Cookies
Everything CFXR stores in your browser. Last updated: 3 September 2026.
Why there is no cookie banner
Every cookie CFXR sets is strictly necessary for something you asked it to do — signing in, staying signed in, or protecting the sign-in itself. Under Article 5(3) of the ePrivacy Directive (in Czech law, § 89 of zákon č. 127/2005 Sb.) that kind of storage does not require consent, so we do not interrupt you with a banner asking for it. We do have to tell you about it, which is what this page is for.
Cookies
All of these are set by cfxr.cc itself. All arehttpOnly (unreadable by JavaScript), SameSite=Lax, and served only over HTTPS in production. None of them is set until you start signing in.
| Name | What it does | Expires |
|---|---|---|
| cfxr_session | Keeps you signed in to your CFXR account. | 30 days |
| cfxr_admin | Keeps an administrator signed in to the admin panel. | 7 days |
| cfxr_oidc_state | Protects the sign-in redirect against cross-site request forgery. | 10 minutes |
| cfxr_oidc_verifier | Holds the PKCE verifier and nonce that prove the sign-in came from this browser. | 10 minutes |
| cfxr_oidc_return | Remembers the page to return you to after sign-in. | 10 minutes |
| cfxr_oidc_id | Lets us sign you out of Titan Auth as well as CFXR. | 30 days |
Browser storage
When you are signed out, your watchlist is kept in your browser's local storage under the key cfxr:watchlist. It never leaves your device unless you sign in, at which point it is imported into your account once and then cleared. Nothing else is stored locally.
Controlling this
You can clear cookies and local storage in your browser settings at any time. Clearing them signs you out and, if you are signed out, discards your local watchlist. Blocking these cookies entirely means you cannot sign in; the resolver, directory, comparison and bulk tools all keep working without an account.
Questions go to [email protected]. For what happens to data once it reaches our servers, see the Privacy Policy.