Privacy controls
Cookies and Browser Storage
The storage used for security, authentication, requested preferences, and optional landing analytics.
Pre-publication draft: this document is not an approved public-beta contract. Publication and open registration remain disabled.
Document: cookies
Version: 2026-07-22-consent-1
Effective date: 2026-07-22
Content hash: 55d5d1f0546b1f1f711eed2b6c7fa83854b1380992c81be28ef0a538beb0739f
Privacy: privacy@gutmask.xyz
Necessary storage
Authentication, refresh, CSRF, MFA challenge, consent-state, and security cookies are used only where required for the requested session or preference.
- Necessary storage is not disabled by rejecting optional analytics.
- Session and security cookies use bounded lifetimes and appropriate HttpOnly, Secure, and SameSite attributes for their role.
Optional landing analytics
The gm_landing_visit identifier and landing impression, page-view, and click attribution are optional analytics. They must not be created before an affirmative analytics choice.
- Essential only prevents new landing assignment and attribution.
- Cookie Settings lets a visitor change or revoke the choice.
Browser preferences
Theme and local shell state may be stored when requested by the user. Exact names, durations, and deletion behavior remain part of the release inventory.
- Questions and rights requests: privacy@gutmask.xyz