Cookie Policy
Cookies and trackers in use, by category.
Cookie Policy is not yet published.
The text below is a draft awaiting legal review. It is not in force, no part of it creates any obligation or right, and nothing on this page should be relied on. Passages marked [TO BE CONFIRMED] are values that have deliberately been left blank rather than guessed.
Catomni Studio handles information about children, so these documents go to a lawyer before they take effect rather than being generated and published.
If you need answers about how your data is handled before these are published, contact your studio directly.
Draft revised: 2026-08-17
Notes for legal review
Open questions and drafting assumptions in this document. These notes are removed when the document goes into force.
- DRAFT for review. The table below is the actual cookie inventory, taken from the code, with real names and lifetimes — not a generic list.
- There are no advertising or analytics cookies and no third-party tracking scripts, which is why no consent banner is presented. That position is defensible for strictly-necessary cookies, but the theme preference cookie is arguably a functional rather than strictly-necessary cookie. Confirm the position for UK/EU visitors under PECR and the ePrivacy Directive.
1. Cookies we set
We keep this deliberately small. Every cookie below exists to make the platform work or to keep it secure.
| Name | Purpose | Lifetime | Category |
|---|---|---|---|
| catomni_session | Keeps you signed in. Sent only over HTTPS in production and not readable by scripts. | 30 days, extended when it is close to expiring | Strictly necessary |
| catomni_oauth_state | Protects the Google sign-in flow against cross-site request forgery. | 10 minutes | Strictly necessary |
| catomni_impersonation | Records an authorised administrator support session. Only set when such a session is started. | 30 minutes, fixed and non-extending | Strictly necessary |
| catomni-theme | Remembers whether you chose the light, dark or system appearance. | 1 year | Functional |
2. Third-party cookies
- Cloudflare Turnstile, on forms on our website, to tell a person from a bot without asking you to solve a puzzle. It may set a token for that purpose.
- Stripe, on pages where a payment is entered, for payment processing and fraud prevention. Stripe's own cookie notice applies to those.
- Cloudflare, as our hosting and security provider, may set a cookie to manage traffic and mitigate attacks.
3. What we do not use
We do not use advertising cookies, and we do not embed third-party analytics, advertising or social media tracking scripts. We do not track you across other websites, and we do not sell or share personal information for advertising. Because of that there is nothing here to opt out of, and we do not present a cookie consent banner.
4. Managing cookies
Your browser can block or delete cookies. Blocking the session cookie will prevent you from signing in, because there is no other way for the platform to recognise you between requests. Clearing the appearance cookie simply returns the interface to following your system setting.
We honour Global Privacy Control and Do Not Track signals to the extent they apply, which in practice means there is nothing for them to change: we do not sell or share personal information, and we run no cross-site tracking.
5. Contact
Questions about this policy: [TO BE CONFIRMED: privacy contact email].