Policies

Cookie notice

Last updated
8 September 2026
Version
2026-09-08
Cookies we set
One, first-party, strictly necessary
Analytics cookies
None
Consent banner
None needed

This site sets one cookie of its own. It keeps your place in the intake form so that a refresh does not lose your answers. There is no analytics cookie, no advertising cookie and no third-party tag manager, which is why you are not being asked to accept anything before you read.

Why there is no banner

European and United Kingdom law requires consent for cookies that are not strictly necessary to provide the thing you asked for. We do not set any, so there is nothing to consent to, so there is no banner in your way.

That is the entire reason. It is not a design preference and it is not a claim about how much we respect you. It follows from the fact that we sell one document and do not run advertising.

The one cookie we set

NameWhat it holdsLasts
bch_intakeA random identifier that ties your browser to the intake you are part way through, so a refresh or a closed tab does not lose your answers.7 days, or until the report is sent

It is first-party, HttpOnly, Secure and SameSite=Lax. It holds no answer, no name and no email address — only the identifier that lets the server find the draft it already holds. It is set the moment you begin an intake and not before. Reading an essay sets nothing at all.

The draft kept in your own browser

The intake also keeps a copy of your part-finished answers in your browser’s local storage, under the key bch.intake.draft. This is not a cookie: it is never sent to us, it stays on your device, and it exists so that a lost connection does not cost you twenty minutes of typing.

It is deleted when you submit the intake. You can delete it yourself at any time by clearing site data for this domain, and doing so costs you nothing except the unsent draft.

Stripe, at the moment you pay

Payment happens on Stripe’s own hosted checkout page, on a Stripe domain. Stripe sets its own cookies there, for fraud prevention and to keep your checkout session alive. Those are strictly necessary to take a payment safely, and they are governed by Stripe’s privacy policy rather than ours.

We do not embed Stripe’s scripts on our own pages, so nothing from Stripe is loaded while you are reading this site.

What is not here

No analytics cookie. No advertising or retargeting cookie. No social network button that phones home. No tag manager, no heatmap, no session recorder, no A/B testing cookie, no consent-management platform — the last of which is itself usually a tracker.

On the routes that handle health information, third-party scripts, images and connections are blocked by a Content-Security-Policy header rather than merely avoided by policy. The health data notice explains how to read that header yourself.

Do Not Track and Global Privacy Control signals are respected by default, in the sense that there is nothing running for them to switch off.

Refusing it

Every browser can block cookies for a single site, and blocking ours has one consequence: an intake will not survive a refresh, so you would need to finish it in one sitting. Nothing else on the site changes.

If this notice ever stops matching what the site does, that is a mistake and we would like to know. Write to privacy@bencaohouse.com. The version and date at the top of this page move whenever anything below changes.

The reading

One cookie, and it only exists to hold your place.

If that is the sort of thing you check before you buy from a stranger, the rest of the policies are written the same way.