Why you are not being asked to consent
Consent is required for storing information on your device unless it is strictly necessary to provide the service you asked for. Every cookie below is strictly necessary: without them you could not stay signed in, and forms could not be protected against cross-site request forgery. We run no analytics, advertising or profiling cookies, on the application or on the sites we publish for customers, so there is nothing to ask you about.
Cookies we set
| Name | Purpose | Lifetime |
|---|---|---|
laravel-session |
Identifies your session so you stay signed in as you move between pages. It holds an identifier, not your data. | 120 minutes of inactivity |
XSRF-TOKEN |
Carries the token that proves a form submission came from a page we served, blocking cross-site request forgery. | 120 minutes of inactivity |
remember_web_* |
Set only if you tick "Remember me" when signing in, so you are not asked for your password on every visit. Signing out removes it. | Up to 5 years, or until you sign out |
All of them are restricted to our own domain, sent only over HTTPS in production, and marked so that scripts on the page cannot read the session and remember-me values.
Stored on your device, but not a cookie
Your light or dark appearance preference is kept in your browser's local storage, so the right theme is applied before the page paints. It never leaves your browser and is not sent to us.
Sites published through OnlyText
The files we serve on behalf of customers set no cookies for visitors. The analytics a customer sees — which files were read, which parts of them, and whether the reader was a person or an AI agent — are derived from server-side delivery records, not from anything stored on the visitor's device.
Controlling cookies
You can delete or block cookies in your browser settings. Blocking the ones listed here will stop you from signing in to OnlyText, because there would be nothing to carry your session.
How the resulting data is handled is described in the privacy policy.