Cookie Policy
Effective: 2026-07-20 · Last updated: 2026-07-20
What cookies we use
We keep it minimal. Every cookie we set is strictly necessary to sign you in and keep that session secure. No analytics cookies, no advertising cookies, no cross-site tracking, no data brokers.
| Cookie | Category | Purpose | Lifetime |
|---|---|---|---|
__session, __session_aux | Strictly necessary | Holds your authenticated Platform session (Amazon Cognito tokens) and keeps you signed in | Up to 30 days |
gh_oauth_state, gh_login_state, dc_login_state, __auth_link_state | Strictly necessary | Protects GitHub and Discord sign-in and account-linking redirects against cross-site request forgery | Minutes, cleared on completion |
Why there's no cookie banner
Consent banners exist to collect permission for optional cookies: analytics, advertising, personalization. We don't set any, so there is nothing to ask you about. Strictly necessary cookies are exempt from consent requirements under the ePrivacy Directive and equivalent rules, because the service you asked for cannot work without them.
They are set only when you sign in. Browsing the marketing site signed out sets no cookies at all.
Related storage
Your theme preference (light or dark) is kept in your browser's local storage under cn-theme, not in a cookie. It never leaves your device and is not used to identify you. Clearing your browser's site data removes it.
How to control cookies
You can block or delete cookies through your browser settings, though blocking strictly necessary cookies will sign you out of the Platform and prevent you from signing back in. Instructions for common browsers: Chrome, Firefox, Safari, Edge.
Changes and contact
If we ever introduce a non-essential cookie, we will update this policy and ask for your consent before setting it. Material changes to this policy are announced the same way as Privacy Policy changes. Questions: legal@theunnamed.dev.