Overview
datafetch.wtf uses a small number of cookies and similar storage to keep you signed in and protect the service. We do not run third-party advertising trackers.
Essential cookies
- Session
- HTTP-only cookie after login — required for console access
- CSRF / security
- Tokens that protect forms and API-adjacent actions
- Preferences
- Lightweight UI prefs (e.g. sidebar collapsed) in local storage
These cannot be switched off without breaking login, so they run on the basis of strict necessity rather than consent.
What the console keeps in your browser
The console stores several things in localStorage instead of sending them to us. This data never leaves your device, is readable only by this origin, and clearing site data removes it.
- df.settings.v1
- Your API key and module preferences
- df.searchHistory.v1
- Recent queries, for the activity chart and quota counter
- df.geo.v1
- Places plotted on the geo map
- df.geo.provider.v1 / df.geo.penalty.v1
- Geolocation provider health, to avoid a failing endpoint
Your API key living in local storage means anyone with access to your browser profile can read it. Use a device you control, and rotate the key if that stops being true.
Analytics
We do not set third-party analytics cookies by default. If that changes, this page will be updated and optional consent will be required where law demands it.
Third parties
Cloudflare may set cookies related to bot protection (e.g. Turnstile / challenge flows) on public surfaces. We set no login cookie: access is a key you paste into the console. Payment providers process checkout on their own domains under their policies. We do not embed advertising or social media pixels.
How long they last
- Session cookie
- Cleared when you log out or the token expires
- Bot protection
- Short-lived, set per challenge by Cloudflare
- Local storage entries
- Persist until you clear site data or use the in-console controls
