1. What cookies are
Cookies are small values stored by a browser. Some are strictly necessary for a requested service; optional cookies may measure audiences, remember non-essential preferences or support advertising.
2. Cookies used now
| Name | Purpose | Duration | Scope |
|---|---|---|---|
th_cookie_notice_v1 | Remembers that the visitor continued with necessary cookies; contains only the value “necessary”. | 180 days | Public site · first party |
th_admin_session | Authenticates the single owner in Admin. HttpOnly, SameSite=Strict and Secure on HTTPS; the token is stored only as a server-side hash. | Up to 8 hours; 30-minute idle limit | Only /admin · first party |
3. Optional categories
- Functional — off. No non-essential language, theme or personalization cookie is used.
- Analytics — off. Google Analytics, Tag Manager and similar tools are not connected.
- Marketing — off and not recommended. No advertising pixels, cross-site tracking or profiling.
If an optional provider is proposed later, this policy and the consent version must first name the provider, exact cookies, purpose, retention and data transfers. The tool must remain technically blocked until an affirmative choice.
4. Control and withdrawal
Use “Cookie settings” in the footer to reopen the notice. You may also delete cookies in browser settings. Necessary Admin authentication stops working if its session cookie is blocked or removed.
5. What must never be stored in cookies
Passwords, passkey private material, biometrics, TOTP secrets, recovery codes, application answers, ESI results, corporate secrets or raw database credentials must never be placed in browser cookies.