Cookie Notice
This is the complete list of cookies and browser storage that The Social Web uses. It is short because we use only what is strictly necessary to sign you in and keep your account safe. There are no advertising, analytics, social media or tracking cookies, and there never will be.
1. The short version
We set at most three cookies of our own, all for signing in and security. Cloudflare, which protects our site, may set one or two security cookies when it needs to check that you are not a bot. Your browser also remembers your light or dark mode choice before you sign in. That is everything.
2. Cookies we set
All of our cookies are first-party, HttpOnly (scripts cannot read them), Secure (sent only over HTTPS), SameSite=Lax, and use the __Host- prefix, which locks them to our exact domain.
| Name | Purpose | Lifetime |
|---|---|---|
__Host-sw_session | Keeps you signed in. It holds a random token that identifies your session; the token itself is stored on our server only as a hash. | Up to 30 days, or until you sign out or end the session |
__Host-sw_csrf | Protects the sign-in, sign-up, password-reset and two-factor forms from cross-site request forgery before you have a session. | 1 hour |
__Host-sw_mfa | Remembers, for a few minutes, that you entered the right password and still need to enter your two-factor code. Only set if you use two-factor authentication. | 10 minutes, deleted when you finish signing in |
3. Cookies Cloudflare may set
Cloudflare provides our encryption, firewall and bot protection. When its security systems decide to check a visitor, they may set a security cookie on our domain:
| Name | Purpose | Lifetime |
|---|---|---|
cf_clearance | Records that your browser passed a Cloudflare security challenge, so you are not challenged again on every page. | Set by Cloudflare, typically 30 minutes to a day |
__cf_bm | Helps Cloudflare tell people from automated traffic, if its bot protection is active for a request. | 30 minutes |
The Cloudflare Turnstile bot check on the sign-in, sign-up and password-reset request forms runs in a small frame served by Cloudflare. It may use its own storage inside that frame to do its job. Cloudflare uses this information only to provide security, and it is not used to track you across websites. See the Privacy Policy for what Cloudflare receives.
4. Other browser storage
- Light or dark mode before sign-in: if you switch modes while signed out, your browser's local storage remembers the choice under the key
sw-mode. It never leaves your device. Once you sign in, the choice is saved to your account settings instead. - App files for offline use: our service worker stores copies of the site's own stylesheets, scripts, fonts, logo and offline page in your browser's cache, so the app loads quickly and can show a friendly page when you are offline. It never stores your posts, messages, media or any other personal content.
Profile songs: if you press play on a member's profile song, your browser fetches the audio from the address that member provided. That host may set its own cookies under its own policy; nothing is loaded until you press play.
5. What we never use
No analytics cookies. No advertising cookies. No social media "like" buttons or embeds. No tracking pixels or web beacons. No browser fingerprinting. No third-party cookies of any kind other than the Cloudflare security cookies above. We do not even use privacy-friendly analytics: we simply do not measure you.
6. Why there is no cookie banner
Cookie consent banners exist so that people can refuse cookies that are not needed to provide the service they asked for, like analytics and advertising. Every cookie we use is strictly necessary to sign you in, protect your account or keep bots out, so there is nothing to opt into or out of. Rather than show you a banner with no real choice in it, we list everything here.
7. Controlling cookies
You can view and delete cookies in your browser's settings at any time. If you block or delete our cookies, you will be signed out and will not be able to sign in until you allow them again, because the session cookie is how the service knows it is you. Blocking Cloudflare's cookies may cause you to see more security challenges.
8. Global Privacy Control and Do Not Track
We honor Global Privacy Control and Do Not Track signals. Because we do not track you, sell your information or share it for advertising, there is nothing for these signals to switch off. You get the same no-tracking experience whether or not your browser sends them.
Questions? Email [email protected] or visit Support.