Cookie Policy

Cookies and trackers in use, by category.

Cookie Policy is not yet published.

The text below is a draft awaiting legal review. It is not in force, no part of it creates any obligation or right, and nothing on this page should be relied on. Passages marked [TO BE CONFIRMED] are values that have deliberately been left blank rather than guessed.

Catomni Studio handles information about children, so these documents go to a lawyer before they take effect rather than being generated and published.

If you need answers about how your data is handled before these are published, contact your studio directly.

Draft revised: 2026-08-17

Notes for legal review

Open questions and drafting assumptions in this document. These notes are removed when the document goes into force.

  • DRAFT for review. The table below is the actual cookie inventory, taken from the code, with real names and lifetimes — not a generic list.
  • There are no advertising or analytics cookies and no third-party tracking scripts, which is why no consent banner is presented. That position is defensible for strictly-necessary cookies, but the theme preference cookie is arguably a functional rather than strictly-necessary cookie. Confirm the position for UK/EU visitors under PECR and the ePrivacy Directive.

1. Cookies we set

We keep this deliberately small. Every cookie below exists to make the platform work or to keep it secure.

NamePurposeLifetimeCategory
catomni_sessionKeeps you signed in. Sent only over HTTPS in production and not readable by scripts.30 days, extended when it is close to expiringStrictly necessary
catomni_oauth_stateProtects the Google sign-in flow against cross-site request forgery.10 minutesStrictly necessary
catomni_impersonationRecords an authorised administrator support session. Only set when such a session is started.30 minutes, fixed and non-extendingStrictly necessary
catomni-themeRemembers whether you chose the light, dark or system appearance.1 yearFunctional

2. Third-party cookies

  • Cloudflare Turnstile, on forms on our website, to tell a person from a bot without asking you to solve a puzzle. It may set a token for that purpose.
  • Stripe, on pages where a payment is entered, for payment processing and fraud prevention. Stripe's own cookie notice applies to those.
  • Cloudflare, as our hosting and security provider, may set a cookie to manage traffic and mitigate attacks.

3. What we do not use

We do not use advertising cookies, and we do not embed third-party analytics, advertising or social media tracking scripts. We do not track you across other websites, and we do not sell or share personal information for advertising. Because of that there is nothing here to opt out of, and we do not present a cookie consent banner.

4. Managing cookies

Your browser can block or delete cookies. Blocking the session cookie will prevent you from signing in, because there is no other way for the platform to recognise you between requests. Clearing the appearance cookie simply returns the interface to following your system setting.

We honour Global Privacy Control and Do Not Track signals to the extent they apply, which in practice means there is nothing for them to change: we do not sell or share personal information, and we run no cross-site tracking.

5. Contact

Questions about this policy: [TO BE CONFIRMED: privacy contact email].