Cookie policy — Linkora

Cookies we set

Linkora uses strictly necessary cookies. There is no advertising cookie and no analytics cookie.

linkora_sid

Set when you sign in. HttpOnly, SameSite=Lax. It carries a random session id. The matching row expires on a 14-day sliding window and never lasts more than 30 days from sign-in. In production deployments it is marked Secure.

linkora_csrf

A random token the browser script can read, so requests that change data can send it back. It is not a tracker. SameSite=Lax.

linkora_form

Set when a page loads. HttpOnly. It records when the form was opened so a script that posts immediately, without waiting for a person, is rejected. It expires after six hours.

linkora_pass

Set only after a person solves the on-site request check. HttpOnly. It lasts about twenty minutes and is tied to that connection so the same check is not shown on every click. It is not an advertising cookie.

linkora_anon

Set only after you shorten a URL. HttpOnly. It lets that browser list, disable, and delete those links. It is not set on a normal page view.

Local storage

The theme choice (light, dark, or system) is stored in local storage under linkora-theme. That is not a cookie and it is not sent to the server.

Consent

Because these cookies are strictly necessary to provide a service you asked for (signing in, or managing a link you just created), this deployment does not show a consent banner for them. If a later version adds optional measurement, it will need a separate choice before those cookies are set.