Privacy

One analytics cookie.
That is the whole story.

This site has no account, no form, no payment and no newsletter. There is nothing here for you to fill in, so there is almost nothing to collect. What remains is analytics, which starts switched off on every visit, and the server logs any website keeps. Whether we ask you first depends on where you are, and the section on that says so plainly. Both are described below in the specific rather than the general.

The short version

Two companies see anything at all.

Measured in a real browser on 4 August 2026, loading a page of this site makes requests to exactly two hosts that are not this one, and both belong to Google: www.googletagmanager.com and www.google-analytics.com. That is the complete list.

Worth stating what is not on it. Every photograph on this site is a file served from this domain, so your browser never contacts a stock-photo library or an image CDN. There are no web fonts loaded from a font service, no embedded videos, no social widgets, no chat popup and no A/B testing tool. Google Tag Manager and Google Analytics are the two hosts, and outside the EEA and UK their advertising signals are switched on so that Google can measure how this site's ads perform; the Analytics section below sets out exactly what is granted where, and how to refuse it from any country.

Beyond that, this site is hosted by Vercel, so Vercel's servers handle the request and keep the ordinary access logs a web server keeps, which include your IP address. That is a condition of the site existing rather than a choice about you.

That list covers reading this site. Sending the request form or the concierge note is a different event with a different set of companies involved, and it gets its own section below rather than being folded into a count it would make wrong.

Analytics

Denied on arrival, every time.

This site uses Google Analytics 4, measurement ID G-NYN8K5B9Z1, behind Google Consent Mode v2. Every visit begins with all four consent signals set to denied. What is lifted from there depends on where you are, and this section says exactly which.

In the European Economic Area, the United Kingdom and Switzerland, a banner appears and nothing is written to your device until you answer it: that is a legal requirement there, and declining is a real choice that sticks. Accepting there grants analytics only. The three advertising signals stay denied. Everywhere else the law asks us to tell you rather than to interrupt you, so no banner appears and, after the first page loads, analytics and the advertising signals are granted, which is what lets us measure how this site's advertising performs. Telling you is what this page is. If you would rather opt out anyway, the button further down does it from any country.

Consent signals, and what this site ever does with them
SignalOn arrivalOutside the EEA/UKIn the EEA/UK/CH
analytics_storagedeniedgrantedgranted on accept
ad_storagedeniedgranteddenied
ad_user_datadeniedgranteddenied
ad_personalizationdeniedgranteddenied

Where the banner appears — the EEA, the UK and Switzerland — it carries no "Accept all", because on that path there is nothing else to accept: the three advertising signals stay denied even when you accept, so agreeing to analytics there does not also agree to ad targeting. Outside those countries, as the table shows, the advertising signals are granted alongside analytics.

If analytics is granted, two analytics cookies are set: _ga and _ga_NYN8K5B9Z1. They give you an identifier that persists between visits so that two page views can be recognised as one visit. Where the advertising signals are granted too, outside the EEA and UK, Google may set additional advertising cookies. Verified on the live site: with an empty cookie jar and no answer given, no cookies are set at all.

If you decline, no cookie is set and no identifier persists.

The part most policies leave out

One request goes either way.

Consent Mode works by loading Google's script immediately and telling it what it may not store. So on your first page view, before you have touched the banner, one request does reach Google. It carries your IP address and the address of the page you are on. It does not set a cookie and it does not create an identifier that follows you.

This is how Google designed the mechanism, and it is still a request about you that you did not agree to, so this page says so instead of describing the banner as though nothing happens until you press a button.

One consequence deserves naming directly, because it is specific to a site about medical screening. A page address on this site can be revealing on its own. /tests/colonoscopy/ says what you were reading about. If that matters to you, the reliable protection is not the banner, it is a browser that blocks the request: any tracker-blocking extension, Firefox's strict mode, or Safari with cross-site tracking prevention will stop it before it leaves your machine.

Not a cookie

Where your answer is remembered.

Your choice is kept in your own browser's local storage under the key medi-consent, holding one word, granted or denied. It is not a cookie, it is never sent to this site or to anyone else, and clearing your browser's site data removes it. An answer you have given wins everywhere and outlasts any travelling: decline in Frankfurt and you stay declined reading from Toronto, because the stored answer is checked before your location ever is.

One more key sits alongside it, in session storage rather than local storage, holding the two-letter country the network edge assigned to your visit. It exists so that only the first page of a visit has to ask, it is written only for visitors who are not shown a banner, and it disappears when you close the tab. It is not a record that you agreed to anything.

You can change your mind at any time.

If you send a form

Health information, and three companies.

The request form asks for things that are health information rather than page views: what you want examined, whether you will accept sedation, and what medication you take. It is treated accordingly, and this section says exactly where it goes instead of gesturing at "trusted partners".

The concierge note is handled the same way by the same three companies, and its own free text is health information too: what care you are looking for is not a page view. The differences are in the Slack line and in the consent, both below.

The forms post to this domain, and this domain hands them to a Cloudflare Worker that validates and stores them. So Cloudflare processes and stores what you sent, Vercel passes the request through, and a one-line summary is posted into our own Slack workspace so a person picks it up.

What each company sees of a submitted form
WhoSeesKept
Cloudflare Everything you typed, including the free text and the medication note. No IP address is stored with it. 90 days, then deleted automatically
Slack One line: your name, age band, country, chosen program, dates, sedation answer, and whether medication is involved. Not your free text, not the medication note, not any contact detail. Until we delete the message
Slack (concierge note) One line: your name, the kind of care, your city and your dates. Not your note, not any contact detail. Until we delete the message
Vercel The request passes through, the same as any page load. Ordinary access logs. Vercel's own retention

The split between the Cloudflare row and the Slack rows is deliberate and is the part worth checking us on. A chat channel is a wider audience than a credential-protected admin page, so the notification carries only what is needed to pick a request up, and the details stay behind the credential. Naming which medications you take never reaches Slack; that a medication is involved does, because it changes who should read the request first.

Nothing you send is used for marketing, added to a list, or sold. It is used to quote a program and hold a date, and shared with the partner centre that would perform the screening, or the clinic that would provide the care, if you go ahead. That is what the consent box on each form covers, and it is the whole of it.

No account is created and no password exists, so there is nothing to log into and nothing to breach on your side. There is also no payment step: nothing is charged through this site at all.

Your rights, and the honest limit

Deletion works. A formal request has no desk yet.

Withdrawing analytics consent works today, with the button above. Earlier deletion of a request works today too: reply to your own request and say so, and it goes before the 90 days. Left alone, it deletes itself anyway.

What does not exist yet is a published address for a formal data request, because this site still carries no email address or phone number. The form is the only inbound route, so a request about your data has to travel the same way as a request for a quote. That is a real gap, not a design choice, and it is stated rather than dressed up as a privacy-by-design feature.

One thing that is genuinely by design: we cannot look you up by anything except what you sent. There is no account, no cookie tying a request to a visit, and no identifier joining the two. The analytics above and a request are never connected.

Elsewhere

The two policies that also apply.

Google processes the analytics described above under its own privacy policy, and Vercel handles the hosting and its access logs under theirs. Neither is a document this site controls, and both are worth reading if the summary above is not enough.

Last updated 4 August 2026. Every claim on this page was checked against the deployed site on that date, not against an intention. If the site changes what it loads, this page is wrong until it is updated, so it carries a date for the same reason every figure on this site does.