Cookie Policy
Essential storage, explained.
Effective August 25, 2026 · Version 2026-08-25
Publish Your Profile uses cookies and short-lived browser storage needed for sign-in, security, navigation, and accurate first-party visit counting. The current service does not place advertising cookies or use browser fingerprints for profile analytics.
1. Essential authentication cookies
Secure, HTTP-only cookies keep a signed-in session associated with the correct account and support security controls such as OAuth state and multi-factor authentication. A normal session may last up to 30 days and can be refreshed while the account remains active. Signing out, changing security-sensitive credentials, or deleting the account may clear or invalidate it sooner. During email signup, a signed HTTP-only eligibility-intent cookie records only that the self-declared adult-eligibility check passed, issuance and expiry times, and a random nonce for up to ten minutes. It never contains the date of birth and is cleared when the credential account-creation challenge begins.
Google or enterprise sign-in uses provider OAuth-state cookies and a restricted pending-session cookie before the date-of-birth step. The pending session can only finish setup, inspect the session, or sign out; it cannot use product features.
The server keeps a short-lived one-way hash of that random nonce and its status to stop the cookie from being replayed. This security receipt is not another browser cookie, contains no account identity or date of birth, and is normally removed within one day.
If the eligibility check does not pass, a separate signed HTTP-only denial cookie records only that this browser had a denied eligibility attempt, plus issuance and expiry times and a random nonce. It applies across signup methods to prevent immediate date changes and repeated attempts for 24 hours. It contains no date of birth, exact age, account identity, email, phone number, or provider subject.
2. Session storage in your browser
The application uses browser session storage to remember a safe post-login destination, prevent a page refresh loop after a service worker update, and avoid counting the same profile or Web Profile view repeatedly in one browser tab. Session storage normally disappears when that tab or browsing session ends.
3. Payments and third-party sign-in
If you choose Google sign-in or continue to Stripe Checkout, that provider may set cookies on its own website for authentication, security, fraud prevention, or payment processing. Those cookies are controlled by the provider and covered by its policy, not this service's first-party cookie settings.
4. Essential offline-page cache
The service worker uses browser Cache Storage to keep only the service's offline, slow-connection, and maintenance pages available when the network fails. It does not intentionally cache signed-in dashboards, public profiles, messages, billing pages, or submitted form data. A newer service-worker version replaces the earlier app-shell cache; browser site-data controls can remove it sooner.
5. Your choices
Browsers can delete or block cookies and site storage. Blocking essential cookies may prevent sign-in, checkout, account security, or other requested features from working. Because the current application uses only essential first-party cookies, it does not offer an advertising-cookie preference panel.
6. Future changes
If optional analytics, advertising, or similar non-essential technologies are introduced, this policy and any legally required consent controls will be updated before they are enabled. For more about associated information, read the Privacy Policy.
