Cookie Policy
Version: 1.2 · Effective: 2026-08-04
Three cookies, all strictly necessary, and still no analytics cookie
There is no analytics cookie on this site. Measurement happens server-side and is gated on your recorded answer, so the only thing stored in your browser is the answer itself — not a tracking identifier.
These are the only cookies that exist:
| Cookie | Purpose | Lifetime |
|---|---|---|
nc_consent |
Remembers your answer about analytics, so we honour it and stop asking | 1 year |
nc_session |
Keeps you signed in. Contains a signed reference to your account, nothing else | 7 days |
nc_oauth |
Holds the one-time security values that prove the sign-in you complete is the sign-in you started | 10 minutes |
nc_consent is set once you answer the question either way — including when you
decline. That is the point of it: without a record of your "no" we would have to
ask again on every page, which is the behaviour that makes consent banners
worthless.
All three are HttpOnly (JavaScript cannot read them), Secure (HTTPS only)
and SameSite=Lax (another site cannot use them to act as you). Signing out
clears the session immediately.
There is still no analytics cookie, no advertising cookie, and no third-party cookie of any kind. No Google Analytics, no tracking pixels, no embedded scripts or web fonts loaded from anyone else.
That is specific enough to verify: open your browser's developer tools, look at Storage, and you will find those two names and nothing else.
Local storage: your theme choice
One thing is kept in your browser that is not a cookie. If you pick a light
or dark appearance on your account page, that choice is saved in localStorage
under nc-theme.
It never leaves your device — it is not sent with requests the way a cookie is, we cannot read it, and it is not tied to your account. It is listed here anyway, because "we only set three cookies" would be technically true and still leave you surprised to find something in your browser storage.
Clearing site data removes it, and the site falls back to matching your operating system's light or dark setting.
What our host sees regardless
Cloudflare serves this site and therefore processes connection data — your IP address, the page requested, your browser's user-agent — because a server physically cannot send you a page without knowing where to send it. That is infrastructure, not tracking, and no report of it reaches us.
Cloudflare may set a security cookie if it needs to challenge traffic during an attack. That is theirs, it is strictly necessary, and it carries no analytics.
Analytics, now that it exists
Page-view measurement went live on 2026-08-04. It is first-party, server-side, and gated on your explicit answer. Mirrorborn stores your assessment answers in your account; Cloud Chirox stores text Dojo Record entries in your account and sends selected text/frame requests to Gemini. Neither sets cookies of its own.
Three commitments, unchanged:
- No analytics cookie is set before you opt in. Not "set and ignored" — not set.
- Declining is one click, and equally prominent as accepting. No dark patterns, no pre-ticked boxes, no cookie wall.
- No third-party or advertising cookies, ever. Analytics is first-party. We do not run ad networks, we do not embed trackers, and we do not sell or share your data with advertisers.
Changing your mind
Withdrawing analytics consent is one click on your account — the same single click that granted it, on a visible control, with no "are you sure" and no retention flow in between. Withdrawal has to be as easy as consenting or the consent was never freely given.
Sign out at any time to clear the session cookie; that control is in the site header on every page. Your browser can clear any of these cookies itself.
The desktop application
ChronoSophia is not a website and sets no cookies of any kind. Its privacy properties are covered in Part A of the Privacy Statement.
Contact
Questions: see SUPPORT.md.