Draft — not legal advice. This document is a starting template and must be reviewed by a qualified lawyer before launch. Bracketed items like [Company name] must be completed.
Cookie Notice
Last updated: October 5, 2026
CtrlShiftQR uses only strictly necessary cookies and local storage. We don't use advertising or third-party analytics cookies, and we set no cookies at all on people who are redirected by a QR code or short link.
What we store
| Name | Type | Purpose | Duration |
|---|---|---|---|
| authjs.session-token | Cookie | Keeps you signed in (encrypted session). | 30 days |
| authjs.csrf-token | Cookie | Protects sign-in forms against cross-site request forgery. | Session |
| authjs.callback-url | Cookie | Remembers where to send you after signing in. | Session |
| theme | Local storage | Remembers light/dark mode. | Until cleared |
| cookie-notice | Local storage | Remembers that you dismissed this notice. | Until cleared |
On HTTPS the session cookies are prefixed with __Secure-. Because these are strictly necessary, they don't require consent under the ePrivacy Directive; blocking them will prevent you from signing in. [Confirm with counsel; add a consent mechanism if non-essential cookies are ever introduced.]