Cookies Policy
Last updated: June 9, 2026
This Cookies Policy explains the cookies and similar browser storage that Scytala uses, who controls them, and how you can manage your choices. Scytala is operated by Hector Antonio Jasso Garza, based in Monterrey, Nuevo León, Mexico. It should be read together with our Privacy Policy.
Cookies are small text files a website stores on your device; similar technologies include browser localStorage and sessionStorage. Scytala deliberately uses very little of this. We do not run advertising or cross-site tracking, and the storage we do use is described in full below.
1. Strictly Necessary Storage
These items are required for the Service to work. They keep you signed in and protect your account during sign-in. You cannot opt out of them without breaking authentication and security, so they are set regardless of your analytics choice. None of them are used for advertising or tracking.
| Name | Type | Purpose | Retention |
|---|---|---|---|
scytala_session | First-party cookie (HttpOnly, Secure, SameSite=Strict) | Authenticates your session and keeps you signed in to the dashboard. Because it is HttpOnly, it cannot be read by page scripts. | Up to 14 days; cleared when you sign out |
afk_oauth_state_* | Browser sessionStorage | Holds a one-time random "state" value during a connect or sign-in flow with an identity provider (for example GitHub or Slack) to protect against cross-site request forgery (CSRF). It is read back and removed once the flow completes. | Until the flow finishes or the browser tab is closed (cleared per session) |
scytala_cookie_consent | First-party cookie + localStorage | Records your cookie choice ("essential only" or "accept all") so we do not show the consent banner again and so analytics stays disabled unless you opted in. | Up to 1 year, or until you clear it |
2. Analytics (Optional, Consent-Gated)
We use PostHog for product analytics — to understand how the Service is used and to improve it. Analytics are off by default and are only enabled if you choose "Accept All" in the consent banner. If you choose "Essential Only," PostHog is never initialized.
- Consent-gated: analytics load only after you explicitly opt in via the banner.
- Do Not Track honored: we set
respect_dnt: true. If your browser sends a Do Not Track signal, PostHog will not track you even if you accepted analytics. - Memory persistence: PostHog is configured with
persistence: "memory". This means it does not write a persistent cookie or store a stable identifier in your browser — analytics state lives only in memory for the current page session and is gone when you close or reload the tab. There is no cross-session tracking identifier. - Minimal capture: automatic event capture and session recording are disabled, on-screen text and element attributes are masked, and only page-view events on navigation are sent.
3. What We Do Not Use
To be explicit, and consistent with our Privacy Policy, Scytala does not:
- use advertising or marketing cookies;
- use cross-site, third-party, or behavioral ad trackers;
- build advertising profiles, run remarketing, or load tag-manager / ad-network pixels;
- sell or rent your personal data.
4. Managing Your Choices
When you first visit, a consent banner lets you choose Essential Only (no analytics) or Accept All (enables analytics). You can revisit this choice at any time:
- Clear the
scytala_cookie_consentcookie andlocalStoragevalue (for example, by clearing site data in your browser); the banner will appear again on your next visit so you can choose differently. - Use your browser settings to view, block, or delete cookies and to enable a Do Not Track signal, which we honor.
Disabling strictly necessary storage will prevent sign-in and secure OAuth flows from working. For how we handle the underlying personal data, see our Privacy Policy.
5. Changes to This Policy
We may update this Cookies Policy to reflect changes in the storage we use or in applicable law. We will post the updated policy on this page with a new "Last updated" date.