Cookie Policy

Effective: 2026-04-22 · Version v2026.04.22

We use cookies and similar storage mechanisms, grouped by purpose. You can accept, reject, or configure non-essential categories at any time using the button above, via the footer link, or from Settings → Privacy → Cookie preferences when signed in.

1. Strictly necessary (no consent required)

Exempted under Art 5(3) ePrivacy Directive because they are strictly necessary for the Service you requested.

NameTypePurposeTTL
guard-core-authhttpOnly secure cookieAuthenticated session (carries a JWT that expires after 15 minutes and is refreshed)4 hours
cookie_consentlocalStorageYour consent choicesUntil cleared
2fa_flowsessionStorageMulti-step 2FA challenge stateSession only

2. Analytics (consent required)

NameTypePurposeTTLProcessor
_rybbit_*first-party cookiesAggregate page-view analytics2 yearsSelf-hosted (analytics.guard-core.com)

Rybbit is self-hosted on our own infrastructure at analytics.guard-core.com. No analytics data leaves our control. IP addresses are truncated before storage.

3. Marketing (consent required)

None currently in use. If we introduce marketing cookies, we will update this page and request consent before setting them.

4. How to change your choice

  • Any public page: the “Cookie preferences” link in the footer opens the preferences modal
  • Signed in: Settings → Privacy → Cookie preferences
  • Revoking a category clears any cookies belonging to it immediately

5. Global Privacy Control / Do Not Track

We honour the Global Privacy Control (GPC) browser signal as an implicit rejection of all non-essential cookies. Users with GPC enabled will not see the consent banner and will not have analytics or marketing cookies set.

6. Changes

Changes are logged in our repository changelog. Material changes are announced with 30 days’ notice.