What this site stores
Nothing, is the short answer. This page is the long one — what is kept, what is sent elsewhere, and what you can refuse.
Last updated 30 August 2026
The whole of it, in four lines
- No cookies. This site sets none, first-party or third-party. There is no analytics, no tag manager, no advertising and no tracking pixel.
- One key in local storage, and only if you answer the banner: it remembers your answer so you are not asked again.
- One third-party request, and only if you allow it: the latest version number is read from GitHub, which discloses your IP address to GitHub. The download works either way — refusing costs you a version number in a label, and nothing else.
- No form. The beta request form is not open at the moment, so nothing you type on this site reaches a server. Requests already sent are covered below.
Cookies
This site sets no cookies at all. Not for sessions, not for preferences, not for measurement. Nothing here reads a cookie either.
That is not a compromise made for this page — it is what the site is. The typefaces are served from this same domain rather than from a font CDN, the images are local, and there is no third-party script anywhere in the pages.
Local storage
If you answer the banner at the bottom of the page, one key is written to your browser's local storage:
- Key
lensmith.consent- Contents
- Your answer (accepted or rejected), the date, and a schema number.
- Purpose
- So the question is asked once rather than on every page.
- Lifetime
- 12 months, after which you are asked again.
- Sent anywhere?
- No. It never leaves your browser.
Storing a refusal is what makes the refusal stick, so this one key is written whichever button you press. You can clear it at any time from your browser's site data, or change your answer with Cookie preferences in the footer.
Requests to GitHub
Lensmith's builds are published on GitHub. Two things follow from that.
The version number. To print the current version in the download
button, the page can fetch a small manifest file from
raw.githubusercontent.com. Making that request tells GitHub, Inc. your IP
address, the page you came from and your browser's user agent — a transfer to a
company in the United States. It is not made unless you accept, and
the download button works without it, because its link is fixed rather than built from
the answer.
The download itself. When you click a download or a release link you are sent to GitHub, and from that point you are on their site under their terms. That is a request you make deliberately, so it is not something a banner can meaningfully gate. What GitHub does with it is described in the GitHub Privacy Statement.
The beta request form
The form is closed at the moment. What follows describes it for when it reopens, and covers requests already sent — those are held, and erased, exactly as written here. While it is open it is the only place on this site where anything you type reaches a server, and it exists for a single transaction: you ask for a code to the private beta, and you get an answer.
- What is asked
- Your name and email (required), and — if you care to — the Mac you would run it on, its macOS version, and a few lines about what you shoot.
- Why
- To decide on the request and to reply to it. If it is accepted, to issue you an invite code and label it with your name so it can be revoked later.
- Lawful basis
- Your consent (GDPR Art. 6(1)(a)), given by ticking the box on the form. The box is never ticked for you, and the form does not send without it.
- Where it goes
- To the server that runs Lensmith's own backend, under the developer's control. It is not sold, not shared, and not passed to any advertising, analytics or mailing service — there is none in this project.
- How long
- Until the private beta ends, after which the requests are deleted. Sooner if you ask.
- What you get
- One reply. There is no newsletter, no drip sequence and no second message — being on this list means nothing except that you asked.
Sending the form twice does not create a second request. The address is the key: a later submission updates the one already there. And the answer the form gives is the same whether the request is new or a repeat — otherwise the form would be a way of finding out which addresses have asked for access, which is nobody's business but theirs.
Withdrawing is as easy as consenting. Write to the contact address and the request is deleted — the whole row, not a flag on it. Withdrawing consent does not undo the reply already sent, and an invite code you have already been given keeps working until it is revoked; those are two different things and you can ask for either or both.
The anti-spam check on that page
The form is protected by Cloudflare Turnstile, which is what stands between a form open to the world and a database of invented names. It sets no cookies, does not profile you and is not used to track you across sites — it is deliberately not Google reCAPTCHA, which does the first and the third.
It does make a request to challenges.cloudflare.com, which discloses your IP
address and user agent to Cloudflare, Inc., acting as a processor under the
European Commission's Standard Contractual Clauses. The lawful basis is legitimate interest
in keeping the form usable (GDPR Art. 6(1)(f)), and the check is a security measure in the
ePrivacy sense, so it is not something a cookie banner governs.
It loads when you start filling the form in, not when the page opens. Read the page and leave, and no request to Cloudflare is made at all — the same principle as the version lookup below: a third party is reached when you do something that needs it, and not because you looked at a page.
Server logs
This site is served by an ordinary web server, which keeps the ordinary access log: the requesting IP address, the moment of the request, the page or file asked for, the response code and the user agent. Those entries exist to keep the site running and to notice abuse — they are not joined to anything else, not used to build a profile of anyone, and not shared.
Those same entries are also read in aggregate — how many visits a page had, which site sent them, which browser asked — and the reading happens afterwards, on the log the server keeps anyway. Nothing is added to these pages to make it possible: no script, no cookie, no identifier. What comes out is totals, not a record of anybody, and the IP addresses are truncated before they reach it.
The lawful basis is legitimate interest in the security and availability of the service, and in knowing whether anyone is reading it (GDPR Art. 6(1)(f)). Entries are kept only as long as they are useful for that, and then discarded.
What this site does not do
- No analytics script of any kind — no Google Analytics, no self-hosted equivalent, nothing on these pages that measures you. Visits are counted afterwards from the server's own access log, described above, and never from your browser.
- No advertising, no remarketing, no data brokers, no social plugins.
- No profiling and no automated decision-making.
- No fingerprinting: nothing here reads your fonts, your canvas or your devices.
- No CDN and no third-party fonts — every asset on these pages comes from this domain.
- No newsletter: the beta request form is answered with a single reply and is not a mailing list, and nothing on this site subscribes you to anything.
The app itself is a separate matter with its own behaviour — the private beta build checks for updates and reports that it is alive. That belongs in the app's own notice, not in this one, which covers this website only.
Your rights
Over the log entries described above, and over a beta request if you have sent one, you have the rights the GDPR gives you: to know what is held, to obtain a copy, to have it corrected or erased, to restrict or object to its processing, to have it handed to you in a portable form, to withdraw a consent you have given, and to complain to your national data protection authority. In Italy that is the Garante per la protezione dei dati personali.
Unless you have sent the beta request form, there is very little to exercise them against — no account, no profile and no identifier that survives the visit. To ask anyway, or to ask anything else about this page, use the contact route below. Requests are answered by the developer personally, so give them a few days.
- Controller
- Fabio Della Selva — the developer of Lensmith
- Contact
- fabiodellaselva.com
- Scope
- This website, lensmith.app
Changes
If this site ever starts doing something it does not do today, this page changes first and the date at the top changes with it. A change that affects what you were asked resets the question, and the banner comes back.
Back to home