Cookie Policy
Effective date: July 23, 2026
Last updated: July 23, 2026
1. What this policy covers
This Cookie Policy explains how mm-to-inches.net uses cookies, browser local storage, scripts, pixels, web beacons, consent signals, and similar technologies. It should be read with our Privacy Policy.
We load the Google AdSense code snippet as a site-verification method and as the bootstrap for Google Privacy & messaging, and we publish an `ads.txt` seller declaration for site review. This verification-only state does not authorize ad placements or ad serving. The Google code may contact Google and process IP address, page URL, browser/device information, consent status, and related technical identifiers for verification, consent-message operation, security, fraud prevention, and service operation. It may make managed-runtime requests even when no visible ad is shown. The `ads.txt` declaration does not render an ad or prove Google approval.
For users in the European Economic Area, the United Kingdom, and Switzerland, the active Google European-regulations message provides Consent, Do not consent, and Manage options. GA4 and Microsoft Clarity remain blocked before permission in that scope. For US-coded requests and other recognized locations outside this message scope, the v3 gate may load GA4 and Clarity only when no GPC or local analytics opt-out applies and the strict callback/scope rules described below permit it. Plausible and Ahrefs are disabled in this baseline. Advertising remains inactive.
2. Current storage and technologies
Browser local storage
The converter uses browser local storage for:
- `mmInchHistory` — recent conversion history; and
- `mmInchFavorites` — saved conversion favorites.
These records stay on your device until you clear them. They support user-requested local history and favorite features, are not advertising cookies, and are not used as a parallel consent record.
`mmti:analytics-opt-out:v1` — value `1` means this browser has asked mm-to-inches.net to block Google Analytics 4 and Microsoft Clarity. The key remains until you withdraw the preference or clear site data. Absence of the key is not consent. The key contains no country, state, timestamp, provider ID, or Google consent value.
The privacy interface uses first-party session-storage flags: `mmti:open-privacy-settings-on-load` and `mmti:privacy-settings-unavailable` for the settings handoff, `mmti:google-decision-callback-seen` for same-tab callback race control, and `mmti:analytics-deny-reload:v1` with only `manual`, `gpc`, or `cmp` as a one-reload guard. They are not consent or geographic records and are removed with tab/site data according to browser behavior.
Hosting and security
Cloudflare and hosting/infrastructure services process network and request data to deliver and protect the website. They may use cookies or similar technologies when needed for security, routing, abuse prevention, or service operation. Exact names and durations depend on the deployed service configuration.
Google verification and Google Privacy & messaging
The preserved Google AdSense code supports site verification and bootstraps Google Privacy & messaging. It is an explicit pre-choice exception and may make managed-runtime requests or create a hidden unfilled probe. Google Privacy & messaging may use consent-related storage and signals to display, save, and apply available choices. This exception is not permission to serve ads.
Google Analytics 4 and Microsoft Clarity
Google Analytics 4 and Microsoft Clarity form one policy cohort. Both load only when the v3 gate allows analytics. We do not use Clarity’s limited no-consent mode. When allowed, provider requests can expose IP address and network metadata and can process page URL, referrer, browser/device characteristics, timestamps, interactions, performance/error information, and provider identifiers or storage under the deployed configuration. We do not replay earlier events after analytics becomes allowed.
Google Analytics control information is available at:
https://tools.google.com/dlpage/gaoptout
Operational scopes and analytics vetoes
Operational scopes and analytics vetoes. Cloudflare classifies each request as `REGULATED`, `OPT_OUT`, `NON_REGULATED`, or `UNKNOWN` and sends only that coarse value. The browser receives and stores no country or state code for this control. `OPT_OUT` includes US-coded requests as a conservative product boundary, not a legal conclusion. `.pages.dev`, absent or malformed location data, request failure, missing headers, and unrecognized values are `UNKNOWN`.
Before GA4 or Clarity loads, the site checks Global Privacy Control and `mmti:analytics-opt-out:v1`. Either signal blocks both providers globally. GPC is read from strict `navigator.globalPrivacyControl === true` and, independently, from Cloudflare’s observation of exact `Sec-GPC: 1`, returned only as `X-MMTI-GPC: 1` on the first-party no-store probe. GPC is not copied into a consent record. The local preference is an independent first-party veto. Removing it does not grant Google consent or override a GPC signal.
