Cookie Policy
Effective
This policy explains the cookies and similar technologies the Indacas Platform uses. It covers both the Indacas application and the public website, including the help centre and contact form. It should be read with our Privacy Policy.
1. Summary
We only use strictly necessary cookies. Every cookie the Platform sets exists to sign you in, keep your in-progress survey response safe, return you to the right page, or remember your display preference. We use no advertising cookies, no third-party analytics cookies, and no tracking across other websites.
Because all our cookies are strictly necessary for the service you have asked for, UK law (the Privacy and Electronic Communications Regulations, PECR) does not require us to ask for consent before setting them, and no cookie banner is shown. Every cookie we set is listed in Section 2.
2. Cookies we set
All cookies below are first-party (set by the Indacas Platform itself) and classified strictly necessary.
| Cookie | Purpose | Duration |
|---|---|---|
ory_kratos_session |
Your sign-in session, issued by our self-hosted Ory Kratos identity service. Without it you cannot stay logged in. | 24 hours from signing in. The application also signs you out after 15 minutes of inactivity. |
{uuid}_{slug} and {uuid}_{response-id} response token cookies (a fixed UUID prefix plus the distribution identifier or the response identifier, e.g. 12b2195b-…_my-survey) |
Hold the token identifying your in-progress or submitted survey response, so anonymous respondents can continue and review their response. Two cookies per response: one keyed by the distribution, so a return visit to the same link resumes your response, and one keyed by the response, so the response's own page can be reopened. | 30 days |
post_auth_next |
Remembers the page you were trying to reach so we can return you there after signing in. | 24 hours |
auth_prefill_email |
When you follow an email invitation, pre-fills the invited email address on the sign-up form. | 1 hour |
flow_survey_return_{response-id} |
When a survey is one step of a study flow, remembers where to send you back once the survey is complete. | Session |
Cookies our reverse proxy may set
Cloudflare sits in front of the Platform as our reverse proxy. It sets no cookies in ordinary use, but may set the following on our domain when it serves a security challenge to a request it considers suspicious. Both are strictly necessary for protecting the Platform.
| Cookie | Purpose | Duration |
|---|---|---|
__cf_bm |
Distinguishes automated traffic from people as part of Cloudflare's bot protection. | 30 minutes |
cf_clearance |
Records that a security challenge was passed so that it is not shown again. | Set by Cloudflare's challenge passage setting, 30 minutes by default |
Similar technologies (not cookies)
| Item | Purpose | Where it lives |
|---|---|---|
theme-preference |
Remembers your light/dark theme choice. | Your browser's local storage. Stored on your device only and never sent to our servers |
cf.turnstile.u |
Used by Cloudflare Turnstile, the bot check on the contact form and on new anonymous survey responses, to run the check. | Your browser's local storage |
3. What we do not use
- No advertising or retargeting cookies.
- No third-party analytics cookies (no Google Analytics or similar). Our operational monitoring runs on our own self-hosted infrastructure and works from server logs, not browser cookies.
- No social media pixels or embedded trackers.
- No cross-site tracking of any kind.
This applies across the whole Platform, including the survey-answering pages Participants and anonymous respondents see.
4. Managing cookies
You can block or delete cookies in your browser settings. Because everything we set is strictly necessary, blocking our cookies will break core functionality: you will not be able to stay signed in, and anonymous survey responses may be lost between pages.
5. If this ever changes
If we ever introduce cookies that are not strictly necessary (for example, optional analytics), we will, before setting any such cookie:
- update this policy with a full description of the new cookies; and
- introduce a consent mechanism (a cookie banner or settings panel) that obtains your opt-in consent as PECR and UK GDPR require, with non-essential cookies off by default.
We review this policy whenever the Platform's cookie usage changes.
6. Contact
Questions about this policy: [email protected].