Cookie policy
- In force since
- 29 August 2026
- Version
- 2026-08-29
Draft — not in force. The operator’s details are not filled in, so this document names nobody and binds nobody. Set LEGAL_NAME, LEGAL_TAX_ID, LEGAL_ADDRESS and LEGAL_CONTACT_EMAIL before taking any money. A production server refuses to start until you do.
This site sets one cookie, and only once you sign in. There is no analytics, no advertising, no tracking and no third-party script watching you — which is why you are not being asked to accept anything.
The cookie
- am_session
- Keeps you signed in. It holds a random session token and nothing else — no name, no email, no identifier that means anything outside our own database. It is set when you sign in and removed when you sign out.
- Lifetime: 30 days, or until you sign out.
- HttpOnly: yes. JavaScript on the page cannot read it, which is what stops a script injection from stealing your session.
- SameSite: lax, so it is not sent along with requests started by other sites.
- Secure: yes in production — it only travels over HTTPS.
Why there is no cookie banner
Consent is required for cookies that are not necessary to provide the service you asked for — analytics, advertising, profiling. A cookie that exists solely to keep you signed in is exempt, and that is the only one here.
If we ever add analytics or anything that tracks you, this page will change and you will be asked before it is set. We would rather not have to.
What about Stripe?
Payment happens on Stripe’s own hosted checkout page, not on this site. While you are there you are on Stripe’s domain and Stripe may set its own cookies, mainly to detect fraud, under its own policy. We do not embed Stripe’s scripts in our pages, so nothing of theirs is set while you are browsing the board.
Refusing or removing it
You can clear or block cookies in your browser settings. Blocking this one means you cannot stay signed in, so you will not be able to submit a project or place a bid — everything else on the site works without signing in.