Cookie Policy
Last updated: September 5, 2026
Exactly what this site stores in your browser: no tracking cookies, one sign-in cookie for editors, two local preferences.
This site does not use tracking cookies. This page lists everything it can store in your browser, so the answer is complete rather than reassuring.
Cookies
| Name | Set for | Purpose | Lifetime |
|---|---|---|---|
OAuth state (/api/auth) | Content editors only, during sign-in to /admin | Protects the GitHub sign-in handshake against request forgery | Minutes; deleted when sign-in completes |
Visitors to the public site never receive this cookie.
Local storage
| Key | Purpose | Sent anywhere? |
|---|---|---|
m9-sound | Remembers whether interface sounds are on | No |
m9nd:analytics | Remembers that you turned analytics off (absent means on) | No |
Analytics
Usage measurement runs in cookieless mode: it sets no cookies and uses no local or session storage. It is described in the Privacy Policy and can be switched off at Preferences.
Third parties
The only third-party script on the public site is Cloudflare Turnstile, loaded on the Deep Space exposure self-check form to block automated abuse; it runs under Cloudflare's own policies. The Stripe checkout and the contact-form challenge open on their own domains under their own policies when you use them.