Cookie Policy

Effective August 6, 2026 · Last updated August 6, 2026

This page lists every cookie and similar technology the Assistance website uses. There are five, all of them needed to sign you in, keep your session, unlock a package you have the password for, or confirm you are not a bot. We run no analytics, no advertising pixels, no session replay, and no cross-site trackers — so there is no consent banner, because there is nothing to consent to.

1. What cookies are

A cookie is a small file a site stores in your browser and reads back on later requests. The same rules cover technologies that behave like cookies without being cookies: local storage, session storage, pixels, web beacons, and device fingerprinting. Where we use any of those, it is in the table below.

Cookies set by us are called first-party. Cookies set by another company whose code runs on our pages are third-party; we have one, and it is named below.

2. Cookies we set

NameProviderTypePurposeDurationCategory
sessionFirst partyHTTP cookieHolds your signed session so you stay logged in to the dashboard. Set only after you sign in with Discord.7 daysStrictly necessary
session_accountsFirst partyHTTP cookieRemembers which Discord accounts this browser may switch between, so you can move between linked accounts without signing in again.7 daysStrictly necessary
pkg_access_<id>First partyHTTP cookieProves you entered the correct password for one password-protected package, so it is not re-requested on every page. One cookie per package unlocked.1 hourStrictly necessary
cf_clearanceCloudflareHTTP cookieSet by the Cloudflare Turnstile challenge on the verification page to confirm the request came from a real browser rather than an automated one.Up to 30 minutesStrictly necessary
Local storageFirst partyBrowser storageInterface preferences such as theme and the layout of the library view. Never sent to our servers.Until you clear itFunctional

"Strictly necessary" means the cookie is required to deliver something you asked for — staying signed in, opening a package you have the password for, passing a bot check. Under EU and UK rules these do not require consent. We have not put anything optional in that bucket.

The verification pages set a keyed hash of your IP address and a browser signature on our servers for abuse detection. That is not a cookie, and it is described in our Privacy Policy rather than here.

3. Third-party cookies

Cloudflare Turnstile is the only third-party technology that sets a cookie on our pages, and only on the verification flow. It exists to tell a person from a script without profiling you or showing you image puzzles. Cloudflare's handling of it is described in its privacy policy.

We do not embed Google Analytics, Meta, TikTok, LinkedIn, or any other advertising or measurement tag. If that ever changes, this table changes first and we will say so before the tag ships.

4. Your choices

You can block or delete cookies in your browser settings. Because every cookie we set is necessary, blocking them means you will not be able to sign in, switch accounts, open a protected package, or complete verification. Nothing you lose by blocking them is a tracking feature.

Signing out clears your session cookies immediately. Removing Assistance from a Discord server stops data collection for that server.

5. Do Not Track and Global Privacy Control

Browsers send Do Not Track signals inconsistently and no standard for honoring them was ever agreed, so the Service does not respond to DNT. We disclose this because California law requires the disclosure.

We do honor Global Privacy Control signals as opt-out requests. In practice this changes nothing about what we do — we neither sell nor share personal information, and we set no advertising or analytics cookies for a signal to switch off.

6. Changes and contact

We review this table at least twice a year, and whenever we add a dependency that touches the browser. The dates at the top of this page reflect the most recent review.

Questions go to TODO_EMAIL_PRIVACY. This policy is published by TODO_LEGAL_NAME and forms part of our Terms of Service.