1. Intro

Cookies are small text files stored on your device. We use them to run the site, remember your preferences, and keep the service secure. This page lists every cookie we set.

2. Cookie categories (PECR classification)

CategoryConsent requiredDescription
Strictly necessaryNo (PECR exception)Site function: CSRF, session, auth
Performance/analyticsYesMeasure site performance (if used)
FunctionalYesRemember preferences
Targeting/advertisingYesNot used v1

3. Cookie inventory

NamePurposeCategoryDurationProvider
cf_clearanceCloudflare WAF challengeStrictly necessary30 daysCloudflare
__cf_bmCF bot managementStrictly necessary30 minCloudflare
_turnstile_tokenTurnstile bot checkStrictly necessaryForm sessionCloudflare
lk_sessionAuth session (post-signup)Strictly necessary30 days rollingLeadKing
lk_csrfCSRF protectionStrictly necessarySessionLeadKing
lk_consentRemembers your cookie choiceFunctional6 monthsLeadKing
lk_themeLight/dark preferenceFunctional1 yearLeadKing

4. What we don't use

5. Consent mechanism

First visit: banner with three buttons — Accept all, Reject all, Manage. Reject is as visually prominent as Accept. Manage opens a modal with per-category toggles (strictly necessary locked on). No dark patterns. No pre-ticked boxes.

Withdrawal: footer link "Manage cookies" reopens the modal any time. Changes apply immediately.

6. Do Not Track & Global Privacy Control

We honour Sec-GPC: 1 (Global Privacy Control) — treats as "reject all" preference. Legacy DNT: 1 also honoured.

7. Third-party cookies

Cloudflare: necessary for site function + security (PECR exception). Stripe (on billing portal only, not marketing site): necessary for payment. No advertising third-party cookies.

8. Changes

Material changes trigger consent banner re-display. Last updated date above.

9. Contact

Email: [email protected]. See also /privacy for broader data policy.