Cookie policy — Linkora
Cookies we set
Linkora uses strictly necessary cookies. There is no advertising cookie and no analytics cookie.
linkora_sid
Set when you sign in. HttpOnly, SameSite=Lax. It carries a random session id. The matching row expires on a 14-day sliding window and never lasts more than 30 days from sign-in. In production deployments it is marked Secure.
linkora_csrf
A random token the browser script can read, so requests that change data can send it back. It is not a tracker. SameSite=Lax.
linkora_form
Set when a page loads. HttpOnly. It records when the form was opened so a script that posts immediately, without waiting for a person, is rejected. It expires after six hours.
linkora_pass
Set only after a person solves the on-site request check. HttpOnly. It lasts about twenty minutes and is tied to that connection so the same check is not shown on every click. It is not an advertising cookie.
linkora_anon
Set only after you shorten a URL. HttpOnly. It lets that browser list, disable, and delete those links. It is not set on a normal page view.
Local storage
The theme choice (light, dark, or system) is stored in local storage under linkora-theme. That is not a cookie and it is not sent to the server.
Consent
Because these cookies are strictly necessary to provide a service you asked for (signing in, or managing a link you just created), this deployment does not show a consent banner for them. If a later version adds optional measurement, it will need a separate choice before those cookies are set.