Cookie Policy
Effective: 2026-04-22 · Version v2026.04.22
We use cookies and similar storage mechanisms, grouped by purpose. You can accept, reject, or configure non-essential categories at any time using the button above, via the footer link, or from Settings → Privacy → Cookie preferences when signed in.
1. Strictly necessary (no consent required)
Exempted under Art 5(3) ePrivacy Directive because they are strictly necessary for the Service you requested.
| Name | Type | Purpose | TTL |
|---|---|---|---|
| guard-core-auth | httpOnly secure cookie | Authenticated session (carries a JWT that expires after 15 minutes and is refreshed) | 4 hours |
| cookie_consent | localStorage | Your consent choices | Until cleared |
| 2fa_flow | sessionStorage | Multi-step 2FA challenge state | Session only |
2. Analytics (consent required)
| Name | Type | Purpose | TTL | Processor |
|---|---|---|---|---|
| _rybbit_* | first-party cookies | Aggregate page-view analytics | 2 years | Self-hosted (analytics.guard-core.com) |
Rybbit is self-hosted on our own infrastructure at analytics.guard-core.com. No analytics data leaves our control. IP addresses are truncated before storage.
3. Marketing (consent required)
None currently in use. If we introduce marketing cookies, we will update this page and request consent before setting them.
4. How to change your choice
- Any public page: the “Cookie preferences” link in the footer opens the preferences modal
- Signed in: Settings → Privacy → Cookie preferences
- Revoking a category clears any cookies belonging to it immediately
5. Global Privacy Control / Do Not Track
We honour the Global Privacy Control (GPC) browser signal as an implicit rejection of all non-essential cookies. Users with GPC enabled will not see the consent banner and will not have analytics or marketing cookies set.
6. Changes
Changes are logged in our repository changelog. Material changes are announced with 30 days’ notice.