Version v0.14-review.1 / Draft dated 15 August 2026 / Not approved

Cookie and analytics position - review draft

The current repository uses authentication and CSRF cookies plus a browser-local theme preference. It does not enable advertising trackers or product analytics by default. Deployed hosting or later integrations may change those facts.

Current browser storage

The signed HTTP-only session cookie supports authentication. A separate same-site CSRF cookie supports browser mutation protection. Theme preference is held in local storage. Exact expiry and security behavior are documented in the repository cookie position.

Analytics posture

Advertising, cross-site profiling, session replay, and product analytics are disabled by default. No such tool may be enabled until its events, data fields, masking, provider, region, retention, notice, consent/legal basis, and opt-out behavior are reviewed.

Deployment verification

Before publication, inventory hosting/CDN logs, security tools, support widgets, browser monitoring, and customer-added scripts. The final notice and controls must reflect the deployed behavior and applicable national rules.