Cookie Policy
DRAFT — NOT YET IN FORCE. The inventory below must be verified against what the services actually set before publication. A cookie policy that under-declares is a finding; one that over-declares is confusing.
The rule we follow
Under the ePrivacy Directive and UK PECR, we may set strictly necessary cookies without asking. Everything else requires your consent before it is set — not after, and not on the basis of continued browsing.
Consent is per-site. Because our services run on separate domains, a choice you make on one does not carry to another; each will ask you once.
Strictly necessary — no consent required
These cannot be switched off without breaking the service.
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
| Session identifier | our services | keeps you signed in | session |
| Authentik SSO session | login.afterdarksys.com | single sign-on across our services | session |
| CSRF token | our services | prevents cross-site request forgery | session |
| Consent record | this site | remembers your cookie choices | 6 months |
[VERIFY: exact cookie names, domains, and lifetimes need to be read out of the running services rather than assumed.]
Anti-automation
Some of our sites use CaptchANG to distinguish humans from automated traffic. It analyses interaction patterns in the page while you are on it. Those signals are used at the moment of the request and are not stored, so there is no persistent identifier to consent to.
Where CaptchANG sets any storage at all, it is strictly necessary — it exists to protect the service from abuse, which is the classic case for the exemption.
[VERIFY: confirm whether CaptchANG sets any cookie or local storage entry at all. If it stores a token across requests, it belongs in the table above with its lifetime stated.]
Analytics — consent required
We run our own analytics rather than sending your browsing to a third-party advertising network.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Analytics identifier | counting visits and understanding which pages are used | [VERIFY] |
These are only set if you agree. If you decline, the service works exactly the same.
[VERIFY: confirm whether the analytics service sets any client-side identifier, or whether measurement is entirely server-side. If server-side and not linked to an individual, it may fall outside the consent requirement — worth confirming, because it would simplify the banner considerably.]
What we do not use
- No advertising cookies
- No cross-site tracking pixels
- No social media embeds that set cookies
- No data broker or audience-matching tags
Changing your mind
You can withdraw or change consent at any time. Withdrawing is as easy as giving it.
[VERIFY: this requires a persistent "Cookie settings" control in the site footer. It is not built yet, and this paragraph must not publish until it is — claiming a control that does not exist is itself a violation.]
You can also block or delete cookies in your browser. Blocking strictly necessary cookies will sign you out and prevent sign-in.
Do Not Track and Global Privacy Control
We honour Global Privacy Control (GPC) signals where your browser sends one. Because we do not sell or share personal information, a GPC signal does not change much for us, but we respect it.
[VERIFY: confirm GPC handling is implemented before publishing this section.]