Cookies and browser storage
Version 1.2 — Effective date 2026-09-14 — Status live — SHA-256 6dff723d702b84c6da0ac4462c12eedeed5af88d7564d7eb6084f377d2e7bce1
Prélude uses the declared cookies and storage for authentication, the natal tunnel and, only after explicit consent, first-party pseudonymous journey measurement. No advertising pixel, third-party analytics or A/B testing is active.
Strictly necessary inventory
- authjs.session-token / __Secure-authjs.session-token — Account-session authentication and security. Durée : 30 days maximum.
- authjs.csrf-token / __Host-authjs.csrf-token — CSRF protection for authentication forms. Durée : browser session.
- authjs.callback-url / __Secure-authjs.callback-url — Return to the requested page after authentication. Durée : browser session.
- prelude-natal — Natal tunnel state, derived data and previews in the current tab. Durée : tab session.
- prelude-measurement-choice — Respect the explicit journey-measurement choice in the current tab. Durée : tab session.
- prelude-journey — Random pseudonymous identifier and minimal state for consented journey measurement in the current tab. Durée : 30 minutes of inactivity, 24 hours maximum.
Management
Browser controls can erase these data. The permanent “Journey measurement” button withdraws this consent and immediately stops measurement in the browser; it requests server deletion. If that request cannot be confirmed, only the pseudonym needed for another attempt remains in the tab for at most 24 hours. Clearing session cookies signs the account out; clearing sessionStorage resets the tunnel for that tab.