Cookies on scrollforge.io
Six first-party cookies, all of them about signing you in and showing the page the way you asked. No analytics cookies, no advertising, no tracking across sites — so there is no consent banner to click.
01What this site sets
Plain English · Browsing sets nothing except, on your first page view, a session-only marker that stops the silent sign-in check from repeating. Opening the sign-in box adds its anti-forgery cookie; signing in adds the session cookie and the appearance hint.
| Cookie | What it does | Set | Lifetime | Attributes |
|---|---|---|---|---|
sf_session | Keeps you signed in on scrollforge.io. Holds your session, encrypted (AES-256-GCM); page scripts cannot read it. | When you sign in | 30 days, or until you sign out | HttpOnly · Secure · SameSite=Lax |
sf_oauth_txn | Protects the sign-in round-trip against forgery (the OAuth state and PKCE verifier) while you are being sent to EternalEngine and back. | When you click Sign in | 5 minutes | HttpOnly · Secure · SameSite=Lax |
sf_csrf | Protects the sign-in box against forgery: another site cannot submit it on your behalf. Holds a random value signed by this site, nothing about you. | When you open the sign-in box | 2 hours | HttpOnly · Secure · SameSite=Strict · sign-in routes only |
sf_mfa_txn | Holds your half-finished sign-in, encrypted, while you type the code from your authenticator app. Page scripts cannot read it. | When your account asks for a sign-in code | 5 minutes, or until you finish signing in | HttpOnly · Secure · SameSite=Strict · sign-in routes only |
sf_sso_checked | Remembers that this browser already checked once whether you were signed in to the EternalEngine app, so the check never repeats or loops. | On your first page view, and on sign-out | This browser session | Secure · SameSite=Lax · readable by page script (by design) |
sf_theme | A hint (light or dark) so the page paints in the appearance you chose in Settings before any script runs. Set only for a signed-in user; cleared on sign-out. | When you sign in or change Appearance | 30 days | Secure · SameSite=Lax · readable by page script (by design) |
All six are essential to the function you asked for (signing in, staying signed in, not looping, painting your chosen appearance). None is used for analytics, profiling or advertising, and none is shared with anyone.
02Stripe, on checkout and payouts
When you are signed in and open a paid listing, and on the seller payout page, this site loads Stripe.js so that Stripe's own payment and onboarding forms can run. Stripe may set cookies from its own domain for fraud prevention on those forms, underStripe's privacy policy. Nothing from Stripe loads on a page you are only browsing.
03What we do not do
- No analytics or measurement cookies on scrollforge.io.
- No third-party advertising cookies, ever.
- No cross-site tracking or fingerprinting.
- No selling or sharing of cookie-derived data.
- No other third-party scripts: fonts are served from this site.
Because nothing non-essential is set, no cookie-consent banner is shown. If we ever add a non-essential category, we will update this page first and ask before setting it.
04Your choices & the app
You can block or delete cookies in your browser at any time; blocking the essential ones prevents sign-in and checkout from working. Signing out clears sf_session andsf_theme. The EternalEngine app at app.eternalengineos.io sets its own cookies, described in the EternalEngine Cookie Policy; how we handle personal data is in the Privacy Policy, and every request you can make is on Your Data & Requests. Questions: info@eternalengineos.io.
