LEGAL & POLICIES
Last updated · August 27, 2026v1.6
Cookie Policy
1. What we use
For authentication, one first-party cookie:
- `session` — keeps you signed in. It is dropped after 90 days of inactivity; opening the app resets that inactivity window. A one-year absolute limit still requires periodic re-authentication even for continuously active sessions. HttpOnly, SameSite=Lax, and Secure when served over production HTTPS.
2. What we do not use
No advertising cookies. No social-media pixels. We avoid third-party tracking cookies on the marketing site.
3. Local storage
The H5 app may use local storage for session pointers, room code hints, language, UI preferences, and a first-party telemetry anonymous id. The marketing site stores its own origin-scoped anonymous telemetry id so aggregate visits and page views can appear in the internal daily report. It is not used for advertising or cross-site tracking. Hand history and review data are served from the backend, not from a marketing-site cookie.
4. Contact
Cookie questions: loong@bluffking.ai.