Session cookie
It is first-party, HttpOnly, SameSite=Lax and Secure in production. Blocking it prevents sign-in and use of the private area.
The current version does not intentionally enable analytics, marketing, remarketing or profiling cookies.
| Name | Type | Purpose | Duration | Category |
|---|---|---|---|---|
cornerengine_session | Cookie HTTP | Authentication, session, roles, permissions and CSRF protection. | up to 8 hours | strictly necessary |
cornerengine-theme | localStorage | Stores the user's explicit light/dark choice. | until changed or cleared | functional preference |
language | server session | Stores the selected RO/EN language. | up to 8 hours | necessary / preference |
It is first-party, HttpOnly, SameSite=Lax and Secure in production. Blocking it prevents sign-in and use of the private area.
The light/dark value is written only when the user changes the theme. It contains no account identifier and is not used for advertising.
Bootstrap and Bootstrap Icons are loaded through cdn.jsdelivr.net, a third-party provider. The browser connects directly to that provider to receive files and transmits normal technical data such as IP address and request headers. CornerEngine does not use this connection for profiling and does not claim that jsDelivr installs CornerEngine cookies.
You can inspect and clear cookies and localStorage in browser settings. Clearing the session signs you out; clearing the theme restores the default.
Any analytics, marketing or profiling must be documented here, blocked before consent and accompanied by equally accessible accept and reject choices before activation.
Romanian Law no. 506/2004, Article 4(5)-(6), governs consent for storage/access on terminal equipment and the technical or strictly-necessary exceptions. CornerEngine keeps optional tracking disabled until a real consent mechanism exists.
This policy describes technologies detected in the current version. Any analytics, marketing or other optional technology requires a new review before activation.