Version v0.14-review.1 / Draft dated 15 August 2026 / Not approved
Cookie and analytics position - review draft
The current repository uses authentication and CSRF cookies plus a browser-local theme preference. It does not enable advertising trackers or product analytics by default. Deployed hosting or later integrations may change those facts.
Current browser storage
The signed HTTP-only session cookie supports authentication. A separate same-site CSRF cookie supports browser mutation protection. Theme preference is held in local storage. Exact expiry and security behavior are documented in the repository cookie position.
Analytics posture
Advertising, cross-site profiling, session replay, and product analytics are disabled by default. No such tool may be enabled until its events, data fields, masking, provider, region, retention, notice, consent/legal basis, and opt-out behavior are reviewed.
Deployment verification
Before publication, inventory hosting/CDN logs, security tools, support widgets, browser monitoring, and customer-added scripts. The final notice and controls must reflect the deployed behavior and applicable national rules.
