Vai al contenuto

Cookie policy

This site sets two cookies, both technical, both needed for the forms to work. There is no analytics, no advertising, no tracking, and nothing loaded from a third-party domain — which is also why there is no consent banner to click away.

Last updated: 1 September 2026

The cookies this site sets

Both are first-party, set by 1801.it itself, and both expire after two hours. Names as they appear in your browser:

XSRF-TOKEN

Carries the anti-forgery token that pairs the form you are looking at with the submission that arrives from it. Without it, a form sent from this site could not be told apart from one forged by another site. Expires after two hours, or when you close the browser session.

The session cookie — 1801-dev-session

Identifies your session on the server so the captcha question shown on the page can be checked against the answer you submit, and so validation errors survive the round trip. It holds a session identifier, not your personal data, and it is HttpOnly: scripts in the page cannot read it. The name is taken from the application configuration, so a different deployment of the same codebase may show a different one.

Why there is no consent banner

Consent is required for cookies that are not strictly necessary. Both cookies above exist only so that a form you chose to submit can be submitted safely, they carry no identifier used to follow you anywhere, and neither is read by anyone but this site — which is the exemption for strictly necessary storage under the ePrivacy rules as transposed in Czech law, and as read by the Czech data protection authority (Úřad pro ochranu osobních údajů). A banner asking permission for a cookie you cannot refuse without breaking the form would be theatre, so there isn't one. If anything non-essential is ever added, the banner comes with it and this page is updated first.

No third-party requests

Loading a font, a script or an icon set from someone else's domain sends your IP address and browser details to that domain whether or not a cookie is involved. This site does none of it:

  • no Google Analytics, no advertising or conversion pixels, no heatmaps, no session recording, no A/B testing tool;
  • no embedded videos, maps, chat widgets or social buttons that phone home;
  • no web fonts loaded from Google Fonts or any other font CDN. The typeface used across the site, Schibsted Grotesk, is served from this domain under the SIL Open Font License; until 1 September 2026 it was pulled from fonts.googleapis.com, which exposed every visitor's IP address to Google, and it no longer is.

The stylesheet and the one script the site loads are served from 1801.it.

Infrastructure

Traffic reaches the server through Cloudflare, which acts as CDN and protection layer and therefore sees the connection, including your IP address. On the pages checked for this notice it set no cookie of its own; its abuse-protection features can set a technical cookie on a request it considers suspicious. What Cloudflare processes is covered in the privacy notice under providers.

Blocking them

Your browser settings can block or delete cookies for this site, and nothing here needs them for reading. Blocking them breaks form submission: without the anti-forgery token and the session, a submitted form is rejected as unverifiable. Reading the site works either way.