Compliance
What the regimes below actually require of a site that collects nothing, and the one place this site does not yet clear the bar.
Last updated 2026-08-24.
Read this first
This page is a description, not a certification. Nobody has audited this site, no regulator has reviewed it, and nothing here is legal advice. It is written the way the rest of this project is written: stating what is verifiably true and naming what is not, so you can check rather than trust.
GDPR and UK GDPR
The regulations govern processing of personal data. This site has no accounts, no forms and no cookies, and its analytics stores no personal data, so the only personal data in play is the IP address that any web request necessarily discloses to whoever serves it.
Cookie consent is not required here, and that is a fact rather than a preference: consent under the ePrivacy Directive attaches to storing or accessing information on a user's device for purposes that are not strictly necessary. The one thing stored is a scheme preference you set yourself, which is strictly necessary to honour that choice, so there is no banner. A site with nothing to consent to should not be asking.
The analytics does not change that. Added 2026-08-11, and chosen on exactly this constraint: Plausible sets no cookie and reads nothing from your device, so the ePrivacy trigger is never pulled, and it retains no identifier and no IP address, so there is no personal data to find a lawful basis for. Google Analytics would have required both a banner and a different answer on this page, which is why it was not used. See the privacy page for what is recorded.
Resolved 2026-08-11. The fonts used to load from Google's servers, which disclosed visitor IP addresses to Google before any interaction - an arrangement a German court has held to be processing personal data without a lawful basis. They are now served from this domain, and the analytics was picked so that this section did not have to be rewritten backwards. See the privacy page.
Corrected 2026-08-21. This paragraph used to end "the analytics script is the only third-party request the site makes". That had stopped being true: Cloudflare's Web Analytics beacon is injected at the hosting layer, so it appeared on every page without any change to this site's code. Two third-party requests, not one, and the privacy page now names both. It changes nothing above - the beacon is cookieless and Cloudflare already serves this page - but a page whose value is that its claims are checkable cannot carry one that is not.
Half of the other gap closed 2026-08-24. Article 13 requires a data controller to be identified by name with a means of contact - two separate things. The means of contact is now real: [email protected], live via Cloudflare Email Routing, alongside the public issue tracker. The name is not: this project has no legal entity yet, so there is no controller identity to attach to that inbox. An email that reaches someone is real progress and is not the same thing as knowing who that someone legally is.
CCPA and CPRA
California's statutes turn on selling or sharing personal information. Nothing is collected, so nothing is sold, shared, or disclosed for cross-context behavioural advertising, and there is no "Do Not Sell or Share My Personal Information" link because there is no such activity to opt out of.
The thresholds that make a business subject to the CCPA in the first place - revenue, volume of consumers, or revenue from selling personal information - are not met either.
DPDP Act, 2023 (India)
Added 2026-08-24. India's Digital Personal Data Protection Act applies by what is processed, not by where the processor is based - Section 3 reaches processing outside India if it relates to offering goods or services to individuals in India. Being an Indian-founded project does not exempt this site, and would not have even if it were founded elsewhere: the same facts that clear GDPR above clear this too, for the same reason. No accounts, no forms, no cookies, and the two third-party requests this site makes - Plausible and Cloudflare's beacon - retain neither an identifier nor an IP address. See the privacy page for what each one actually does.
The Act is being phased in, not fully in force yet. The provisions that matter here - notice, consent, a grievance officer, breach notification - activate 2026-11-13, twelve months after the Act and its Rules were notified on 2025-11-13. A further set of obligations lands 2027-05-14. Today, only the provision establishing the Data Protection Board is live.
The same gap as GDPR, for the same reason. Once the Act's notice and grievance-officer duties activate, they attach to a Data Fiduciary that processes personal data - and even under the broadest reading, where the IP addresses inherent to any web request count, this project has no legal entity yet to name as one. That is the item already tracked above, not a second one.
Accessibility
The target is WCAG 2.1 level AA. What has actually been verified, on the built pages and in both colour schemes: contrast measured by resolving each computed colour through a canvas rather than by parsing a colour string, with zero failures and a worst case of 4.87:1 against a 4.5 requirement; primary actions at 44 by 44 or larger, with every other control measured at 24 by 24 or larger and links inside a sentence exempt as the target-size criterion allows; full keyboard navigation with a visible focus ring; and no horizontal scroll at 375px.
What has not been verified: a screen reader has not been run over these pages end to end, and no assistive-technology user has tested them. That is a real gap and is recorded as one rather than covered by a conformance claim.
The components themselves carry the same rule the site does: state is never carried by colour alone. A switch reads correctly in a greyscale screenshot because knob position encodes it, and a segmented control does because thumb position does.
Export control and sanctions
The software contains no cryptography beyond the HTTPS provided by the Java standard library, and is published as open source from a public repository. Distribution is GitHub's, so GitHub's own trade-control terms apply to who can download it.
Children
This is a developer tool with nothing to sign up for and nothing collected, so it is not directed at children and holds no data about anyone regardless of age. COPPA and the UK Age Appropriate Design Code have no subject matter here.
Reporting a problem
Security issues, privacy concerns and accessibility barriers all go to the issue tracker, or to [email protected] for anything that should not be public - a security report chief among them.