Cookies Policy
Last updated: 8 July 2026
The short version: this site sets a small number of strictly-necessary cookies to make signing in work, and nothing else. We use no analytics, advertising, or tracking cookies of any kind, which is why you do not see a cookie consent banner here — none of our cookies require consent under UK law (PECR), because they are all essential to a service you explicitly request: logging in.
Fonts are self-hosted, so your browser makes no requests to third-party font or script servers when you visit.
Cookies we set
| Cookie | Purpose | Lifetime |
|---|---|---|
__Secure-authjs.session-token | Keeps you signed in to your dashboard. An encrypted session token, httpOnly and secure — it cannot be read by scripts. | Session (up to 30 days) |
__Host-authjs.csrf-token | Protects sign-in and account forms against cross-site request forgery. | Session |
__Secure-authjs.callback-url | Returns you to the right page after signing in. | Session |
__cf_bm | May be set by Cloudflare, which hosts this site, to distinguish real visitors from malicious bots. | Up to 30 minutes |
These cookies are only set when relevant — the sign-in cookies when you create an account or sign in, the Cloudflare cookie as part of serving the site securely.
Payments and Stripe
When you upgrade to a paid plan, checkout happens on Stripe's own pages (checkout.stripe.com). Stripe sets its own cookies on its own domain there — not on rotuli.co.uk. See Stripe's cookie policy for details.
Controlling cookies
You can block or delete cookies through your browser settings at any time. Because every cookie we set is essential to signing in, blocking them will prevent you from using your account — the public pages of the site will work fine without any cookies at all.
If this ever changes
If we ever introduce non-essential cookies — analytics, for example — we will add a consent mechanism first and update this page before anything is set. Questions? Email privacy@rotuli.co.uk, or see our Privacy Policy.