Cookie policy
This site uses a small number of cookies and browser storage entries. This page lists them by purpose, because a list by name ages badly and tells you nothing useful.
Last updated: September 24, 2026
The session cookie
One cookie keeps you signed in. It holds a random identifier and nothing else - no email, no balance, no order data. It is marked Secure, so it is only ever sent over HTTPS, and HttpOnly, so page scripts cannot read it. It expires when you close the browser or when you sign out. Without it you cannot stay signed in, so it has no opt-out.
The CSRF token
A second value, carried inside the same session, proves that a form submission came from a page we served rather than from another site acting in your name. It is required on every action that changes something and is renewed each time you sign in.
Analytics
We use Google Analytics and Microsoft Clarity to see which pages get used and where people get stuck. These set their own cookies and record page views, clicks and scrolling. They are not used to build an advertising profile, and we do not sell what they collect. If your browser blocks them, the site works exactly the same.
What we do not use
No advertising pixels, no retargeting tags, no cross-site trackers and no fingerprinting. Nothing on this site follows you to another one.
Turning them off
Every browser can block or clear cookies for a single site, usually from the padlock in the address bar. Blocking analytics changes nothing about how the site behaves. Blocking the session cookie means you will not be able to sign in, because there is nowhere left to keep the fact that you did.