Published policy
Cookie Policy
The strictly necessary cookies and local browser state used by Unoctu for sign-in and secure checkout.
Cookie types and inventory
Unoctu distinguishes strictly necessary HTTP cookies from local preference storage and provider-controlled storage. Strictly necessary cookies support requested account and checkout functions; they do not require optional consent. Optional repository metadata requests run only after you choose Accept all. We do not install analytics, advertising, social-media, or other optional tracking cookies on the Unoctu domain.
| Name or technology | Type / category | Purpose | Duration | Consent |
|---|---|---|---|---|
__Host-unoctu_session (or unoctu_session locally) | First-party HTTP cookie; strictly necessary | Carries the signed, HttpOnly short-lived access token | Up to 15 minutes; renews while a valid refresh credential exists | Not required for the requested account service |
__Host-unoctu_refresh (or unoctu_refresh locally) | First-party HTTP cookie; strictly necessary | Keeps the browser signed in using an opaque value stored only as a hash in D1 | Up to 365 days after normal use; ends on logout, account deletion, or server-side revocation | Not required for the requested account service |
ai.unoctu.launcher.auth in Windows Credential Manager | First-party OS credential; strictly necessary for the launcher | Stores the launcher-only sign-in credentials so WebView cookie loss does not sign you out | Until explicit launcher logout, account deletion, or credential removal; access tokens are renewed as needed | Not a browser cookie; not used for tracking |
__Host-unoctu_checkout_state (or unoctu_checkout_state locally) | First-party HTTP cookie; strictly necessary | Binds a short-lived Stripe checkout handoff to the account and prevents cross-site request forgery | 10 minutes | Not required for secure checkout |
unoctu_cookie_consent | First-party localStorage; preference | Stores the selected consent choice, timestamp, and policy version | 365 days or until the policy version changes; you can clear it sooner | Created when you choose Accept all or Reject optional |
unoctu.launch.workspace-preferences.v1 and similar app preferences | First-party localStorage; functional preference | Remembers local display and workspace choices; it is not sent to Unoctu | Until you clear browser or app storage | Not used for tracking |
| Stripe-hosted checkout and Cloudflare provider storage | Third-party / provider-controlled | Payment security, fraud prevention, and delivery of the hosted service when you follow that service flow | Set by the provider under its policy | Managed on the provider domain; Unoctu does not install optional tracking cookies on this site |
Consent and preference management
The browser stores a structured unoctu_cookie_consent preference containing your choice, timestamp, and policy version. A current choice lasts up to 365 days and is requested again when the policy version changes or the record expires. You can reopen Privacy settings at any time to accept, reject, or withdraw optional processing. Rejecting optional processing does not block the site, account, or checkout.
Third-party services
Cloudflare supports the site and account API, Stripe handles checkout when you choose to purchase, and Resend or Cloudflare Email Service may deliver sign-in email. GitHub is contacted for optional public repository metadata only after you choose Accept all. Those providers may use cookies or local storage on their own domains under their own policies; Unoctu does not control that provider storage.