UCmodSTOP SPAM

Privacy and browser storage policy

Last updated: 8 September 2026

This policy covers the public website stop-spam.ucmod.com. Its main interface is published as static pages, with no registration, user account or form that accepts user data.

Cookies

As of the audit date, the website sets no first-party cookies. HTTP responses contain no Set-Cookie header, and the page code does not read or modify document.cookie.

NameDataPurposeRetentionPartyNecessary
NoneNothing storedCookies are not usedNot applicableNot applicableNot applicable

The website therefore shows no consent pop-up and does not create a fictitious technical cookie. If cookies are introduced, this policy and the consent mechanism will be updated before they are enabled.

localStorage and sessionStorage

The website uses neither localStorage nor sessionStorage. Visitor choices and identifiers are not stored in the browser.

Live counters

A visible home-page tab requests /go/site-stats no more than once per minute. The response contains only three aggregate counts and the update time, with no user, chat or group identifiers. If the request fails, the page keeps the last received or fallback values. The request sets no cookies and writes nothing to browser storage.

Cloudflare and connection security

Cloudflare is a third-party infrastructure and security provider. It proxies HTTPS requests and may process the IP address, request time, URL, HTTP headers and technical security signals. The website currently uses neither CAPTCHA nor Cloudflare Turnstile.

The NEL and Report-To headers configure browser network reporting for 604,800 seconds (7 days). This is not a cookie, localStorage or sessionStorage, and page JavaScript cannot access this internal browser setting. See the Cloudflare Privacy Policy.

Analytics, advertising and third-party elements

Cloudflare automatically adds its third-party beacon.min.js script (Web Analytics/RUM) to the HTTP response. It is intended to measure page-load performance, is not technically necessary, and is blocked on this website by Content Security Policy: the browser must not load the script or send data to it. No separate consent is therefore requested. If this block is removed, the script must not be enabled before consent.

Cloudflare documents that the beacon itself uses no cookies, localStorage, sessionStorage or other storage data. If allowed, raw performance data is retained for 7 days and aggregate metrics are available to the owner for up to 6 months. No retention period applies while loading remains blocked.

The /go/… routes used by links in the Telegram bot menu only increment an aggregate server-side counter by source, destination and language. They set no cookie and store no browser identifier.

HTTPS transmission

HTTP requests are redirected to HTTPS. Because the website creates no cookies, the Secure, HttpOnly, SameSite, Path and cookie lifetime attributes do not currently apply. Any future necessary cookie will be sent only over HTTPS and use the smallest practical scope and lifetime.

← Back to the website