Cookie Policy

Effective: April 29, 2026

This Cookie Policy explains how Axolotl Army uses cookies and similar local-storage technologies on the Axolotl Army Portal at https://portal.axolotlarmy.net. Read it together with our Privacy Policy, which covers everything else we do with personal data.

1. What cookies are

Cookies are small text files a website asks your browser to store so that the next time you visit, the site can recognize you, remember your preferences, or keep you signed in. Cookies set by the site you are visiting are called “first-party” cookies; cookies set by other domains loaded on the page are called “third-party” cookies. We also use related browser-storage features (localStorage, sessionStorage) which behave like cookies but are not transmitted on every request.

2. Categories of cookies we use

Strictly necessary cookies

These cookies are required for the portal to work. Without them you cannot sign in, stay signed in, or submit forms safely. Under EU ePrivacy rules and the UK PECR, strictly-necessary cookies do not require consent, so we do not show a consent banner for them.

Performance and analytics cookies

None.The portal does not run Google Analytics, Mixpanel, Amplitude, Segment, or any other third-party analytics product, and it does not set any analytics cookies. We collect product usage metrics in our own database (no cookies, no third party); see the “Operational logs” entry in the Privacy Policy for details.

Functionality cookies and local storage

We store a small amount of preference data in your browser's localStorage — most notably your theme preference (dark or light) and the dismiss-state of one-time UI hints. This is not strictly a cookie, but we disclose it here for completeness because the practical effect (a value held in your browser, readable by our JavaScript) is the same. Clearing site data in your browser removes these values.

Advertising and targeting cookies

None. We do not run advertising on the portal and we do not set any cookies for cross-context behavioral advertising, retargeting, or audience building. We do not allow third parties to set advertising cookies through our pages.

3. Specific cookies we set

The cookies below are set by the portal during normal use of the Service. Names beginning with __Secure- are the production-mode equivalents that browsers will only return over HTTPS.

NamePurposeLifetimeTypeCategory
authjs.session-tokenAuthenticated session. Identifies your signed-in account so we can render your portal.30 days (sliding)First-party, HttpOnly, Secure, SameSite=LaxStrictly necessary
authjs.csrf-tokenCross-site request forgery defense for sign-in and account forms.Session (deleted when browser closes)First-party, HttpOnly, Secure, SameSite=LaxStrictly necessary
authjs.callback-urlRemembers the page you were trying to reach so we can return you there after sign-in.SessionFirst-party, HttpOnly, Secure, SameSite=LaxStrictly necessary
__Secure-authjs.session-tokenProduction-mode equivalent of the session cookie above. Sent only over HTTPS.30 days (sliding)First-party, HttpOnly, Secure, SameSite=LaxStrictly necessary
__Secure-authjs.csrf-tokenProduction-mode CSRF cookie.SessionFirst-party, HttpOnly, Secure, SameSite=LaxStrictly necessary
__Secure-authjs.callback-urlProduction-mode callback URL helper. Sent only over HTTPS.SessionFirst-party, HttpOnly, Secure, SameSite=LaxStrictly necessary
portal-theme (localStorage)Remembers your dark/light theme choice between visits.Until you clear site dataFirst-party browser storageFunctionality

4. Third-party cookies

We do not embed third-party trackers in the portal. However, two normal flows redirect you off our domain to a partner who sets their own cookies under their own privacy policy:

Cookies set on those external pages are not under our control. Each provider lists its own cookies and your choices in the policies linked above.

5. Your choices

Because we do not set advertising or analytics cookies, there is no consent banner to dismiss and no opt-out toggle for those categories. If we ever add cookies that require consent, we will deploy a banner that asks before they are set, and update this page.

6. Changes to this policy

We will update this page when the cookies we set change. The “Effective” date at the top reflects the most recent revision. For material changes (for example, adding analytics or consent-required categories) we will email account holders at least 30 days before the change takes effect.

7. Contact

Questions about cookies or this policy: privacy@axolotlarmy.net.