Public policy draft

Cookie Notice

Cookies used by the current web application.

Draft for professional legal review before launch. This is not legal advice and has not been approved by counsel.

Effective date: [PLACEHOLDER — set after legal review]

Last updated: July 27, 2026 (local draft)

Essential session cookie

The __session cookie authenticates the signed-in user. It is HTTP-only, SameSite=Lax, uses Secure on HTTPS, and has a five-day maximum age. Server verification checks revocation. Signing out clears the cookie and revokes the Firebase session where available.

Theme preference

The app-theme cookie remembers light or dark appearance for up to one year. It is not used for advertising or cross-site tracking.

What is not implemented

The current application does not implement advertising cookies, analytics cookies, cross-site behavioral profiling, or a marketing-consent cookie banner. If non-essential cookies are introduced, consent and rejection controls must be added before use.