Cookies, and what we count
Three cookies exist here in total, and two of them only once you have signed in. None of them advertises at you, follows you anywhere, or tells us who you are.
The two cookies
They arrive when you sign in, because that is what being signed in means, and they go when you sign out. There are no others, ever.
| What it is called | What it does | How long it lasts |
|---|---|---|
| gttg_session | Keeps you signed in on this device | Thirty days, or until you sign out |
| gttg_csrf | Proves a request really came from our pages, so another site cannot act as you | The same |
Both are strictly necessary for something you asked for — being signed in — so the law does not require us to ask permission, and asking would be strange: refusing them means refusing to be signed in. Never make an account and you will never meet either.
Counting which pages get read
We do not. There is no analytics on this site at all — no counter, no beacon, no third-party script of any kind. Nobody is measuring which pages you read, and that includes us.
If it ever changes it will be a count of page views and nothing else, with no cookie and nothing traceable to you — and a note will appear on every page saying so, the same day it starts. One setting in the build switches the counting and the note together, so a site that counts without saying so is not something we could ship by accident.
The bot-protection cookie
From 18 August 2026 the site uses Cloudflare’s Bot Fight Mode, which checks whether a visitor is a real browser or an automated script. When it runs it sets one cookie, cf_clearance, recording that this device already passed — so you are not checked over and over.
It is Cloudflare’s, not ours. We cannot read it, it says nothing about who you are, and it is not used to advertise or to follow you anywhere. Cloudflare also adds a small script to pages for the same check.
Why we turned it on. This site lets people upload documents to a shared trip, and an upload endpoint with no protection is an invitation. This is the cheapest honest defence, and the law treats security measures like this as strictly necessary — so it does not need your permission, but it does need saying, which is what this section is.
Everything else, and none of it is cookies
A cookie is only one way of keeping something on a device, and here it is much the smallest. Your theme, where you are travelling from, the countries you saved, your packing ticks, and the pages kept so the site works when your signal does not — all of that sits on your device, and none of it reaches us unless you sign in and choose to sync.
The storage page lists every single one, tells you whether it is on your device right now, and gives you a button to delete each and a button to delete the lot. It also has a second button that stops the site storing anything at all. We keep that working because a page describing your rights that will not let you use them is decoration.
What we never do
No advertising cookies. No tracking across other sites. Nothing sold, nothing handed to data brokers, no profile of you anywhere. We have no advertising to target and no wish to build any.
Which rule each part relies on
The law here is the Privacy and Electronic Communications Regulations, rewritten in February 2026 by the Data (Use and Access) Act 2025. It lets us keep something on your device without asking in a few narrow cases, and each thing above sits in one of them.
The two sign-in cookies are strictly necessary for a service you requested. Your settings and saved things are there to remember choices you made, which is allowed so long as we tell you plainly and give you a simple, free way to say no — that is exactly what the storage page is. Counting how the site is used in order to improve it has its own rule on the same terms: tell people clearly, and let them object easily. We have taken all three as they are meant. Nothing here is buried, and every refusal is one press.
If any of this is wrong, unclear, or does not match what you actually see, tell us. We would rather fix it than be technically correct.