Cookie policy

Last updated: August 2026

This page sets out what the privacy policy sums up: which cookies are set, by whom, why, and for how long. Nothing beyond a session cookie is set until you have given your agreement.

Necessary, active without consent

These cookies are essential to the site working. Without them, the session does not hold. They serve no tracking purpose.

access_token : the session token that keeps you signed in. Set by Auralfa, marked httpOnly, so out of reach of the page's JavaScript. Its lifetime follows the site's session-duration setting.

oauth_verifier : a temporary security cookie, set only during a sign-in through a third-party service, and deleted on return. Ten minutes.

Consent choices and display preferences : kept in your browser's local storage, not in a cookie sent to the server. They remember your theme and your answer to the banner, so as not to ask again at every visit.

Audience measurement, only if you accept

They tell us which pages are useful and where people get lost. No script is loaded before your agreement: this is not a setting, it is the loading itself that is conditional.

Google Analytics 4 : traffic statistics, with IP anonymisation. Usual lifetime of thirteen months.

Microsoft Clarity : usage statistics and heatmaps, to see which parts of a page are actually used. Usual lifetime of one year.

Advertising

This category appears in the banner, and no advertising cookie is active to date. We keep it visible rather than removing it: were that to change, the choice would already be in your hands, and nothing would fire without agreement.

Change or withdraw your consent

At any time, with no reason given, and in the same number of clicks as accepting.

You can also delete cookies from your browser's settings. Deleting the session cookie will simply sign you out.

Going further

How your data is handled beyond cookies, the list of processors and your rights of access and erasure are set out in the privacy policy.