Draft Cookie Policy
Draft dated 2026-08-21
1. Essential cookie inventory
Only these two essential entries are used to operate and protect Postsie. They are not used for advertising or profiling.
2. Session security and duration
The session cookie is host-only, so it is not shared across subdomains. It is HTTP-only, uses SameSite Lax, and is marked Secure in staging and production.
It follows the configured short session duration and expires after that idle period rather than indefinitely.
3. CSRF scope and duration
The CSRF cookie or corresponding token is used only to protect state-changing requests where it is emitted. It is scoped to the current host and follows the same session-duration category.
4. Optional cookies and consent
Postsie does not currently set advertising, cross-site tracking, or optional analytics cookies. No consent banner is shown because no optional cookie or script is loaded.
Any future optional cookie or script requires an updated inventory and an approved legal basis. Genuine pre-load consent must be obtained wherever applicable law requires it before that cookie or script is enabled.