly necessary

fos_session is strictly necessary. It carries no advertising identifier and is not shared with anyone. It is set when you sign in and cleared when you sign out. There is no way to use an account without it, so it is not something you can opt out of and still be signed in.

4. Your choice

Analytics is on by default and you can turn it off here. Once you do, neither analytics script is inserted, no request goes to clarity.ms or googletagmanager.com, and none of the three analytics cookies above is set again. Turning it off costs you nothing — the site works identically either way.

When you turn analytics off we delete the cookies it set at the same time. Opting out has to be as effective as never having been counted, and an identifier left behind in a cookie is still an identifier.

Checking…

This choice is stored in this browser only. Clearing site data resets it, and analytics goes back to on.

5. Analytics and session recording

We run two tools. Google Analytics counts visits and tells us which pages people arrive on and leave from. Microsoft Clarity shows how pages work: heatmaps of where people click, and recordings of how pages were navigated. Text you type into a form field is masked in the browser before anything is sent, so passwords, answers and document details do not leave your device through Clarity. Recordings show layout and interaction.

The signed-in workspace, the setup questions and the intake form are masked in full, not just their input fields — balances, filings and uploaded identity documents are rendered content, and Clarity does not capture any of it.

We use both to find what is broken or confusing, and nothing else. Neither is joined to your account record, sold, or used for advertising, and Google Analytics runs without advertising features or data sharing turned on. Microsoft keeps Clarity data for 13 months; Google keeps analytics data for 14.

6. What we do not do

  • No advertising or retargeting pixels.
  • No sharing of browsing data with ad networks or data brokers.
  • No cross-site tracking, and no selling of personal information.
  • No third-party fonts fetched at page load — typefaces are served from our own domain.

7. How to turn things off

The control in section 4 is the quickest way, and it takes effect immediately. Beyond that, every browser can block or delete cookies, usually under Privacy or Site settings, and most offer a per-site control. Blocking fos_session will sign you out and keep you out.

You can also opt out for every site at once — Google publishes a browser add-on for Analytics, and Microsoft an opt-out for Clarity at Microsoft’s Clarity opt-out, and browser-level “Do Not Track” and Global Privacy Control signals are honoured where the law requires it.

8. Changes

If we add a tool that sets something new, it goes in the table above before it ships. How the resulting data is handled is covered by the Privacy Policy, and the providers involved are named in the subprocessor list.