With neither veto present, `REGULATED` still requires the existing strict Google analytics decision, `UNKNOWN` remains blocked, and `OPT_OUT` or `NON_REGULATED` may use the three-second no-callback path. A callback containing denied, unknown, malformed, mixed, partial, or `NOT_CONFIGURED` values cannot use that path. Advertising storage, ad user data, and ad personalization remain denied. Plausible and Ahrefs remain disabled.
Plausible ShipSolo endpoint
Plausible at `plausible.shipsolo.io` is disabled pending evidence. Its script, initializer, preconnect, and requests are absent. We do not describe it as cookieless or anonymous. It may be added only after the exact endpoint’s provider role, bytes, storage behavior, request payload, IP/user-agent/referrer handling, retention, and lawful-basis decision are documented and this policy is re-frozen.
Ahrefs Analytics
Ahrefs Analytics is disabled in this baseline. It may not be enabled without the same strict analytics gating, current configuration evidence, and an updated provider inventory.
3. Why these technologies are used
Enabled technologies are used to:
- provide local history and favorite features;
- deliver and secure the website;
- verify the website and operate the Google consent message;
- save and apply available consent choices;
- measure page and feature usage only after analytics is allowed; and
- diagnose errors, abuse, and performance problems.
A provider’s exact cookie names, identifiers, and retention can change with its configuration. The production storage/network inventory and provider settings are the source of truth; template names or durations must not be substituted for verified values.
4. Accept, reject, and manage
For users in the European Economic Area, the United Kingdom, and Switzerland, the Google message provides:
- Consent — accept the optional purposes shown in the message;
- Do not consent — reject optional processing; and
- Manage options — review providers and purposes and make granular choices.
Rejecting or turning analytics off keeps GA4 and Clarity blocked. Analytics consent does not grant advertising storage, ad user data, or ad personalization. The core converter remains available after rejection.
5. Change or withdraw a choice
Use Privacy & analytics choices on any normal page to opt out of GA4 and Clarity on this browser or to withdraw that local opt-out. Withdrawing removes only the local key and reruns all other gates; it is not an analytics grant. Where the Google European-regulations flow applies, Review consent settings separately reopens available Google choices. If GPC is on, optional analytics remains blocked until the browser or extension stops sending GPC.
On the standalone Privacy Policy route, Privacy & analytics choices is a plain link to `/cookie-policy#privacy-choices`; the policy route itself does not invoke Google or optional analytics.
A new opt-out blocks future site dispatch after detection and triggers available denial or erase commands if a provider already loaded. It does not guarantee deletion of information already processed by a provider.
Browser controls can also block or delete cookies and site data. Clearing mm-to-inches.net site data may remove the local analytics opt-out as well as conversion history and favorites; a currently enabled GPC signal remains independently effective.
We do not claim that a browser “Do Not Track” signal automatically blocks or limits technologies. DNT is separate from Global Privacy Control.
6. Conditional future advertising technologies
This section describes a future state; advertising is not currently active and Google approval is not claimed.
If Google AdSense ad serving is later enabled in a separately approved release:
- third-party vendors, including Google, may use cookies to serve ads based on a user’s prior visits to this website or other websites;
- Google and selected partners may place or read cookies or use web beacons, IP addresses, page URLs, device information, and other identifiers for ad delivery, measurement, frequency control, fraud prevention, and, where permitted, personalization;
- users can control Google ad personalization at https://adssettings.google.com/; and
- the consent interface or an accessible provider list will identify enabled ad technology providers and their available controls.
For personalized ads in the EEA, United Kingdom, and Switzerland, the later release must use the required current Google-certified CMP/TCF flow and pass a new account, Legal, network, storage, and placement review.
7. Updates and contact
We update this policy when technologies, providers, settings, purposes, or publication state change and use a fixed update date.
Questions: [email protected]
Privacy & analytics choices
Optional analytics helps us understand page and feature use. You can block Google Analytics 4 and Microsoft Clarity on this browser. This control does not affect the core converter or necessary hosting and security processing.