Cookie policy
Version 2026-10-06.1 · Prepared 6 October 2026
Current cookie inventory
The application uses rf_session, a first-party authentication cookie, for up to 12 hours after login. It links your browser to a server-side session. It is HttpOnly, SameSite=Strict and marked Secure in production HTTPS mode. Logout clears it. The cookie is needed for requested signed-in functions, not advertising.
Optional tracking
This supplied build installs no analytics, advertising pixels or social tracking widgets and does not use browser local storage for marketing. Marketing pages can be read without signing in. Because only essential session storage is used, there is no pretend “accept all cookies” banner. If optional tracking is added, the operator must assess the applicable rules and implement any required prior, granular choice, rejection and withdrawal before activating it.
External services and browser controls
Stripe checkout, OAuth sign-in and external provider websites are separate destinations and may set their own cookies under their policies. They are not treated as consent to tracking on this site. Your browser can remove or block cookies, but blocking the login cookie prevents the account service working. Recheck the inventory after changing hosting, scripts or integrations.
Related policies: Privacy · Terms · Cookies · Contact and complaints