01 What cookies are
Cookies are small text files stored on your device when you visit a website. Similar technologies, such as local storage, work in comparable ways. Together they let a Service remember information between requests, such as your session or your preferences.
We use only the cookies described below. We do not use cookies to build advertising profiles. This policy forms part of, and should be read with, our Privacy Policy.
02 Cookie categories we use
We group cookies into the following categories. Strictly necessary cookies are always active; all others are set only with your consent.
Required for core functionality such as sign-in, session management, security, and remembering consent choices. Includes the unified Arcnode session cookie (arcnode_session, issued by the identity provider across .arcnode.dev), the consent-choice cookie (arcnode_consent), the short-lived Discord linking cookie (discord_oauth_state), the short-lived survey invitation cookie (survey_invite), and the legacy session cookies (client_token, admin_token) that remain valid during the migration to the unified account. These cannot be switched off.
Retention: Session or short-lived for most cookies (a few minutes for discord_oauth_state, up to 2 hours for survey invitation access), up to 12 months for the consent-choice cookie, and up to 30 days for the legacy client_token session (7 days for the legacy admin_token session).
Remember preferences and settings to provide enhanced, personalized functionality.
Retention: Up to 12 months.
Help us understand how the platform is used, in aggregated and privacy-respecting form, so we can improve it.
Retention: Up to 12 months.
Reserved for future use. No marketing cookies are currently set. If introduced, they will only run with explicit consent.
Retention: Not applicable; currently disabled.
The Platform uses the following strictly necessary cookies for signing in and remembering your consent choice:
- arcnode_session: the unified Arcnode session, set by the Identity Provider (backboard.arcnode.dev) when you sign in to your Arcnode Account. It is httpOnly, Secure, SameSite=Lax, and scoped to .arcnode.devso a single sign-in works across the website, Client Portal, and other network services. It carries a signed session token that each Service verifies against the Identity Provider's public keys; it is never readable by client-side scripts.
- arcnode_consent: records the cookie categories you have accepted or declined, so we do not ask again unnecessarily. It is SameSite=Lax, is not httpOnly (so the site can read your choice), and lasts up to 12 months.
- discord_oauth_state: a short-lived, httpOnly cookie set only while you link a Discord account to your Arcnode Account. It protects the linking flow against cross-site request forgery and is deleted as soon as linking completes.
- client_token and admin_token: legacy httpOnly, Secure session cookies (30 days and 7 days respectively) that remain valid during the migration to the unified arcnode_session. They are never accessible to client-side scripts.
Analytics does not use cookies
When you consent to analytics, we do not set an analytics cookie. Our first-party visit measurement sends an anonymous, aggregated request to our own servers, and the cookieless Vercel analytics we use do not store identifiers on your device. Declining analytics stops both.
03 Survey-related cookies and storage
Public surveys on the Platform use a small amount of additional storage, all of it either strictly necessary or kept entirely on your own device:
- survey_invite: a strictly necessary cookie set when you open a valid invitation link to an invite-only survey. It is httpOnly, Secure, SameSite=Lax, scoped to survey pages, and expires after at most 2 hours. It contains a signed reference to your invitation, never the invitation token itself, and exists so the invitation link can be removed from your address bar.
- Cloudflare Turnstile: survey pages that use spam protection load Cloudflare Turnstile, a third-party verification service. Cloudflare may set its own cookies or use similar storage under the challenges.cloudflare.com domain to distinguish humans from automated traffic. This storage is strictly necessary for spam prevention on those forms and only occurs on pages where Turnstile is active.
Local draft storage is not a cookie
Where a survey enables it, your unfinished answers are kept in your browser's local storageso you can continue later. This is not a cookie: the draft is never sent to our servers, stays entirely on your device, and is deleted when you submit the survey or choose “Start over”. You can also remove it at any time by clearing your browser storage.
04 Consent management
For any non-essential cookie, we ask for your consent before it is set, in line with the AVG / GDPR and applicable e-privacy rules. Strictly necessary cookies do not require consent because the Service cannot function without them.
When consent is needed, you can accept or decline each optional category. Your choice is remembered using a strictly necessary cookie so that we do not ask again unnecessarily.
05 Withdrawing consent
You can withdraw your consent at any time, with the same ease as giving it. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
- Update your choices wherever the Service presents its cookie preferences.
- Clear cookies through your browser settings, as described in section 6.
- Contact legal@arcnode.dev if you need help exercising this right.
06 Managing cookies in your browser
Most browsers let you view, block, or delete cookies through their settings. You can usually choose to be warned before a cookie is stored, or to refuse cookies entirely.
Blocking necessary cookies
Strictly necessary cookies keep core features such as sessions and security working. If you block them, parts of the Arcnode Network Platform at arcnode.dev may not function as intended.
07 Changes to this policy
We may update this policy if the cookies we use change or when required by law. The effective date above reflects the current version. Where a change affects optional cookies, we will ask for your consent again where required.
08 Contact
For any question about cookies or your consent choices:
Arcnode Network, Netherlands
legal@arcnode.dev