Cookie policy
1. What a cookie is
A cookie is a small piece of text a website asks your browser to keep and send back on the next request. It is what lets a site recognise that two page loads came from the same person, which is the only reason Wordfolk uses them.
This policy sits alongside the privacy policy, which covers everything else we do with personal data.
2. The cookies we set
Every cookie Wordfolk sets today exists to keep you signed in. There are no advertising cookies and nothing that follows you between sites.
| Purpose | Category | What it is for | Lifetime |
|---|---|---|---|
| Session | Strictly necessary | Identifies your signed-in session. Without it, signing in would not survive loading the next page. | 7 days |
| Sign-in preference | Strictly necessary | Records that you did not ask to stay signed in, so the session ends when you close the browser. | Until you close the browser |
All three are set only once you sign in. Browsing the directory signed out sets no cookies at all.
We describe these by what they do rather than printing their internal names, which change when the software behind them does. Your browser will show you the exact names and values for this site at any time, under its own storage or cookie settings.
How they are protected
- They are marked HttpOnly, so scripts running in the page cannot read them. A cross-site scripting bug could not steal your session this way.
- They are marked Secure in production, so they are only ever sent over an encrypted connection.
- They are marked SameSite=Lax, which blocks them from being sent along with most cross-site requests. Lax rather than Strict deliberately: your session has to survive returning from the payment provider's checkout and following a link from an email we sent you, and Strict would sign you out at both.
In production they also carry a prefix that tells the browser to refuse the cookie outright if it ever arrives over an unencrypted connection.
3. Third-party cookies
One third party can set a cookie through Wordfolk: the bot check on our sign-up, password-reset, contact and newsletter forms. It is provided by a specialist supplier, and any cookie it sets belongs to that supplier's own domain rather than ours. Its purpose is to tell a person from an automated script. It is not used for advertising or cross-site tracking, and we receive no profile of you from it.
The check loads only on those four forms. Every other page on the site loads it not at all.
Beyond the bot check, very little third-party code runs here. There is no advertising network, no social embed and no comment widget, and our fonts are served from our own servers. The one other outside request a page makes is for blog icons and sponsored images, which come from our image host, so that host sees the IP address and browser that asked for them, as any web server would.
4. What we keep in your browser
Two things are kept in your browser's own storage rather than in a cookie. Neither is ever sent to us, and neither identifies you.
- A pending action. If you try to save or endorse a blog while signed out, we remember which one while you sign in, and carry it out afterwards so you do not lose your place. It is cleared as soon as it is used, and when you close the tab.
- An administrator's view preference on the audit log page. Only administrators ever have this, and it records a display setting, nothing else.
You can clear both at any time by clearing site data for wordfolk.app in your browser.
5. Why there is no consent banner
You have not seen a cookie banner here, and that is deliberate rather than an omission.
UK and EU rules require consent before storing anything on your device that is not strictly necessary for a service you asked for. Every cookie above is strictly necessary in that sense: each one exists solely to keep you signed in, and none of them exists to profile or advertise to you. As things stand there is no non-essential cookie to ask you about, so a banner would be asking permission for nothing.
If we ever add anything that does need consent, we will ask before setting it, and this page will say so first.
6. Controlling cookies yourself
Your browser can block or delete cookies for any site, usually under a Privacy or Site settings menu. Blocking ours has one consequence, which is worth knowing before you do it: you will not be able to stay signed in, so submitting a blog, saving a listing, or buying a placement will not work.
Browsing, searching and reading the directory work perfectly well with cookies blocked, because none of it needs an account.
Signing out clears your session cookies immediately. Changing your password clears every other session's as well.
7. Changes to this policy
If the cookies we set change, this page changes with them, and the date at the top will move. A change that introduced a cookie needing consent would be announced before it took effect, not after.
8. Contact
Questions about cookies or anything else on this page: hello@wordfolk.app.