Cookie Policy
A short list, because we use very few.
Last updated
1. The short version
TedIS sets two cookies, and both are strictly necessary to sign you in and keep your account secure. We do not use advertising, analytics, or third-party tracking cookies.
2. Cookies we set
| Name | Purpose | Lifetime | Accessible to JavaScript |
|---|---|---|---|
| tedis_session | Keeps you signed in. Holds an opaque session token — never your password. | 30 days (sliding) | No — HttpOnly |
| tedis_csrf | Protects against cross-site request forgery by pairing a cookie value with a request header. | 30 days | Yes — required for the double-submit check |
Both cookies are set with SameSite=Lax, and are marked Secure in production so they are only ever sent over HTTPS.
3. Things that are not cookies
Your theme preference (light or dark) is stored in your browser’s local storage, not in a cookie. It never leaves your device and is not sent to us.
4. Third-party cookies
We do not embed third-party advertising or analytics scripts, so no third party sets cookies through TedIS. Our infrastructure providers may process technical request data — these are listed in the Privacy Policy.
5. Controlling cookies
You can clear or block cookies in your browser settings. Blocking the two cookies above will prevent you from signing in, because the service cannot maintain a session without them.
Signing out, or revoking a session from Settings, invalidates the session server-side — not just in your browser.
6. Contact
Questions about cookies: [email protected].