Cookies and local storage
Everything this site puts on your device, listed. It is a short list, and none of it is tracking.
Last updated: 6 September 2026
There is no consent banner on this site, and that is not an oversight. Article 5(3) of the ePrivacy Directive requires consent before anything is stored on or read from your device — with one exception, for storage strictly necessary to provide the service you asked for. Everything below sits inside that exception. There is no analytics, no advertising pixel, no tag manager, no social widget, no embedded video, no chat box, and since the typefaces were brought in-house there is no request to any other domain at all. Nothing here is capable of following you, because nothing here talks to anyone who could.
A banner asking permission for things that need none is not extra caution. It is a false statement about what the site does, it trains people to click through the banners that do matter, and — where it nags until you accept — regulators have treated it as a dark pattern in its own right. So you are told what is stored, and not asked to approve it.
1. Cookies
Two, both strictly necessary, neither of them about you.
| Cookie | What it is for | How long |
|---|---|---|
datum-preview |
Only while the site is behind its pre-launch gate, and only for whoever holds the
preview key. Opening any page once with the key sets this, and it is what lets that
browser through the gate afterwards. It carries the key and nothing else, it is
HttpOnly so no script can read it, and an ordinary visitor never receives it.
It disappears with the gate. |
90 days |
| The sign-in session cookie, set by our licence server | Set only when you sign in to a DATUM account, by api.datumbim.com. It is
what keeps you signed in from one page to the next, and it is the only thing that proves
a request to see your own licence keys is coming from you. HttpOnly,
Secure and SameSite, so it cannot be read by a script or sent
from another site. Signing out deletes it. If you never open an account, it is never set. |
The session |
That is the complete list. Authentication and a security gate are the textbook examples of strictly necessary storage, and neither is used for any purpose beyond the one described.
2. What is kept in your browser's local storage
Local storage is not a cookie — it is never sent to a server, and we cannot read it. It stays on your device, readable only by pages on this domain, and clearing your browser data removes all of it. The same Article 5(3) applies to it, and the same exception covers it: every one of these exists so the site works the way you left it.
| Key | What it holds |
|---|---|
datum-theme | Light or dark |
datum-cur | Which currency you chose to read prices in |
datum-vat | Whether prices are shown with or without VAT |
datum-cart, datum-cart-items | What is in your cart, until you check out |
datum-cart-x | That you closed the cart panel, so it stays closed |
datum-account-email | The address you last signed in with, so the field is filled in for you. Not the password, and not the session — the session is the cookie above. |
datum-user, datum-library | A local copy of what you have bought, so the account page has something to show before the server answers |
datum-recent | The last six products you looked at, to put them back on your account page |
datum-votes | Which roadmap items you marked. It stays in this browser; it does not reach us. |
datum-promo, datum-cd-x | That you dismissed a promotion or a countdown, so it stops coming back |
datum-waiting-list-… | That you already joined the list for a particular product, so you are not asked twice |
datum-cookie | That you dismissed the note at the bottom of the page |
None of these identifies you, none is sent anywhere, and none is joined to anything else.
datum-cookie is worth being clear about: dismissing that note is not consent to
anything, because nothing on this site needed any. It only stops the note reappearing.
3. Third parties
None. Loading any page here makes requests to this domain and to no other.
Until recently that was not quite true: the three typefaces came from Google Fonts, so every visitor's browser handed their IP address to Google before the first word was drawn. A German court held that to be an unlawful transfer of personal data where the visitor had not consented (Landgericht München I, 20 January 2022, 3 O 17493/20). The fonts are now served from this domain, which removes the request rather than disclosing it — and with it the one thing on this site that would have needed a consent mechanism.
Where you go on to pay for a template, you leave this site for our checkout provider's own pages, which are theirs and have their own cookie notice. Nothing of theirs runs here.
4. What would change this
Said plainly, so that whoever next edits this site knows where the line is. Each of the following stops the strictly-necessary exemption from applying, and none may be added until a real consent mechanism is in place — one that asks before the thing loads, that treats refusing as no harder than accepting, and that records what was agreed:
- any analytics at all, including self-hosted and including "cookieless" products;
- an advertising or conversion pixel of any kind;
- an embedded YouTube, Vimeo, Google Maps or social post;
- a chat widget, a review widget, a heatmap or a session recorder;
- a font, script, stylesheet or image loaded from someone else's domain;
- an A/B testing tool, or anything that stores a persistent identifier.
The Content-Security-Policy in _headers is set
so that most of these would simply fail to load rather than silently start collecting. That is
deliberate: a policy is a promise, and a header is what keeps it.
5. Controlling it yourself
Every browser can block or clear cookies and site data, per site or altogether, and you do not need our permission or a control on this page to do it. Clearing this site's data resets your theme, currency and cart, and signs you out. Nothing else is lost, because there is nothing else.
6. Changes
If this page changes, the date at the top changes with it.
7. The rules this page follows
- Directive 2002/58/EC (ePrivacy), Article 5(3), as amended by Directive 2009/136/EC
- Закон за електронните съобщения, чл. 4б
- Regulation (EU) 2016/679 (GDPR), Articles 6 and 13
- EDPB Guidelines 2/2023 on the technical scope of Article 5(3) ePrivacy
See also the Privacy policy, which covers what happens to data once it reaches us, and the company details for who "us" is.