Cookie Policy
Effective 2026-04-18
We use a small number of cookies to operate the Site. We do not use third-party advertising cookies or cross-site tracking pixels.
Categories
1. Strictly necessary (always on)
Required to provide core functionality (login, security). You cannot opt out of these without breaking the Site.
| Cookie | Purpose | Lifetime |
|---|---|---|
| cbs_session | Authentication session (HTTP-only, SameSite=Strict). | Session |
| cbs_csrf | Double-submit CSRF token paired with cbs_session. | Session |
2. Analytics (anonymous, no consent required where lawful)
We plan to deploy a self-hosted Plausible instance. Plausible does not use cookies and does not collect personal data — it counts hits with salted, daily-rotated hashes that cannot be tied back to an individual.
3. Marketing
We currently use no marketing cookies. If we add a retargeting pixel in the future, it will be opt-in via a consent banner and listed here.
How to control cookies
- Most browsers allow you to block or delete cookies in their settings. Blocking strictly necessary cookies will log you out and break checkout flows.
- You can clear our cookies for this domain at any time via your browser's "Site settings" or DevTools > Application > Cookies.
Do Not Track
We honor the spirit of the DNT signal: we do not load any third-party tracker regardless of header.
Changes
Material changes will be posted on this page. The current cookie inventory is auditable in your browser DevTools.