Cookie & Tracking Policy

Last updated: February 13, 2026 · Effective: February 13, 2026

This Cookie & Tracking Policy explains how Universe Solver ("we," "us," or "our") uses cookies, local storage, and tracking technologies on universesolver.com (the "Platform"). This policy supplements our Privacy Policy.

TL;DR: We don't use traditional tracking cookies. Our analytics system uses localStorage (not cookies) and only operates after you explicitly consent. We use zero third-party trackers. You're in full control.

1. What Are Cookies?

Cookies are small text files that websites place on your device to store information. Universe Solver uses minimal cookies — only what is strictly necessary for the Platform to function. We do not use advertising, targeting, or third-party analytics cookies.

2. Technologies We Use

2.1 Strictly Necessary Cookies (No Consent Required)

These cookies are essential for the Platform to function and cannot be disabled:

Name Purpose Duration Type
session Flask session cookie — stores your login state (encrypted, HttpOnly, SameSite=Lax) Browser session Cookie
csrf_token Cross-site request forgery protection token Browser session Cookie
remember_token Persistent login (only if you check "Remember Me") 30 days Cookie

2.2 localStorage (Analytics — Consent Required)

If you consent to analytics, we use localStorage (not cookies) to store:

Key Purpose Duration
_us_consent Your analytics consent choice ("granted" or "denied") Persistent
_us_consent_ts Consent version number (to detect policy changes) Persistent
_us_sid Random session identifier (32-character hex string) 30 min inactivity
_us_sid_ts Session timestamp (for expiration checking) 30 min inactivity

3. What We Track (With Consent Only)

Our custom-built analytics system collects the following, only after explicit consent:

  • Page views: URL path, page title, referrer, performance metrics.
  • Clicks: Element type (button, link), element ID/class, position. We never record form field values, passwords, or sensitive text.
  • Scroll depth: How far you scroll on each page (milestone-based: 25%, 50%, 75%, 100%).
  • Mouse movements: Coordinates sampled every 50ms for session replay. Used to understand navigation patterns and improve UX.
  • Errors: JavaScript errors (filename, line number, message) to help us fix bugs.
  • Session metadata: Browser, OS, screen resolution, language, timezone offset.

4. What We Do NOT Track

  • Form field contents, passwords, or sensitive user inputs.
  • Keystrokes or keyboard events.
  • Audio, video, or camera activity.
  • Activity on other websites (no cross-site tracking).
  • Personal identifiers in URLs (we strip query parameters containing email, token, etc.).

5. Third-Party Technologies

Service Purpose Data Shared
Google Fonts Font delivery (Inter, JetBrains Mono) IP address (standard HTTP request); see Google Privacy Policy

We do not use Google Analytics, Facebook Pixel, Hotjar, Mixpanel, or any other third-party analytics or tracking service.

6. Managing Your Preferences

6.1 Consent Banner

When you first visit the Platform, a banner asks whether you consent to analytics tracking. You can accept or decline. If you decline, no analytics data is collected.

6.2 Change Your Choice

You can change your analytics consent at any time:

  • Logged-in users: Go to Settings → Privacy Preferences.
  • All users: Clear _us_consent from your browser's localStorage (Developer Tools → Application → Local Storage) to be re-prompted.

6.3 Browser Settings

You can configure your browser to block cookies, clear localStorage, or send Do Not Track (DNT) signals. We honor DNT signals — if your browser sends a DNT header, our analytics system will not track your activity.

7. Data Retention

  • Analytics session data is automatically purged after 90 days.
  • Mouse recording data is automatically purged after 90 days.
  • Consent preferences are stored indefinitely in your browser's localStorage (you control this).

8. EU ePrivacy Directive Compliance

In compliance with the EU ePrivacy Directive (2002/58/EC as amended by 2009/136/EC), we:

  • Obtain explicit, informed, and freely given consent before setting any non-essential storage (analytics localStorage items).
  • Provide clear information about what data is collected and why.
  • Allow users to withdraw consent at any time.
  • Only use strictly necessary cookies (session, CSRF) without consent, as permitted under the "strictly necessary" exemption.

9. Contact

Universe Solver — Data Protection
Email: privacy@universesolver.com
Subject line: "Cookie Policy Question"