Cookie Policy
Last updated: 5 August 2026 · Version 1.0
There is no cookie banner, and that is deliberate
Omnidara sets four cookies. All four exist only to provide something you have asked for, which is the exact exemption in Article 5(3) of the ePrivacy Directive - so no consent is required and no banner is shown. We would rather say that plainly than put a pointless dialogue in front of you and ask permission for something we are not doing.
We set no analytics, advertising, marketing, social or cross-site tracking cookies, and no third-party cookies of any kind.
Every cookie we set
| Name | Purpose | Type | Expires |
|---|---|---|---|
| JSESSIONID | Keeps you signed in as you move between pages, and carries the anti-CSRF token that protects every form you submit. Without it, signing in would not be possible. | Strictly necessary | When you close your browser, or when you sign out |
| remember-me | Set only if you tick "Remember me" at sign-in. Lets you return without signing in again. Signed with a server-side secret so it cannot be forged. | Strictly necessary (set at your request) | 14 days |
| omnidara_theme | Remembers whether you chose the light or the dark appearance. Set only when you actually pick one - until then there is no cookie and we simply follow your device's own setting. It holds one word, light or dark, and nothing else. It exists because these pages are rendered on the server: without it the server could not know which appearance to send, and every page would flash the wrong one before correcting itself. | Preference (set at your request) | 1 year, or immediately when you switch back to "System theme" |
| omnidara_sidebar | Remembers that you collapsed the app's side navigation to its icons. Set only when you collapse it - until then there is no cookie and the navigation is shown in full. It holds one word, collapsed, and nothing else. Same reason as the appearance cookie: the pages are rendered on the server, and without it every page would open at full width and then narrow. | Preference (set at your request) | 1 year, or immediately when you expand the navigation again |
Signing out deletes the first two. You can clear any of them from your browser's settings at any time; the only consequence is that you will be asked to sign in again, the appearance goes back to following your device, and the navigation opens in full again.
Local storage and similar technologies
We do not use localStorage, sessionStorage, IndexedDB, fingerprinting or tracking pixels.
Third-party requests
A small number of things can involve a request from your browser reaching another company. None of them sets a cookie on our domain, and each is disclosed here:
- Stripe - only when you start a checkout or open the billing portal, at which point you are redirected to Stripe's own pages. Any cookies set there are Stripe's, on Stripe's domain, under Stripe's privacy policy. Nothing from Stripe runs on our pages.
- Google - only if the login page offers "Continue with Google" and you choose it, at which point you are redirected to Google's own sign-in pages. Any cookies set there are Google's, on Google's domain, under Google's privacy policy. Nothing from Google runs on our pages, and we set no additional cookie of our own for it - the sign-in handshake lives inside the same session cookie listed above.
- Cloudflare - only if a bot check is shown on the sign-in, sign-up or password-reset forms. The check is Cloudflare Turnstile, loaded from challenges.cloudflare.com; it exists to keep automated abuse off those forms, and it is the one script our content security policy allows from anywhere but our own domain. Any state it keeps is Cloudflare's, under Cloudflare's privacy policy.
All application JavaScript, styling and typefaces are served from our own domain, with a single named exception: the bot-check script above, allowed from exactly one Cloudflare host and nothing else. Our content security policy allows scripts and fonts from no other origin, so this list cannot quietly grow.
If this changes
If we ever add a cookie that is not strictly necessary, we will ask for your consent before setting it, and update this page first. Questions: [PRIVACY CONTACT EMAIL].