Privacy Policy
What we store
This website stores two things on your device. That’s it.
Your preferences: zest.preferences (localStorage)
When you pick a theme (Light / Dark / System) or toggle High Contrast mode, we save your choice to your browser’s localStorage under the key zest.preferences. This data never leaves your device. No server ever sees it.
Consent proof: zest_consent (cookie)
The Playground at /play/ runs a live Zest CMP so you can try it. When you accept or reject cookies, Zest writes a signed zest_consent cookie to your browser. The Zest script loads from our own domain, not a CDN or any third-party endpoint.
No other pages set this cookie unless you interact with the playground.
What we don’t do
- No third-party cookies, pixels, or beacons.
- No ads, no cross-site tracking, nothing sold or shared.
- No fingerprinting and no device identifiers.
- No account required.
Cookieless analytics
We count page views, clicks, and how far people scroll so we know which pages people actually use. The counting is first-party, anonymous, and server-side. Nothing is stored on your device:
- Your IP address is never stored. The server hashes it with a salt that rotates daily and keeps only that short-lived hash. The same visit counts once per day, and the hash cannot be linked to any other day.
- Each event stores the page path, the referrer, the browser user-agent string, an approximate country from the request, a rough device class, and UTM parameters. Nothing else.
- The data never leaves our infrastructure, is never shared with third parties, and cannot be linked back to you.
The search index
The search palette (⌘K) loads a static JSON index from /search-index.json. Queries are matched entirely in your browser using Orama Search. No search terms leave your device.
The policy generator
The free generator at /tools/policy-generator/ sends the answers you type (site name, tools you use, contact email) to a language model hosted on Cloudflare Workers AI. Cloudflare acts as our processor for this request: answers go from your browser to our endpoint, then to the model, and back to you. Answers are processed in memory to produce the draft and are never stored, logged, or shared by us. The draft comes back to your browser and goes nowhere else.
The geo lookup gateway
Sites using Zest’s optional geo/jurisdiction gating send visitors’ browsers to geo.cookiezest.com to learn which privacy regulations apply (GDPR, US state laws, and similar). The gateway reads the visitor’s IP address from the connection to resolve the country, returns only regulation flags, and discards the IP. It stores nothing: no database, no logs, no cookies, no analytics. It is off by default and a site works fully without it.
Contact
Questions? Open an issue on GitHub.