Cookie policy
Last updated August 25, 2026
What this policy covers
Sodality uses a small number of cookies so the site can work. A cookie is a short piece of text your browser stores for this site. This page explains which cookies we set, why, and how you can control them.
This policy is for this copy of Sodality (this instance). If someone else hosts their own copy, their cookies and operators may differ.
Cookies we set
Sign-in session. After you sign in with an email link or a password, we set a session cookie so we know it is you on the next page. These cookies are required to stay signed in. They are set by our sign-in system (Better Auth). Typical names include a session token such as better-auth.session_token. They are first-party, HttpOnly where the system allows it, and use SameSite=Lax. They last until the session expires or you sign out.
Language. If you pick a language, we store it in a cookie named sodality_locale so we do not have to guess from the browser every time. This is a preference cookie. It lasts about one year.
Cookie notice. When you tap OK on the cookie notice, we set sodality_cookie_ok so we do not keep showing the bar. It lasts about one year.
What we do not use
We do not set advertising cookies. We do not use third-party ad networks. We do not currently set third-party analytics cookies (no Google Analytics, Meta Pixel, or similar).
Some pages load fonts from the same app. We do not load extra tracking scripts for ads.
Why we need the essential ones
Without the session cookie, you would have to sign in on every click. Without the language cookie, we would only follow the browser language until you choose again. You can use the public pages (home and these policies) without signing in; the session cookie is set only after a successful sign-in.
How you can control cookies
You can delete cookies in your browser settings, or use a private window. If you delete the session cookie, you will be signed out. If you delete the language cookie, we fall back to your browser language.
Blocking all cookies may break sign-in. That is expected: the session has to live somewhere.
There is no “sell my data” toggle because this instance does not sell personal information or run ads against it.
Changes
We will update this page if we add new cookies. The date at the top is the last change. Current version: August 25, 2026.