Cookie Policy
This Cookie Policy explains how Chispa uses cookies and similar technologies in the web application. It is a companion to the Privacy Policy and Terms of Service. Capitalized terms not defined here have the meaning given there.
1. What are cookies and similar technologies
Cookies are small text files a website places on your device. "Similar technologies" include browser storage: localStorage and sessionStorage (key-value stores that persist across page loads, indefinitely or until the tab closes). Together we call these "Cookies and Storage". We do not currently use service workers or IndexedDB for tracking.
2. First-party cookies we set
All cookies we set are strictly necessary to operate the Service. We do not set analytics or marketing cookies.
| Name | Purpose | Duration | Attributes |
|---|---|---|---|
sid | Authenticates your session (keeps you signed in). | Up to ~24 hours | HttpOnly, Secure (HTTPS), SameSite=Lax |
csk | Secures your requests against tampering and cross-site request forgery (request signing). Readable by the app to sign requests. | ~1 hour (rotated) | Secure (HTTPS), SameSite=Lax |
3. Edge and security cookies (Cloudflare)
Our content-delivery and security provider, Cloudflare, sits in front of the Service. Where its bot-mitigation and security protections are enabled, Cloudflare may set its own strictly-necessary cookies at the network edge:
| Name | Purpose | When |
|---|---|---|
__cf_bm | Bot management and abuse mitigation. | If bot management is enabled |
cf_clearance | Records that a security challenge was passed. | Only if a challenge is presented |
These are managed by Cloudflare, not by us; see the Cloudflare Privacy Policy. Our product-usage measurement (Cloudflare Web Analytics) is cookieless.
4. Browser storage
We use localStorage and sessionStorage for functional preferences and interface state, for example, your language choice, notification and animation/SFW preferences, message drafts so they are not lost on reload, recent emojis, and per-conversation interface state. This data stays in your browser; it is not personal data shared with third parties.
5. What we do not use
We do not use advertising, marketing or cross-site tracking cookies; we self-host our fonts (no third-party font provider is contacted to render the page); and we do not embed a third-party card-payment widget (top-ups use a cryptocurrency processor off our pages).
6. Legal basis and consent
Strictly necessary cookies do not require consent under applicable law because the Service cannot function without them. Functional storage is used to honor your preferences. Where consent is required for any non-essential technology, we will obtain it.
7. Managing Cookies and Storage
Because our cookies are strictly necessary, disabling them will prevent sign-in and core features. You can clear or block Cookies and Storage through your browser settings, and manage Cloudflare's cookies subject to its policy.
8. Changes and contact
We may update this policy at any time; the current version and effective date are shown on this page. Contact: [email protected].