Legal
Cookie policy
Storage for authentication, private drafts, user-requested settings and optional performance-sharing preferences.
These legal documents are published in English. Interface language preferences do not alter their meaning, scope or governing version.
- Effective date
- 23 July 2026
- Service operator
- The Diligence Room
Strictly necessary session cookie
After Discord OAuth sign-in, the API sets tdr_member_session. It is HTTP-only, Secure in production, SameSite=Lax and scoped to the portal path. It lets the API recognize the signed-in member and expires no later than the configured session period, currently up to 30 days.
A separate CSRF token protects account-changing requests. These controls are necessary to provide the authenticated service and cannot be disabled while remaining signed in.
No advertising or analytics cookies
The portal does not currently install advertising, behavioral profiling or third-party analytics cookies. Therefore no optional-cookie consent banner is shown.
Optional first-party performance sharing is disabled by default. The footer control enables or disables it without installing third-party analytics cookies. The browser stores this choice in local storage under tdr.performance-consent.v1. Reports contain only performance values and broad device/surface categories; samples expire within seven days. The feature is not advertising or behavioral profiling.
Browser storage
Interface language and the optional performance-sharing choice use local storage. Member-scoped session storage retains filters, working context and recoverable drafts in the current browser tab. Signing out clears that member's tab-scoped state. Explicit account draft snapshots are stored privately on the server, not in a cookie.
The private Founder backoffice stores its API connection details in that browser's local storage. This is separate from the member portal and is used only for the operator's authenticated administration session.
Control and deletion
Signing out revokes the server session and clears the session cookie. You can also remove site data through browser settings, which will sign you out.