Cookies · last updated 2026-07-10
Short version: essential cookies only, no tracking. That’s why you don’t see a consent banner — under GDPR and CCPA, essential cookies (session, CSRF, security) are exempt from consent requirements.
| Name | Kind | Purpose | Lifespan |
|---|---|---|---|
coalstoke_session | Session | Keeps you logged in to the dashboard. | 90 days rolling; auto-renews on activity |
csrf_token | Session | Prevents cross-site request forgery on form submissions. | Per session |
cf_clearance | Security | Cloudflare anti-bot protection. | 30 days |
All essential cookies are marked HTTP-only where applicable, Secure, and SameSite configured to prevent CSRF.
GDPR (Article 5.3 of the ePrivacy Directive) and CCPA both exempt strictly necessary cookies from consent requirements. Essential cookies for session management, CSRF protection, and security fall in that exempt category.
If we ever add analytics or tracking cookies, I’ll ship a proper consent banner before they go live. That’s a promise.
Your browser has cookie settings that can block all cookies or specific ones. If you block our essential cookies, the dashboard won’t work — you won’t stay logged in. The marketing site (this page, the docs, the blog, etc.) still works fine without cookies.
Questions about cookies? hello@coalstoke.com. Related pages: privacy policy · terms of service.