Cookies

Cookie policy

One cookie, set only if you sign in, with no way to switch it off because without it there is no sign-in. That is the entire list.

Last updated 8 September 2026

Why there is no consent banner

Consent is required for storage that is not strictly necessary - analytics, advertising, profiling, anything that follows you. Gatebound uses none of it. The one cookie below exists solely to keep you signed in to a control panel you deliberately signed in to, which is exactly the exemption for strictly necessary storage under the ePrivacy Directive and the UK PECR. Asking you to opt in to it would be a box that cannot say no.

You will still see a short notice the first time you visit. It is an explanation, not a gate, and dismissing it stores a flag in your browser's local storage rather than setting a cookie.

Cookies this site sets

NamePurposeLifetimeType
__Host-gatebound_session Holds the random sign-in token created when you redeem a six-digit link code, so the control panel knows which linked profiles belong to this browser. The server keeps only a SHA-256 hash of it. 90 days, or until you use Sign out device Strictly necessary, first party

The cookie is HttpOnly so scripts cannot read it, Secure so it never leaves over plain HTTP, SameSite=Lax so another site cannot cause it to be sent, and __Host- prefixed so it is locked to this exact origin. If you never sign in, it is never set.

Other browser storage

KeyKindPurposeLifetime
gatebound.cookie-noticeLocal storage Remembers that you dismissed the notice above, so it does not return on every page.Until you clear site data

What this site does not use

  • No analytics or measurement cookies of any kind.
  • No advertising, retargeting or profiling cookies.
  • No social media buttons, embedded videos, fonts or scripts from other origins - the stylesheet, the script, the font and the images are all served from this domain, which the page's content security policy enforces.
  • No cookies at all on the public pages. Read the whole site signed out and your browser will hold nothing from it but the notice flag.

Removing it

Use Sign out device in the control panel, which revokes the token on the server as well as clearing the cookie. Clearing site data in your browser removes the cookie and the notice flag, but does not revoke the server-side session - so on a shared computer, sign out properly. Blocking cookies for this site entirely is fine: everything except the control panel keeps working.

Questions about any of this go to privacy@gatebound.net.