Cookie Policy
Last updated
We use as few cookies as the service can function with. This page lists every one of them, including the ones that only appear if you consent.
Strictly necessary
These are set without consent because the service cannot work without them. They contain no tracking identifiers.
- etk_session — authenticates your session. HttpOnly, Secure, SameSite=Lax. Expires after 7 days or on sign-out.
- etk_refresh — refresh token, scoped to the auth endpoint only. HttpOnly, Secure, SameSite=Strict. 30 days.
- etk_csrf — CSRF double-submit token. Secure, SameSite=Lax. Session only.
Preferences
- etk_consent — stores your cookie choices. Kept in localStorage rather than a cookie, so it never travels with a request. Persists until you clear site data.
- theme — remembers light or dark mode. localStorage.
Analytics (only with consent)
- _ga, _ga_* — Google Analytics 4, anonymised IP, 2 years. Used to understand which tools people need most.
- _clck, _clsk — Microsoft Clarity, session recording with automatic text masking, 1 year.
Marketing (only with consent)
We currently set no marketing cookies. If that changes, this section will list them and the consent banner will present them separately.
Third parties
Google and Microsoft act as processors for the analytics cookies above. If you decline analytics, their scripts are never loaded at all — we do not load them in a "consent-pending" state.
Managing cookies
Use the consent banner, which reappears if you clear site data, or change your browser settings. Blocking strictly necessary cookies will prevent sign-in but will not stop the browser-based tools working.
Do Not Track
We honour the Global Privacy Control signal by treating it as a rejection of analytics and marketing cookies.