Cookie Policy

Effective June 12, 2026 · Last updated June 12, 2026

We use only essential cookies. No advertising, no analytics, no third-party tracking. The cookies we do set keep your login working and protect form submissions.

This Cookie Policy explains what cookies we use, why, and how you can control them. Cookies are small text files placed on your device by a website. We use them only to make the service work for you.

1. What we use

CookieTypePurposeLifetime
PHPSESSID Strictly necessary Keeps you logged in across page loads on /account/ and related authenticated pages Session (browser close) or up to 14 days for "remember me"
csrf_token Strictly necessary Protects against cross-site request forgery on form submissions Session
__cf_bm, cf_clearance Strictly necessary (Cloudflare) Cloudflare bot management + DDoS protection 30 minutes / up to 30 days

That\'s it. We do not set advertising cookies. We do not set analytics cookies. We do not use third-party tag managers, behavioral retargeting pixels, fingerprinting libraries, or "anonymized" identifiers that the law treats as personal data.

2. What we don\'t use

3. Cloudflare cookies

Our DNS + edge layer is Cloudflare. Cloudflare may set a small number of strictly-necessary cookies for bot management and DDoS protection. These are set by Cloudflare\'s infrastructure, not by our application. Details: Cloudflare\'s cookie policy.

4. How to manage cookies

Because we only set strictly-necessary cookies, blocking them will break login + form submissions. If you still want to manage cookies:

EU/EEA + UK note: under the ePrivacy Directive and UK PECR, strictly-necessary cookies do not require consent. We do not place any non-essential cookies, so no consent banner is required for our service. If we change that, we\'ll add a proper consent mechanism first.

5. Changes

If we ever start using non-essential cookies (we don\'t plan to), we will update this policy AND surface an in-product consent prompt before placing the new cookies.