Privacy policy
Corner Lab runs no analytics, sets no tracking cookies, and makes no third-party requests. If you hold an account we store your email address and your membership status, and nothing else — payments are handled by Polar, and card details never reach us. That is the whole policy; the rest is detail.
Last updated 7 September 2026.
Who is responsible
Corner Lab is run by an individual based in British Columbia, Canada, who is the data controller for the purposes of the UK and EU GDPR. For anything in this policy, including a request about your own data, write to finn@cornerlab.ca.
What this site collects
Without an account: nothing. Reading this site involves no sign-up, no contact form, no comments and no newsletter. The pages are static, nothing is stored in your browser, and you are not tracked between visits.
With an account: your email address and your membership status. That is the entire record. No lap times, no telemetry, no setups, no reading history — we do not store what you look at, so we could not hand it over or lose it.
One cookie, and only if you sign in. It holds a random session token and nothing else — no name, no email, nothing readable. It is the mechanism that keeps you signed in, and it is built to be the safest version of that: HttpOnly, so no script on the page can read it; Secure, so it never travels unencrypted; SameSite=Lax, so another site cannot use it to act as you. It lasts seven days, and signing out deletes it.
Browsing without an account sets no cookie at all, and the build checks that on every page. There is no banner because there is nothing here to track you with — no analytics, no advertising, no third-party scripts — so there is nothing we could reasonably ask you to agree to.
No third-party requests. Fonts are served from this domain rather than from Google Fonts or any other service, so loading a page does not reveal your IP address to anyone but our host. There are no trackers, no embedded video, no social buttons and no advertising. This is also checked at build time.
What our host records
The site is hosted by Cloudflare, Inc., which automatically logs each request at its network edge: your IP address, the time, the page requested, and your browser's user-agent and referrer. This is ordinary for any website and happens before our code runs.
Why: to keep the site available and to block malicious traffic. Legal basis: legitimate interests, Art 6(1)(f) UK/EU GDPR — the interest being the security and availability of the service, which is difficult to provide otherwise and does not override your rights, since the data is not used to profile or identify you.
Cloudflare acts as our processor. Its edge logs are retained under Cloudflare's own schedule; the operational logs we enable are kept for a maximum of 7 days and are then deleted. See Cloudflare's privacy policy and its data processing addendum. Cloudflare is a US company and operates a global network, so a request may be served from outside your country; its DPA covers the transfer terms.
While the site is private
Corner Lab is not open to the public yet. Access is currently restricted through Cloudflare Access, which asks anyone reaching the site to sign in and records that sign-in. Only the operator has an account. When the site opens, this restriction and this section both go.
Your rights
If you are in the UK or EU you have the right to ask what personal data we hold about you, to have it corrected or erased, to object to or restrict our processing of it, and to receive it in a portable form. Because the only data involved is our host's edge logs, in practice a request means asking us to retrieve or delete log entries for your IP address.
Write to finn@cornerlab.ca. We aim to respond within 30 days. If you are not satisfied you can complain to your local supervisory authority — in the UK the Information Commissioner's Office, and in Canada the Office of the Privacy Commissioner.
Children
This site is not directed at children and collects nothing that would identify one.
How signing in works
There is no password. You give an email address, we send a link, and clicking it signs you in. The link works once and expires in fifteen minutes.
This is a privacy decision as much as a convenience one. A password would mean storing a hash of it and defending that hash — and a "forgotten password" flow is an emailed link anyway, so the link is the real key either way. Without a password there is simply nothing of that kind to store, lose or leak.
Asking for a link does not create an account. Nothing is recorded until somebody clicks one, so an address typed in by mistake, or by somebody else, leaves no trace beyond a code that expires in fifteen minutes.
Payments
Payments are handled by Polar Software Inc., who act as the seller of record. You buy from them, and they pay us.
Card details never reach Corner Lab. Checkout and the billing portal are Polar's own pages; we never see, store or process a card number, and we hold no billing address. What we receive back is a customer reference and whether the membership is active — which is the whole of it.
Polar hold the data needed to sell to you and to meet their tax obligations, under their own privacy policy. They are a US company; where that means a transfer out of the UK or EEA, their terms carry the transfer safeguards.
The legal basis for holding your email address and membership status is contract — we cannot give you what you paid for without knowing who you are and whether you paid. Invoice records are kept as long as tax law requires, which is a legal obligation and outlives the account.
When this changes
Any change is published here with a new date at the top. A material one is announced rather than quietly edited.