Cookies
ServerPulse uses only what is strictly necessary to sign you in, keep forms safe from forgery, and remember choices you make. There are no analytics, advertising or social-media cookies, no third-party scripts, and no third-party fonts — so there is nothing to consent to, and no consent banner — just a one-time note saying so. (ePrivacy Directive Art. 5(3) and the DPDP Act require consent for storage that is not strictly necessary for a service you asked for; none of ours is.)
Cookies
| Name | Purpose | Lifetime |
|---|---|---|
serverpulse_session | Keeps you signed in; on the public site, ties a form to the page that showed it. Encrypted, HttpOnly, Secure, SameSite=Lax. | 8 hours of inactivity |
XSRF-TOKEN | Protects forms against cross-site request forgery. Secure, SameSite=Lax. | Same as the session |
remember_web_… | Only if you tick "Remember me" when signing in. | Until you sign out |
Browser storage (not sent to us)
| Key | Purpose |
|---|---|
sp-theme | Your light/dark choice. |
sp-cookie-note | That you closed the "no tracking cookies" note, so it is not shown again. |
sp-width and similar sp-* keys | Console layout and display preferences you set (page width, panels you opened or dismissed). |
sp:nekoba:* (session only) | Carries a question to the assistant across one page load. |
Public-site statistics without cookies
To see where visitors drop off, the public site records the step reached and the name of a form field — never what was typed — against a code derived from the session and a salt that changes every day. It sets no cookie of its own and cannot recognise you on another day. Details are in the privacy notice.
Changing your mind
You can clear cookies and site data in your browser at any time; you will simply be signed out and your display choices reset. If we ever add anything that is not strictly necessary, it will stay off until you agree to it, and refusing will be as easy as agreeing.