Essential session cookie
The __session cookie authenticates the signed-in user. It is HTTP-only, SameSite=Lax, uses Secure on HTTPS, and has a five-day maximum age. Server verification checks revocation. Signing out clears the cookie and revokes the Firebase session where available.
Theme preference
The app-theme cookie remembers light or dark appearance for up to one year. It is not used for advertising or cross-site tracking.
What is not implemented
The current application does not implement advertising cookies, analytics cookies, cross-site behavioral profiling, or a marketing-consent cookie banner. If non-essential cookies are introduced, consent and rejection controls must be added before use.