Legal

Cookies Policy

We set the cookies required to run the site, plus Google Analytics to measure which pages get read. No advertising, no retargeting, no session recording.

Last updated 27 July 2026

1. What cookies are

Cookies are small text files a website stores in your browser. They are commonly used to keep you signed in, remember preferences, measure how a site is used, or track behaviour across sites. We use them for the first three, and never the fourth.

2. What we set

The first two cookies below are strictly necessary and are set only once you interact with a feature that needs them. The analytics cookies are set as soon as a page loads.

  • Session cookie: issued when you sign in, so the site knows who you are between requests. It is HttpOnly (unreadable by JavaScript), Secure (sent over HTTPS only), and expires after 24 hours. It holds an opaque identifier, not your personal data.
  • CSRF token cookie: a random value paired with a request header to prove a form submission genuinely came from our site. It is readable by our own JavaScript by design, which is what makes the double-submit check work, and holds no personal data.
  • Google Analytics cookies (_ga and _ga_XMQDDN0524): set by Google Analytics 4 to count visitors and see which pages get read. They store a randomly generated identifier, not your name or email, and expire after two years. They are written on the odonat.ai domain, but the script that sets them is served by Google and the measurement data is processed by Google.

3. What we do not set

  • No advertising or retargeting cookies.
  • No Google Signals, no ads personalisation, and no cross-site advertising identifiers.
  • No session-recording, heatmap, or replay scripts.
  • No social media embeds that would set cookies on our behalf.

4. Consent

Under the ePrivacy rules and equivalent regimes, cookies that are strictly necessary to deliver a service you have requested, such as keeping you signed in and protecting a form against forgery, do not require prior consent. The session and CSRF cookies above fall in that category.

Analytics cookies do not. They are not required to deliver this site, so in the EU, the UK, and other regimes that follow the same rule, they require your consent before being set. We do not yet present a consent banner, which means visitors from those regions currently have analytics cookies set without being asked. We would rather write that down than let this page imply an exemption we are not entitled to. A consent control is being added; until it ships, the browser and Google opt-outs in section 5 are the way to prevent measurement.

5. Controlling cookies

You can block or delete cookies in your browser settings. Blocking the session and CSRF cookies will not affect the public pages, but you will not be able to sign in or submit the contact form, because both depend on them. Blocking the analytics cookies affects nothing you can see; it only means your visit is not counted.

To opt out of Google Analytics across every site that uses it, install Google’s browser opt-out add-on. Most browsers’ tracking-protection settings and any standard content blocker will also stop the tag from loading.

6. Changes

If we introduce any new cookie we will update this page and, where the law requires it, ask for your consent before setting it.

7. Contact

Questions about this policy: contact@odonat.ai. See also our Privacy Policy.